A common issue of banking websites is that they force weak passwords, but I rarely hear about banking websites being "hacked". Why?
Accounts also have plenty of protection besides the password: IP is logged, if it's not the usual IP my bank asks a secret question, and after 3 failed tries it locks out the account until you phone them, succeed at getting a human on the line and explain your situation. You can't brute-force much in 3 attempts.