In a largely cashless society like the UK, ‘banking apps’ are effectively people’s wallets. Knowing you got paid, being able to pay your rent, being able to pay for goods and services… seem like pretty everyday concerns.
That's going to be a problem when the UK faces sustained service disruption attacks. Building fragile systems like this during peacetime is usually an ill-informed bet.
[dead]
All of that can be handed via your bank's website, ATMs, a credit card, or even (god forbid) writing a cheque.
If you're bored, have Claude pull apart your APK and do a privacy report.
Your banking app is almost certainly using a company like (horrible and evil) Yodlee, which is given data by your banking app under the guise of "organizing your transactions into categories". Yodlee then quickly de-anonymizes it, by the identifiers which are identical and given to firebase, and various other orgs. Yodlee has been caught doing this before, and they still operate.
Lots of other companies do this, so if your banking app has any callbacks to anywhere but the bank itself, it's nothing but trouble.
After deanoymoization, such data is of course sold to everyone, including intelligence agencies, domestic and foreign.