The dataset for hashed credit card numbers is small enough that it can be easily represented in a static lookup table, or brute forced.
So providing a hashed card number to a potential scammer is just as bad as providing the card number.
You can still get targeted for a direct attack but much less likely to end up caught in a dragnet approach.
Keep in mind this in the context of an account holder asking the bank to authenticate themselves on a phone call using data only the bank and the account holder should know. sha256(card number) was an example of something that is obviously inappropriate, and I don't think sha256(card number + salt) is any different qualitatively.
> That would prevent using a pre-generated lookup table
Only for a healthy pinch of salt, not a couple grains, right?