They know that you likely read some email from HSBC and if you happen to read the same one again they will know it was the same one.
HTTPS the attackers know a conversation is happening, but no idea what
But, I personally think the threat is being overblown (I am happy to be corrected though)
The main problem seems to be tracking pixel itself to deduce involvement. The suggested approach to send email to confirm email seem better, unless it contains link to login page (as it can be phished). So, the best seems to be that one should send email that explains user how to confirm e-mail by logging manually to the app.