Like, I know intellectually that this must happen, but my experience (which tilts much more to investment banks, to be fair) is that an FTP server with plaintext files is much more common.
I can confirm that banks do this. They do ftp as well but to exchange credentials they’ll use PGP. The hardest part is identity verification which is often done with a phone call.