Le Lézard
Classified in: Science and technology
Subjects: Photo/Multimedia, Product/Service, Survey

Approov Mobile Threat Lab Finds 92% of Popular Fintech Apps Immediately Expose Valuable, Exploitable Secrets


Approov, the end-to-end mobile security provider, today issued findings showing that 92% of the most popular banking and financial services apps contain easy-to-extract secrets such as API keys, which could be used in scripts and bots to attack APIs and steal data, devastating consumers and the institutions they trust.

The Approov Mobile Threat Lab downloaded, decoded and scanned the top 200 financial services apps in the U.S., U.K., France and Germany from the Google Play Store, investigating a total of 650 unique apps. Ninety two percent of the apps leaked valuable, exploitable secrets and twenty three percent of the apps leaked extremely sensitive secrets.

As well as immediately exposing secrets, scans also indicated two critical runtime attack surfaces that could be used to steal API keys at runtime. Only 5% of the apps had good defenses against runtime attacks manipulating the device environment and only 4% were well protected against Man-in-the-Middle (MitM) attacks at run-time.

"Have we all unknowingly become beta-testers for financial services apps? Is this putting our personal finances at risk? Continuing news about breaches seems to indicate this is the case and it is unacceptable!" said Approov CEO Ted Miracco.

"This research shows hardcoding sensitive data in mobile apps is widespread and a massive problem since secrets can easily be extracted. A simple automated scan can show any threat actor how well protected apps are at runtime. Unfortunately, financial apps fall short," Miracco added.

Other findings:

The Approov Mobile Threat Lab report is available here (https://info.approov.io/secret-report).

The report explains the approach and provides detailed findings. Using this report, financial services teams can replicate tests performed and check the security of their apps without delay.

About Approov

Approov is considered a cornerstone of mobile application security for leading global organizations whose consumer and B2B applications are used by millions annually, including eCommerce, financial services, healthcare and connected car sector organizations.

Approov provides a comprehensive runtime security solution for mobile apps and their APIs, unified across iOS and Android. Mobile apps have become a critical element for every business and unfortunately can expose organizations to breaches, fraud, denial of service, and other forms of API abuse. Approov immediately stops any automated tools or compromised apps from manipulating any part of the end-to-end mobile platform, turning away unauthorized access attempts by scripts, bots and fake or tampered apps.

By eliminating false positives and providing runtime application self-protection (RASP) as well as just-in-time-management of API keys, secrets and certificates, Approov delivers both exceptional operational convenience and highly robust security at scale.


These press releases may also interest you

at 04:09
China and Kazakhstan have always supported each other and have always been partners in times of challenges, Chinese President Xi Jinping said in a signed article in the Kazakhstanskaya Pravda newspaper and Kazinform International News Agency on...

at 04:05
H.I.G. Capital ("H.I.G."), a leading global alternative investment firm with $64 billion of capital under management, is pleased to announce that an affiliate has signed a definitive agreement to acquire CGH Group S.A. ("CGH" or the "Company"), a...

at 03:55
The International Nut and Dried Fruit Council (INC), conducted an extensive study on Latin America's Gen Z dietary...

at 03:44
Truecaller, the leading global platform for verifying contacts and blocking unwanted communication, is publishing its interim report for January-June on Friday 19 July 2024 at 07.30 CET.  Alan Mamedi, CEO and Odd Bolin, CFO presents the report and...

at 03:20
Calliditas Therapeutics AB (STO: CALTX) ("Calliditas") today announces that its partner Viatris Pharmaceutical Japan G.K. ("Viatris") has initiated a phase III clinical trial in Japan with Nefecon, named VR-205 in the Japanese market, in Japanese...

at 03:09
China and Kazakhstan have always supported each other and have always been partners in times of challenges, Chinese President Xi Jinping said in a signed article in the Kazakhstanskaya Pravda newspaper and Kazinform International News Agency on...



News published on and distributed by: