How about if there was a supply chain attack on the bank’s software?
A hack is a hack. A single point of failure is actually worse for everybody.
There are many, many technical means available to do this. I usually control security on my server...