I don't know how things are in the states, but a lot of banks in the UK ask you to input randomly selected characters from your password rather than asking for the whole thing. This suggests they're storing the passwords in the clear. The financial times wrote an article about it recently:
https://www.ft.com/content/33503e4a-8f95-11e6-a72e-b428cb934...