"How do they get the data" doesn't seem mysterious once you give them your logins. "Is this safe and why or why not" is the question I'd be much rather have answered.
I think this would be illegal in the UK under Computer Misuse Act, or somesuch, as it's unauthorised access to a computer system; the user doesn't have the authority to grant others access.
curl -d "username=foo&password=bar" https://yourbank.com | grep balance