It would be better if banks educated customers on best practices such as "don't trust anything on a different domain" and "only provide PII for verification if you are the one initiating the call". Of course, both of those would require that banks stopped engaging in those two practices which make legitimate interactions indistinguishable from phishing.