- What Santander stores in a cookie?
- Full name
- PAN (Credit card number)
- Bank account number and sort code
- Alias
- User ID
Santander cookies are removed when you close browser, but data isn't removed after clicking "Logout" — so cookies can be read also if you logout, but do not close browser.
Cookies with data:
rinfo
NewUniversalCookie
The data of the second cookies is XML coded in base64, so here can be another susceptibility
In Privacy Policy is written that cookies don't contain personal data.
More informations: http://seclists.org/fulldisclosure/2012/Oct/101