Yes, but supposedly no in the clear passwords were breached?
If they need to log into the banking on someone's behalf, they need to be able to decrypt those passwords. You would be surprised how many people store the encryption keys and salt in the same database.