OP-mobile Security & Privacy Scorecard
Android
User activity is tracked by Firebase and Adobe Marketing Cloud. Multiple high-severity findings were identified in how financial data is stored and transmitted, which may leave banking information less protected than expected. Device details and usage patterns are shared with several third-party services.
Best for
OP bank customers comfortable with analytics
Avoid if
You share devices with others
Findings
- 3 critical
- 9 high
- 6 medium
- 2 low
- 3 info
0 issues identified across security and privacy analysis.
Top security issues
- BlobHandler JavaScript Interface Path Traversal Vulnerability
- API Tokens Encryption Unverified
- Test JWT Generation Endpoint in Production Build
Top privacy issues
- Callsign Behavioral Biometrics Without Explicit Consent (GDPR Article 9)
- Adobe Marketing Cloud in Banking App Without Consent
- Comprehensive Behavioral Profiling via Analytics
Full analysis
OP-mobile
fi.op.android.opmobiili | Version 79.0.1 | Analyzed: 2026-01-31
What This Means for You
User activity is tracked by Firebase and Adobe Marketing Cloud. Multiple high-severity findings were identified in how financial data is stored and transmitted, which may leave banking information less protected than expected. Device details and usage patterns are shared with several third-party services.
Recommendation: Use With Caution
Best For: OP bank customers comfortable with analytics
Avoid If: Users who share devices with others
Key Findings
Data Security - 5 findings (4 high, 1 medium)
Network Security - 2 findings (1 critical, 1 medium)
Code Safety - 0 findings
Privacy - 5 findings (2 high, 3 medium)
Privacy Concerns
What Data is Collected
The app collects device identifiers, location data, and behavioral data including user in-app actions, transaction patterns, and usage frequency. This information supports analytics and personalization features within the app.
Third-Party Data Sharing
Data is shared with the following third-party services:
- Firebase - Analytics and crash reporting
- Adobe Marketing Cloud - Marketing analytics and behavioral profiling
- Google Maps - Location and mapping services
- Samsung Pay - Payment processing
- Callsign - Identity and authentication services
- Bouncy Castle - Security library
- Jackson - Data processing library
- Kryo - Data processing library
- OkHttp - Network communications library
- VASCO - Authentication services
Understanding the Scores
| Category | Score |
|---|---|
| Security | 45/100 |
| Privacy | 55/100 |
| Data Security | 50/100 |
| Network Security | 60/100 |
| Code Safety | 40/100 |
| Data Collection | 70/100 |
| Data Sharing | 65/100 |
| User Control | 50/100 |
Positive Security Features
- None identified in this version of the app.
Areas for Improvement
- Financial data stored on the device may benefit from stronger protection to reduce risk to banking information.
- Communications between the app and banking servers travel with less protection than expected, which is relevant on public Wi-Fi.
- The app's underlying code practices need strengthening to reduce the risk of unauthorized access to account information.
About This Analysis
This scorecard is generated from automated static analysis of the app's code and behavior patterns. Scores are on a 0-100 scale where higher is better.
App Details
- App: OP-mobile
- Package: fi.op.android.opmobiili
- Version: 79.0.1 (build 7905)
- Scan Date: 2026-01-31
Versions & scan history
| Scan | Date | Overall score |
|---|---|---|
| #1 (current) | 50/100 |