-

Approov Mobile Threat Lab Finds 92% of Popular Fintech Apps Immediately Expose Valuable, Exploitable Secrets

Inadequate Protection of API Keys at Runtime Places Consumer Data and Treasure at Sharp Risk. Stolen API Keys Can be Used to Steal Personal and Financial Data.

PALO ALTO, Calif.--(BUSINESS WIRE)--Approov, the end-to-end mobile security provider, today issued findings showing that 92% of the most popular banking and financial services apps contain easy-to-extract secrets such as API keys, which could be used in scripts and bots to attack APIs and steal data, devastating consumers and the institutions they trust.

The Approov Mobile Threat Lab downloaded, decoded and scanned the top 200 financial services apps in the U.S., U.K., France and Germany from the Google Play Store, investigating a total of 650 unique apps. Ninety two percent of the apps leaked valuable, exploitable secrets and twenty three percent of the apps leaked extremely sensitive secrets.

As well as immediately exposing secrets, scans also indicated two critical runtime attack surfaces that could be used to steal API keys at runtime. Only 5% of the apps had good defenses against runtime attacks manipulating the device environment and only 4% were well protected against Man-in-the-Middle (MitM) attacks at run-time.

“Have we all unknowingly become beta-testers for financial services apps? Is this putting our personal finances at risk? Continuing news about breaches seems to indicate this is the case and it is unacceptable!” said Approov CEO Ted Miracco.

“This research shows hardcoding sensitive data in mobile apps is widespread and a massive problem since secrets can easily be extracted. A simple automated scan can show any threat actor how well protected apps are at runtime. Unfortunately, financial apps fall short,” Miracco added.

Other findings:

  • None of the 650 apps “ticked all the boxes” in terms of the three attack surfaces investigated. All failed in at least one category.
  • Only four apps had runtime protection against channel MitM attacks and “man-in-the-device.” All were payment and transfer apps and none were in the U.S.
  • In general, apps deployed in Europe were better protected than apps available only in the U.S., for immediate secret exposure and runtime protections. This may be due to stricter privacy rules in Europe and more focus on security.
  • Crypto apps were more likely to leak sensitive secrets as 36% immediately offered highly sensitive secrets when scanned.
  • Only 18% of personal finance apps leaked sensitive information, possibly because they are less dependent on sensitive APIs.
  • For Man-in-the-Device attacks, traditional banks are twice as likely to be well protected over other sectors reflecting the use of packers and protectors to protect against run-time manipulation.

The Approov Mobile Threat Lab report is available here (https://info.approov.io/secret-report).

The report explains the approach and provides detailed findings. Using this report, financial services teams can replicate tests performed and check the security of their apps without delay.

About Approov

Approov is considered a cornerstone of mobile application security for leading global organizations whose consumer and B2B applications are used by millions annually, including eCommerce, financial services, healthcare and connected car sector organizations.

Approov provides a comprehensive runtime security solution for mobile apps and their APIs, unified across iOS and Android. Mobile apps have become a critical element for every business and unfortunately can expose organizations to breaches, fraud, denial of service, and other forms of API abuse. Approov immediately stops any automated tools or compromised apps from manipulating any part of the end-to-end mobile platform, turning away unauthorized access attempts by scripts, bots and fake or tampered apps.

By eliminating false positives and providing runtime application self-protection (RASP) as well as just-in-time-management of API keys, secrets and certificates, Approov delivers both exceptional operational convenience and highly robust security at scale.

Contacts

Engage with Approov:
Website: https://www.approov.io/
Twitter: @approov_io

Media Contact:
Dan Chmielewski
Madison Alexander PR, Inc.
949-231-2965
dchm@madisonalexanderpr.com

Approov


Release Summary
92% of the most popular banking and financial services apps contain easy-to-extract secrets that can let attackers steal consumer data and finances.
Release Versions

Contacts

Engage with Approov:
Website: https://www.approov.io/
Twitter: @approov_io

Media Contact:
Dan Chmielewski
Madison Alexander PR, Inc.
949-231-2965
dchm@madisonalexanderpr.com

More News From Approov

Approov Turbocharges Global Security: Cloudflare Argo Smart Routing Halves Latency for Next-Gen Mobile Attestation

EDINBURGH, Scotland--(BUSINESS WIRE)--Approov, a leading provider of mobile app and API security solutions, today announced significant strategic expansion of its global network infrastructure, positioning its unique cloud-based mobile app and device attestation platform as the essential defense against rapidly evolving AI-based API threats. This expansion includes the deployment of Cloudflare's Argo Smart Routing technology across its multi-cloud network, which is supported by Amazon Web Servi...

Approov Launches Next Generation Attestation to Secure Mobile Apps Against Threats from AI and Meet New EU Regulations

EDINBURGH, Scotland--(BUSINESS WIRE)--Approov, the leader in mobile API security, today announced the launch of Approov 3.5, a significant platform update designed to protect businesses and their customers from a new wave of mobile threats. The release directly addresses security challenges posed by regulations like the EU’s Digital Markets Act (DMA) and the rise of sophisticated AI-driven attacks. The mobile landscape is changing dramatically. New rules are opening up app distribution beyond t...

Approov Closes £5M Series A Funding to Redefine Mobile App Security for the AI Era in Round Led by Maven Capital Partners

EDINBURGH, Scotland & PALO ALTO, Calif.--(BUSINESS WIRE)--Approov Limited, a leading innovator in mobile app and API security, has successfully closed a £5 million (US$ 6.7 million) Series A funding round. The investment, spearheaded by the Investment Fund for Scotland, managed by Maven Capital Partners (“Maven”), also saw participation from Souter Investments, and existing investors Lanza techVentures and Scottish Enterprise. This funding milestone enables Approov to bolster its Research &...
Back to Newsroom