Your Bank May Leak Your Data to Advertisers, Even If You Reject Cookies

New research suggests some financial institutions continued sharing sensitive information with advertising platforms even before users consented… and after they rejected tracking altogether.
We receive compensation from the products and services mentioned in this story, but the opinions are the author's own. Compensation may impact where offers appear. We have not included all available products or offers. Learn more about how we make money and our editorial policies.

Consumers are taught that clicking "Reject all" on a cookie banner protects their privacy. But new Jscrambler research suggests that isn't always what happens.[1]

The security firm analyzed financial institutions across Europe and found multiple cases where websites transmitted customer information to advertising and analytics companies such as Google, Meta, TikTok, LinkedIn and Salesforce — sometimes before visitors made any cookie choice, and in other cases even after they explicitly rejected tracking cookies.

"Tracking pixels were once just a small snippet of code on a webpage to confirm an ad impression or to log a visit," Jscrambler wrote. "What many website owners likely don't realize is that TikTok and Meta's pixels go far beyond traditional tracking tags, collecting user emails, phone numbers, and addresses and turning seemingly anonymous browsing data into persistent, identifiable user profiles."

While the findings focused on European banks, they raise broader questions about whether consumers can rely on cookie banners to accurately reflect what's happening behind the scenes.

In this article
Researchers found customer data flowing to major tech companies
Mortgage applications and account openings weren't off limits
Why this isn't just the banks' problem
What it means for you

Researchers found customer data flowing to major tech companies

Jscrambler analyzed 14 financial institutions and found tracking technologies activated without valid user consent at nine organizations.

According to the researchers, tracking sometimes began before users interacted with a cookie banner, restarted after they moved to another section of the same website, or continued despite visitors selecting "essential cookies only."

"Tracking fired without a valid consent choice at nine separate companies, whether before the banner was actioned, after the user rejected all cookies, or despite an essential-cookies-only selection," the researchers wrote.

The data was transmitted to roughly a dozen third parties.

Researchers also found that "both TikTok and Meta's pixel code can load and begin transmitting data before the website's consent management system has time to block it, meaning information can leave the browser before the user's choice is applied."

In several cases, customer information was either hashed or merely encoded instead of encrypted. Hashed or encoded information can still be linked back to an individual under the right circumstances.

Mortgage applications and account openings weren't off limits

The findings become more concerning because the tracking wasn't limited to generic marketing pages.

In one example, an unnamed Spanish bank transmitted a customer's hashed email address and phone number to TikTok after the customer accepted cookies while applying for a mortgage. According to Jscrambler, TikTok wasn't listed as a vendor in the bank's cookie or privacy policy.

Another Portuguese bank was found sending even more sensitive information through Salesforce tracking technology. According to Jscrambler, requests included a customer's email address, followed later by their name, age, Portuguese tax identification number, and a Salesforce contact identifier during the account-opening process.

Researchers also found a consumer lender transmitting loan application details to Google Analytics through a URL containing encoded financial information, including the requested loan amount, repayment term, and insurance selection.

As Jscrambler noted, the problem is that tracking technologies originally designed for advertising are now embedded on pages handling highly sensitive financial information.

"Tracking pixels and personalization tags were once simple tools for confirming an ad impression or counting a visit. On a banking website, the same tags now sit alongside mortgage calculators, account-opening forms, and loan applications...They collect contact details, hash them, attach them to persistent identifiers, and transmit product and financial intent to platforms the bank does not control. Most institutions are unlikely to realize how much of this is happening by default."

Why this isn't just the banks' problem

The issue isn't as straightforward as banks intentionally handing customer information to advertisers.

Jscrambler argues many advertising platforms enable features such as automatic data matching by default, meaning organizations may unknowingly transmit more information than they intended after installing standard tracking code.

"A bank that drops in a standard pixel does not intentionally configure it to send a customer's hashed email and phone number from a mortgage page," the researchers wrote.

Instead, the firm says responsibility is shared between website operators and the companies providing the tracking technologies.

Gareth Bowker, head of security research at Jscrambler, told Dark Reading the problem crosses multiple disciplines: "At its root, it's a third-party risk problem: code the organization does not write or fully control is executing on its most sensitive pages."

Bowker added that it quickly becomes a privacy issue when personal information is transmitted without meaningful consent and a security issue because sensitive information can end up in third-party systems.

What it means for you

This research doesn't mean every bank is secretly sharing your financial information with advertisers. It does, however, serve as a reminder that clicking "Reject all" on a cookie banner doesn't necessarily guarantee that your privacy preferences are being enforced exactly as you expect.

Modern websites often rely on dozens of third-party scripts for advertising, analytics, personalization, and customer support. Jscrambler says many organizations understand that tracking pixels measure conversions but may not realize how much additional customer information those tools can collect automatically through default settings and third-party integrations.

If privacy is a priority, security experts generally recommend:

Jscrambler also says organizations should continuously monitor how tracking pixels behave after they're installed rather than assuming default settings align with their privacy policies.

"It is the responsibility of every organization to ensure that the tracking pixels it implements on its website are configured correctly to close the gap between what it is permitted to do and what it is actually doing."

The research underscores a broader question for internet users. Are cookie banners giving people meaningful control over their personal data, or simply the appearance of it?

#1 Adblocker — Even Blocks YouTube Video Ads
5.0
Editorial Rating
Get Deal
On Total Adblock's website
2026 Editors’ Choice
Best Overall Ad Blocker
Ad Blocker
Total Adblock
PROMOTION: Get 80% Off
  • Top ad blocker that historically scores 100/100 on AdBlock Tester, passing every banner, interstitial, pop-up, and contextual ad test
  • Successfully blocked YouTube ads in our testing, one of the trickier platforms for ad blockers to handle consistently
  • Works across Chrome, Edge, Safari, and Opera, plus Android and iOS mobile apps

Author Details
Thomas Kent is a multi-disciplined reporter with over a decade of experience covering online platforms, digital trends, and consumer-facing tech. Tom focuses on digital privacy, data tracking, and user behavior, with a particular interest in how cookies, online surveillance, and platform design shape the modern internet experience. His reporting takes a research-driven, news-focused approach, translating complex technical topics into clear, accessible insights.

Citations

[1] Beyond Analytics: The Silent Collection of Commercial Intelligence by TikTok and Meta Ad Pixels