Regulators take aim at banking app security, and many are still unprepared

Regulators take aim at banking app security, and many are still unprepared

Mobile banking fraud is booming. After years of development, the players, processes and technologies have developed to create a veritable criminal industry around mobile banking exploitation. Kern Smith, Vice President, Global Solutions, Zimperium, explores the radical developments in mobile banking fraud, and how efforts to resist it now need to focus squarely on the mobile device.  

The banking and financial services sector may be among the most regulated industries in the world. It’s easy to see why – these are the institutions that underpin the global economy. Failures to protect personal data, to transact with integrity and or to understand who their customers are could pose significant systemic risks.

Yet something is changing in the way that regulators police these institutions. While banking security regulation has traditionally focused on the perimeter security of these institutions, regulators around the world are now focusing on the modern centre of personal banking: the mobile device and the applications within.

The mobile app is the new bank kiosk

The rise of the mobile app has had a groundbreaking effect on banking. While only a few decades ago, high street banks would have been populated with lines of customers – all looking to deposit or withdraw funds from their accounts – those queues and kiosks have now been replaced by proprietary applications used to manage customer accounts.

The rise of Open Banking has meant that a whole new industry of third-party banking software providers has emerged in its wake. Banking apps are now a fact of life. In fact, according to Zimperium’s 2026 Mobile Banking Heist report, 54% of consumers say that mobile apps are now their primary means of managing their bank accounts. Crucially, that figure has doubled since 2017.

That’s unlocked new efficiencies and flexibility that can be felt across the entire global economy. However, as with all such developments – the emergence of a new technology, for threat actors, means the emergence of a new attack surface. As cybercriminals increasingly adopt a mobile-first attack strategy, banking applications and the devices they run on have become highly attractive targets for fraud, malware and account takeover attacks.

Every silver lining has a cloud

Zimperium’s Mobile Banking Heist report shows that 80% of fraud now happens either online or mobile platforms. Indeed, mobile banking app exploitation is booming.

Banking trojan attacks on Android – the globally dominant OS – rose by 56% in 2025 while the number of unique trojan banker installation packages rose by 271% in 2024, signifying not just a growth but diversification in this illicit practice. Indeed, one in 20 verification attempts are now deemed fraudulent.

Unfortunately, many organisations continue to leave exploitable weaknesses within their mobile applications. Over half – 60% – of mobile banking apps lack basic code protection, leaving their architecture and logic open for attackers to study. In turn, attackers use that information to build malware that can successfully exploit those mobile banking apps. That will include tampering with the app, or copying and repackaging it, such that malicious versions can then be distributed to unsuspecting users. As a result, the mobile banking app has effectively become a significant centre of risk for banks and a huge opportunity for threat actors.

Regulation

It’s against that backdrop of rising attacks and lowered defences that regulators are focusing on mobile banking applications.

This isn’t isolated to one country or region but is happening across the world. In the European Union – often a leader in international security regulation – DORA and PSD3 govern a new generation of rules around mobile banking applications. DORA compels financial institutions to incorporate security measures directly into their banking applications, such as anti-tampering, reverse-engineering and API hardening. PSD3, on the other hand, as a direct continuation of the EU’s flagship Open Banking regulations PSD2, will require firms to harden the apps they produce, and require biometric access controls, device binding and dynamic linking, so that authentication is tied to individual transactions and payees.

In other parts of the world, national authorities have already set in place a wide range of statutes that demand similar measures around banking apps.

Under new rules from the Central Bank of the United Arab Emirates (CBUAE), banks are to rid their apps of SMS one-time-passwords for authentication and move towards app-based authenticators and device passkeys by 2026. In Singapore, both the Monetary Authority of Singapore’s Technology Risk Management Guidelines and Safe App Standard 2.0 require that banking apps maintain malware detection, anti-screen capture technologies and secure device binding. Next door in Malaysia, new fraud standards will require that banking apps be tied to one user and device, preventing tactics like session token hijacking. Hong Kong now requires financial institutions to actively block screen mirroring and scan for rooted and jailbroken devices.

The Reserve Bank of India’s (RBI) Digital Payment Security Controls explicitly demands code obfuscation for apps, as well as Anti-Tampering measures.

As authorities start to understand the scope of the banking app problem, pressure is growing on banks to carry out hard measures to police these ever more central parts of modern banking.

The buck stops at banking app development

Regulation in this sector may have salutary effects, but banking app developers still need to go beyond the most basic compliance expectations. 

The first crucial step is to prevent reverse-engineering by attackers. This can be achieved by hardening the app’s code, making it impervious to static analysis. Furthermore, the embedded keys and business logic need to be protected and obfuscated so that they can’t be gleaned through outside analysis.

The runtime integrity of these apps is also a crucial point of focus here. Modern attackers work in runtime, where they intercept authentication factors and hijack active sessions, while the app appears to be functioning entirely normally.  To that end, defenders need to be able to detect tactics such as code injection and hooking attempts while blocking overlay attacks, keylogging and screen capture attempts. All the while, they need to maintain the ability to terminate session manipulations before fraudulent transactions can be executed.

Of course, the banking apps in question run on customers’ and employees’ personal devices which are generally beyond the control of the banks themselves. Still, attackers are increasingly using capabilities which grant them full remote access to those devices, while mimicking legitimate user behaviour.

App developers should then be proactive in identifying rooted, jailbroken and compromised devices, concentrating visibility directly on the endpoint itself to catch active malware and fraud. By the same token, they should be able to terminate sessions remotely as and when suspicious activity is detected.

Traditional approaches to security and banking regulation have often failed to address the dawning reality of both mobile threats and banking. In turn, they’ve missed the critical locus of defence: the mobile device itself and the applications within. New global regulations will help push banks and financial institutions in the right direction, but these organisations need to still be pro-active against a widening horizon of threats that attack bank customers and institutions directly through their mobile applications.

Browse our latest issue

Intelligent Fin.tech

View Magazine Archive