They force weak passwords for the users, not for the admin, so you could hack an account but not the website itself.
Accounts also have plenty of protection besides the password: IP is logged, if it's not the usual IP my bank asks a secret question, and after 3 failed tries it locks out the account until you phone them, succeed at getting a human on the line and explain your situation. You can't brute-force much in 3 attempts.
Comments
A common issue of banking websites is that they force weak passwords, but I rarely hear about banking websites being "hacked". Why?
They force weak passwords for the users, not for the admin, so you could hack an account but not the website itself.
Accounts also have plenty of protection besides the password: IP is logged, if it's not the usual IP my bank asks a secret question, and after 3 failed tries it locks out the account until you phone them, succeed at getting a human on the line and explain your situation. You can't brute-force much in 3 attempts.