The fact that you choose to use usernames and passwords to authenticate humans is your choice. It is well known that humans don't secure passwords well (reuse, writing on postit notes, etc). As a bank, any losses attributable to someone evil finding/guessing a password are your own.
That's why credential stuffing counts as a breach. Even though most banks will try to tell you that it's your responsibility to protect your passwords, the law doesn't see it that way.
Technically, Paypal is not regulated as a bank (per FDIC). That said, they certainly have immense fiduciary & privacy duty to their customers considering the format of their business.
PayPal has a banking license in Luxembourg which allows them to operate in Europe.
I guess it depends on the region/country.