If it's "completely insecure," then why aren't there reports of people correctly dialing their banks phone number and being connected to a scammer?
To change the routing of a call other than yours would require you to access a carrier's systems and change where the call is routed to--which is substantially more difficult.
phone - I dial the number my bank gave me and no man in the middle ever answers or interrupts. But still completely insecure!
Now imagine you see me trying to enter my credentials over an http connection to AwfulBank.com. "Stop! That's completely insecure!" you say. "Sure, but so is calling a bank using the phone number they gave me."
If both cases are already completely insecure, why am I wrong?