Lots of scams want your bank details. Unlike with SMS 2FA where the phone company never offered their service as a magic universal authenticator, the scammers want your bank account because it's a bank account. To the extent such scams work, we should be pretty unequivocal that it is your bank's fault. Banks are always reluctant to put
their hands in their pockets when it comes to meaningful security. Whereas merchants and customers must upgrade to satisfy PCI DSS rules the banks gave themselves an unlimited free pass to just do whatever they wanted under PCI DSS because hey, those upgrades look expensive, we'd rather not bother.
My good bank actually has security. I'm fairly confident that I couldn't sleepwalk into giving bad guys access to the funds in that account by whatever means. I have a physical authenticator device to get into their online banking site, for example, so your scam would need to persuade me that I need to go get the authenticator and use that to sign in, all more chances for me to realise it's a scam.
But I have two other bank accounts, which both still think passwords are a pretty good level of security in 2021. One of them even lets me sign in using a numeric PIN, presumably they feel they've done enough to protect against brute force and so this is fine.