Internet banking logins do not just use 4-digit pins. A card, sure. A card you can block/cancel with a phone call for a reason. But to add/remove beneficiaries, make EFT payments, move money around (like EFT the entire contents of your account to another account) usually requires a username...
It is still insecure. Forcing your users to use a 4-digit pin as their password is insanely bad security. Even if it's locked after 3 attempts. I don't know the mechanism for how they determine the lock, or how easy it is to unlock. I still think it's bad security. Especially for a bank account.
If anyone is using the spot money app, I recommended you be very careful what money you put in there.
It only uses a 4 digit pin to access your account. Literally, no password, no 2fa, nothing. Imagine signing up for a website and it forced your password to be a 4 digit number! And its not just...