Trust is the True Tipping Point of Mobile Banking Loyalty
By Jason Cortlund, Mobile App Security Evangelist at Guardsquare
Simple Subscribe
Subscribe Now!
A recent article in The Financial Brand proposes that mobile apps have become the battleground for loyalty in the banking industry. “With 50% of digital banking users open to switching for a better experience, the app is no longer just for servicing — it’s where retention and growth are won or lost.” The research they cite suggests that half of customers are readily willing to switch providers for a better digital experience – competitive features, better in-app engagement, and frictionless services.
But the table stakes of mobile banking app loyalty aren’t just a question of an optimized user experience and the latest competitive services. Nor are they simply a functional question of application performance or monitoring customer behavior for warning signs of dissatisfaction.
Bottom line: It’s more broadly a question of earning and maintaining trust.
While mobile banking security is often taken for granted when it comes to the sensitive nature of financial transactions, it deserves equal weight in the customer loyalty equation because it has a direct impact on line-of-business interests. This includes more easily quantifiable security incident costs like chargebacks and regulatory penalties, as well as more abstract damages like app downtime and reputational harm.
Proof point: A recent global survey of 1,360 mobile app developers and security leaders revealed that 65% of organizations have observed customer churn or uninstalls due to security issues.
Customer trust of mobile banking apps depends on a holy trinity of performance, user experience (UX), and security – because each is essential to the ultimate success of the business. Here are a few specific reasons why banking app security, in particular, shouldn’t be left as an assumption or afterthought.
Mobile is Global But Security Worries Remain
The first reason that security should be an equal factor in the trust equation is that mobile banking apps are an expanding target for attacks – and customers are already feeling the heat.
Overall, researchers estimate that 4.2 billion people worldwide use mobile banking, representing about two-thirds (66%) of the global population. Despite rising adoption rates around the world, more than half of all banking customers cite security as a key concern when using mobile apps. Specific regional growth patterns include:
- North America: 76% of adults in the U.S. choose “mobile first” for banking, with roughly 39% of those being exclusively mobile – avoiding physical bank branches altogether. Canadians are increasingly likely to use a mobile app for banking, with 70% adoption last year.
- Europe: Mobile banking penetration across Europe also stands at 76%, with Nordic markets exceeding 87% adoption. The United Kingdom has about 69% mobile banking usage.
- Asia-Pacific: The APAC region generates about $740 billion in mobile banking revenue per year, with 82% of adults in Indonesia and South Korea tying for the highest in-region adopters. China remains the single largest national market with around 860 million mobile banking users. However, cybersecurity and data privacy risks are key challenges across APAC, with the Australian Cyber Security Centre reporting that attacks are rising by more than 30% per year.
- Latin America: The region’s mobile banking revenue grew by approximately 29% to reach $172 billion last year. Brazil records 76% mobile banking penetration, underscoring widespread app-based banking usage.
- Middle East: 83% of adults in Turkey use mobile banking, placing it among the top countries for global adoption.
- Africa: Mobile devices now account for at least 75% of all online banking traffic on the continent. However, 50% of African banks report concerns over malware and fraud, which hinder customer confidence.
As the “mobile-first” banking attack surface continues to grow, bad actors will have greater incentive and more opportunities to exploit mobile app weaknesses.
Fraud Hits #1 with a Bullet
Sophisticated , multi-step fraud attacks surged by 180% last year, and that upward trend is predicted to only get worse. A recent report from INTERPOL notes that new AI-based tools, cryptocurrencies, and Fraud-as-a-service (FaaS) platforms have all helped enable fraud as a global industry. Investigators estimate that AI-enabled fraud attacks are about 4.5 times more profitable than those without AI.
The World Economic Forum’s (WEF) Global Cybersecurity Outlook for 2026 shows that phishing attacks and cyber fraud have overtaken ransomware as the top cybersecurity concern of business leaders.
According to credit reporting agency Equifax, “…mobile app security is often neglected by developers — making apps more vulnerable to fraud.” That analysis seems to be supported by the fact that mobile fraud has been escalating (up 15% year over year since 2020) while desktop fraud is declining, making mobile the primary battleground for digital fraud attacks.
