The fact that you choose to use usernames and passwords to authenticate humans is your choice. It is well known that humans don't secure passwords well (reuse, writing on postit notes, etc). As a bank, any losses attributable to someone evil finding/guessing a password are your own.
That's why credential stuffing counts as a breach. Even though most banks will try to tell you that it's your responsibility to protect your passwords, the law doesn't see it that way.