mBank PL - Twój bank i finanse Security & Privacy Scorecard

Android

86
Overall trust score
Trustworthy
85
Security
90
Privacy

Analytics collection is permanently disabled in this build. Active Firebase components for push notifications and performance monitoring share functional data with Google. Behavioral and usage data processed by the Synerise CRM module remains on mBank-controlled servers and requires explicit GDPR consent.

Best for

Daily banking with strong on-device security

Findings

  • 0 critical
  • 1 high
  • 1 medium
  • 2 low
  • 2 info

1 issue identified across security and privacy analysis.

Top security issues

  • Legacy WebView JavaScript Interface Exposes Authenticated HTTP Proxy to Bank Backend
  • EMakler SSO ContentProvider Protected by `dangerous` Rather Than `signature` Permission Level
  • Government eID Integration API Key Hardcoded in BuildConfig

Top privacy issues

  • Synerise CRM Behavioral Tracking Includes Banking Tier Metadata
  • Ad Attribution API Enabled with `allowAllToAccess="true"` in Banking App

Full analysis

mBank PL - Twój bank i finanse

What This Means for You

Your account and payment data is protected by strong device-level encryption and verified connections, and consent-gated behavioral analytics may send your in-app activity along with your banking tier status to mBank's CRM system when you enable marketing features.

Recommendation: Trustworthy

mBank provides robust security for Polish banking customers, with hardware-backed key storage, verified connections across all mBank domains, and screenshot protection active throughout the app. A legacy browser component in the codebase carries a theoretical risk that would only activate if bank-hosted content were compromised first, making it a low-probability concern for everyday users.

Best For: Users who need a full-featured Polish banking app with strong security controls and are comfortable with consent-gated marketing analytics.

Key Findings

Data Security - 3 findings (1 medium, 2 info)

Network Security - 0 findings

Code Safety - 1 finding (1 high)

Privacy - 2 findings (2 low)

Privacy Concerns

What Data is Collected

  • Personal information: name, email address, and phone number are shared with mBank servers and, when you consent to marketing features, sent to mBank's CRM analytics system.
  • Financial information: account balances, transaction history, and payment activity are shared with mBank servers to deliver banking services.
  • Location data: approximate and precise location are accessed on your device for branch and ATM finder features.
  • Contact information: phone contacts are accessed on your device to enable BLIK phone-number transfers and are not sent to third parties.
  • Device information: device identifiers and performance data are sent to Firebase services for push notifications and app stability monitoring.

Third-Party Data Sharing

The following third parties may receive your data:

  • Synerise (via mBank-controlled infrastructure) - behavioral analytics and CRM profiling, gated behind two separate GDPR marketing consent toggles
  • Google (Firebase, Maps, Ad Services) - push notifications, app performance monitoring, map features, and install attribution
  • FaceTec - biometric identity verification for account access and sensitive operations
  • Mastercard - contactless and mobile payment processing via MPSDK
  • PWPW/edoApp - government eID document verification

Understanding the Scores

Security: 85/100
Privacy: 90/100

Security Breakdown

  • Data Security: 88/100 - Account data and payment information are secured with strong device-level encryption. A legacy brokerage component uses a weaker permission model for authentication data storage, and two configuration items warrant verification by the development team.
  • Network Security: 100/100 - All connections to mBank services are encrypted in transit with no exceptions, and server identity is strongly verified across all mBank domains including Czech and Slovak endpoints.
  • Code Safety: 83/100 - The app is built with strong security defaults throughout. A legacy browser component contains an authenticated request interface that could be misused if bank-hosted content were ever compromised elsewhere.

Privacy Breakdown

  • Data Collection: 92/100 - The app collects personal and behavioral data within a clearly consent-controlled framework, with Firebase Analytics permanently deactivated at the build level.
  • Data Sharing: 93/100 - Data sharing with third parties is narrow in scope, and behavioral analytics are routed through mBank-controlled infrastructure rather than directly to external parties.
  • User Control: 92/100 - You can request data deletion, and marketing analytics require two explicit GDPR consent approvals before any behavioral data is sent.

Positive Security Features

  • Hardware-backed key storage: cryptographic keys for authentication are generated in the device's secure hardware and cannot be extracted by software.
  • All connections to mBank services are encrypted in transit with no exceptions, enforced at the application level across all regional endpoints.
  • Screenshots are blocked across all app screens and dialogs, protecting your financial information from screen capture.
  • App data is excluded from Android backup systems, preventing unintended data exposure through cloud or USB backup.
  • Firebase Analytics is permanently deactivated in this build, eliminating Google's standard behavioral tracking.
  • Payment data for BLIK contactless payments is stored with strong encryption on your device.
  • In-app browser components block local file access entirely, containing any browser-level risks.
  • The modern browser component used for the main app experience has no script interface and enforces strict content policies.
  • All diagnostic logging and debug modes are disabled in the released build.

Areas for Improvement

GDPR / CCPA Compliance

The app's privacy practices could be strengthened by:

  1. Banking Tier Disclosure Transparency
    When marketing analytics are enabled, your Private Banking status is included as a data point in CRM profiling. This distinction could be made clearer in the consent flow so users understand what account metadata is shared alongside behavioral data.

  2. Ad Attribution Scope Reduction
    The ad attribution configuration currently allows any qualified measurement provider to attribute app installation and in-app events to advertising campaigns. Restricting this to specific known providers would reduce the scope of platform-level measurement.

Security Enhancements

  1. Legacy Browser Component Retirement
    The deprecated browser component that exposes an authenticated request interface is being replaced by the modern component already present in the app. Completing this transition would eliminate the risk associated with the legacy code path.

  2. Brokerage Authentication Permission Hardening
    The eMakler brokerage sign-on data storage uses a permission level that any third-party app can request from the user. Upgrading to a signature-level permission would restrict access to apps signed with mBank's own signing key.

Technical Context

App Type: Financial services - mobile banking (high sensitivity)
Classes Analyzed: 86,000
Third-Party Services: 18
Context Tags: financial, sensitive_data


About This Analysis

This security analysis was conducted by CITT (Can I Trust That), an independent security analysis service. We perform static code analysis on Android applications to help users make informed decisions about app security and privacy.

App Details

Developer: mBank S.A.
Version: 3.119.0 (versionCode: 94785)
Analysis Date: 2026-06-13
Package: pl.mbank

Analysis Limitations

  • Static analysis only (code review without running the app)
  • Based on APK version 3.119.0 analyzed on 2026-06-13
  • May not reflect server-side security controls
  • Cannot detect all runtime behaviors

Versions & scan history

ScanDateOverall score
#1 (current) 86/100