The vast majority (71%) of financial fraud losses today result from compromised credentials and account takeovers (up from less than half of reported incidents in the previous year). Some recent real-world threat examples include:
- Albiriox targeted Austrian users for over 400 banking, fintech, crypto wallets, payment, and trading apps via compromised accessibility services.
- The GoldFactory cybercrime group has staged attacks in Southeast Asia using modified banking applications that act as a conduit for Android and iOS malware.
- DeVixor used phishing to distribute an Android banking malware at scale in Iran.
It’s also worth noting that most consumers expect protection and control from their financial institutions: 68% view fraud alerts as a necessary feature of the mobile experience.
Compliance Complexities
The pervasive fraud problem has been a major driver for new or updated financial services industry security standards and regulations around the world. For example:
- PCI SSC Secure Software Standard v2.0 (global): The Payment Card Industry Security Standards Council (PCI SSC) recently published the first major revision to their Secure Software Standard. This helps assure that software is designed, developed, and maintained in a manner that protects payment-related data and functionality. One new addition is that software development kits (SDKs) are now eligible to be assessed.
- PSD3 and PSR (EU): The new Payment Services Directive 3 (PSD3) and Payment Services Regulation (PSR) bring significant changes to fraud prevention, ensuring better protection for consumers and more robust mechanisms for financial institutions. PSD3 mandates proactive mitigation strategies, such as real-time transaction monitoring.
- DORA (EU): Introduced last year, the Digital Operational Resilience Act (DORA) provides a standardized risk management framework for European financial institutions.
- GLBA (US): The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect customer data and systems, which extends to protection for mobile banking applications.
- RBI (India): The Reserve Bank of India (RBI) maintains comprehensive cybersecurity requirements for digital payment applications (including banks).
- MAS (Singapore): Monetary Authority of Singapore (MAS) regulations address risk management for banks, including mobile security requirements.
Setting aside the pressure of financial penalties that might come with a compliance violation, many organizations are struggling just to keep up with the complexities of implementing these new requirements. In fact, compliance ranks as the top challenge for financial institutions when dealing with fraud – ahead of reimbursing losses and increasing threat sophistication.
You Can’t Win Loyalty with Compromised Security
Loyalty is ultimately earned through trust. Mobile banking trust is built when the app performs as expected, when it delights the end user with convenience and thoughtful capabilities, and when it keeps transactions and data secure from fraud attacks.
Unfortunately, most developers today feel forced to compromise on mobile app security in order to meet increasingly aggressive delivery cycle goals, and widening adoption of AI-assisted coding tools are only increasing those expectations. The vast majority (79%) of mobile app developers cite time-to-market pressure as the top barrier to stronger protection – and more than half (57%) admit shipping code they knew was vulnerable due to deadlines.
But in order for security to hold its rightful place in the trinity of trust, dev teams need purpose-built tools for mobile app testing and protection that don’t slow down delivery cycles, impede application performance, or negatively impact the user experience. Here are some best practices for achieving this kind of a unified DevSecOps pipeline:
- Automate your testing: Choose purpose-built mobile application security testing (MAST) tools that align with OWASP guidelines for continuous, automated code analysis to help fix security issues in-context. Research shows that automated testing delivers faster release cycles.
- Step up your protection: Multi-layered code hardening (obfuscation) makes it significantly more difficult for attackers to reverse engineer and tamper with your mobile banking apps. Runtime Application Self-Protection (RASP) enables apps to detect and respond to fraud attacks at runtime.
- Establish real-time visibility: Once an app is released, you need threat monitoring and detection capabilities to help identify suspicious user behavior. Real-time threat data lets you see which tools and tactics attackers are employing against your mobile apps, so you can then quickly adjust your protections as needed. These capabilities can also be invaluable when proving regulatory compliance.
- Add mobile API security: When it comes to fraud protection, your client-side banking app is only half the story. Backend/API abuse is increasing for 82% of organizations and 44% of all advanced bot activity now targets APIs. To prevent fraud, you need to block non-genuine (e.g., cloned or modified) mobile apps and malicious bots from interacting with your APIs with dedicated application attestation capabilities.
