Your Bank May Be Sending Your Loan Details to TikTok Without Knowing It

New research finds that tracking tools baked into banking websites are quietly forwarding customers' personal and financial data to advertising platforms, sometimes before anyone clicks 'accept cookies'.

ThreatVectr Newsdesk· 4 min read
Full-frame edge-to-edge photoreal editorial image of a glowing data pipeline made of fiber-optic strands flowing from anonymous storefront silhouettes into a ce
Share

Key points

  • Jscrambler documented 14 financial services cases in Europe and the US where customer data leaked through third-party tracking tools embedded in bank websites.
  • Tracking fired without a valid consent choice at nine separate companies, either before the cookie banner appeared, after users rejected tracking, or despite an 'essential cookies only' selection.
  • A Spanish bank sent hashed customer email addresses and phone numbers to TikTok during a mortgage application, despite TikTok not appearing anywhere in the bank's privacy policy.
  • A Portuguese bank transmitted a customer's name, age, tax identification number, and a Salesforce account key during an account-opening process.
  • Several tracking requests began before any consent was offered, or restarted automatically when a user moved to a different section of the bank's website.

Your bank's website almost certainly contains code it did not write. Tiny invisible programs called tracking pixels, which are small pieces of code that advertising platforms use to record what you look at and what you do online, are standard furniture on most commercial websites. On a retailer's homepage, that is mildly irritating. On a mortgage application form, it is something else.

Security firm Jscrambler published research this week showing that banking websites in Europe and the US are firing these trackers in ways that send genuinely sensitive customer data to companies including Google, Meta, TikTok, LinkedIn, Salesforce, and Adobe. The research, first flagged by Dark Reading, covered 14 financial services cases.

How did customers' private details end up with advertisers?

The short answer is default settings. When a bank drops a standard advertising pixel onto its website, that pixel often comes pre-configured to grab and transmit whatever personal data it can find, including names, email addresses, and phone numbers. The bank's web team may never have switched that feature on deliberately. It was simply on.

Jscrambler watched one Spanish bank run a standard cookie-consent banner during a mortgage application. The user accepted. TikTok's pixel then collected the user's hashed email address and phone number, where "hashed" means the data was scrambled with a mathematical formula rather than stored as plain text. Scrambling is not the same as encryption. With enough data and the right tools, hashed values can sometimes be matched back to real people. TikTok does not appear anywhere in that bank's privacy policy. The customer had no way to know.

A Portuguese bank skipped even the hashing step. During an account-opening flow, a tracker sent a customer's email address, name, age, and Portuguese tax identification number to Salesforce in plain, readable text inside a web request.

A separate Portuguese credit provider sent Google Analytics a full web address from a loan application page. That address contained the loan amount, the repayment term, and a note that insurance had been selected.

Who is to blame? TikTok and Meta have previously said advertisers control how the pixels are configured. Jscrambler pushes back on that, pointing out that many of the data-grabbing features are switched on by default, which means a bank that simply copies the standard pixel code into its website is inadvertently collecting far more than it intended.

For customers in Europe, several laws are directly relevant here. The General Data Protection Regulation, Europe's main privacy law, requires organisations to handle personal data carefully and with proper consent. The ePrivacy Directive covers cookies and tracking tools specifically. France already fined Google 100 million euros and Amazon 35 million euros in 2020 for dropping advertising cookies without clear explanation or consent.

If you have recently opened an account, applied for a loan, or used an online mortgage calculator at a European or US bank, your details may have reached advertising platforms without your knowledge. There is no simple fix on your end, but it is worth being cautious about sharing more information than a form strictly requires.

Jscrambler recommends banks audit what third-party code is running on their most sensitive pages, enforce consent rules across every section of their website, and switch off automatic data-collection features that go beyond what the bank has explicitly approved.

© 2026 Threat Vectr