Even when a bank or organisation does have good general security practices, I have, far too many times, encountered CS agents who have leaked information like sieves - given me multiple attempts on passwords, hinted which address I’ve registered with. I get
why - many people have no idea about any of this stuff, and if CS don’t cut corners they never get to serve anyone. Many, many people I know can’t recall any passwords, and reset them every single time they need them.
I was recently targeted by I-don’t-know-what. Third party opened a fault ticket on my BT FTTC line, and then through a combination of SMS SC spoofing, real links to BT systems, and false links to very plausible looking “book an engineer visit” screens tried to get me to invite a criminal over to play with my technology.
The idea was likely to get me to welcome some unknown party into my home to mess with my router - I would assume putting some kind of packet sniffer in place to skim data and cards - but I honestly have no idea to what ends.
As a general rule, I ignore all communication from banks and service providers, as I’ve nearly fallen for a “card fraud” scam twice - the second time, they already had my card, and had already done some petty fraud that they wanted to talk to me about, with the hope of me giving them access to my online banking. The worst case in ignoring them is that they will try again. If it’s actually important, they’ll keep trying. If it’s fraud, I’ll notice and will contact them.