I'm not sure if you're aware, but Europe has proper 2FA in the form of a dongle type device, and not this SMS BS many companies in the US use out of laziness. They also need to use this device for not just online banking, but basic everyday transactions.
If theft through online banking even exists, it's at such a low volume as to be irrelevant. Most online banking interfaces are a read-only view of recent transactions. Some provide the ability to transfer funds between your own linked accounts at the same bank. Fewer still provide bill pay for a specific set of partner institutions, and a tiny proportion of the most technologically sophisticated banks provide the ability to transfer money to any arbitrary person. When they do, adding a new payee is loud (sends a bunch of notifications) and requires SMS verification and/or digits off your debit card. The transfer is loud and takes several days to actually happen (so you can cancel it), and is limited to a couple thousand dollars at most. This is a fringe thing that a handful of people use occasionally. Most peer-to-peer transfers are going to happen through Venmo, which piggy-backs off a debit card, or through paper checks. Most online bill pay is going to happen by giving the biller your account and routing number.
The largest vector by far for stealing from a bank account is capturing a debit card number in some legitimate transaction, and reusing it to make fraudulent transactions. The strength of the communication channel between payer's bank and payer is irrelevant, because you don't get to weigh in on debit card transactions (or checks) against your account. They just happen, and then you can dispute them later.
In the country where I live all internet banks supports this. And all of course use 2FA. Most if not all banks here let's me do any kind or transactions. Not just viewing my data but transferring money, buying stock, setting up new bank accounts, pension management and everything else.
Maybe it's the lack of security at your place which prevents useful functionality.
Phishing and other things were a large attack vector until 2FA mostly did away with it.
In the US, it isn't. On the off chance that the capability is there, it's seldom used. You make transactions by telling the other party your account number.
If someone would hack my online banking account they could do quite a few nasty things...
What year is this, 1997? Is this normal in the US? I'm beyond amazed. Using online banking for transferring money is such a normal activity here (has been for at least 10 years).
In general I think the US is comfortable to limp along putting band-aids on broken systems, because the failings are seen as being intrinsic to the "natural state" of things (see also: common law and court precedent reigning), and the losses are ultimately sustainable. The possibility of a fraudulent transaction can never be eliminated, so therefore it's whatever party facilitates/blesses the transaction that fully bears the responsibility. Meanwhile the EU doesn't seem afraid to create new foundational semantics - eg get rid of the concept of "pulling" money, and then dictate that banks cannot charge customers for the equivalent of initiating an ACH push [0].
[0] Bank of America actually charges for this. They also charge for walk-in cashing of checks drawn on themselves - meaning they are inducing their own customers to write fraudulent checks!
Also, something you said in a related comment:
> tiny proportion of the most technologically sophisticated banks provide the ability to transfer money to any arbitrary person
My experience is that every US bank has an "external account" transfer feature (for use with your other accounts) that can initiate ACH credits or debits, as well as a "Bill Pay" that will do ACH credits to any routing/account number. But (as I alluded to) banks limit the dollar amount of transactions initiated through them, as they are responsible for cleaning up any mess due to "fraud".