At this stage, if you have to pay the company that leaks your own data to prevent it from harming you, it starts to sound like protection racket.
And regardless of whether you claim the evidence is inconclusive, it is simply not acceptable to dismiss a known vulnerability in something important by saying "I don't know of any case where it has been exploited yet."
I know that flaws have and will continue to be discovered in those authentication systems, and also that a theoretical shift in liability occurs. Any bugs will need to be fixed, and that's important. But you can't ignore the situation in practice – liability is not being shifted, and all UK banks and credit card providers are pretty happy to refund fraudulent transactions regardless.
Does your statement about UK banks no longer shifting liability apply in cases of fraud against merchants?