Unless you have a very unique login, you are going to often seen login attempts. Common names such as john, john123, john234, johnq, qjohn will happen more often especially for a big site.
This will probably give rise to support calls to the bank...
Then you'll learn that your username is one that's under attack and that it's even more important to have a strong password. Put some useful documentation on the login page that explains it. What's wrong with that?
Have you seen how severely 2FA drops the rate of unauthorized accesses? It's incredible. What have you seen that moves you to hedge on the value of 2FA?
In general, relying on a second factor whose security practices aren't the best, could actually compromise security compared to having a strong and unique password.
I personally wish that more banks would support 2FA authentication using a username/password in combination witH TLS client side certificates.
This will probably give rise to support calls to the bank...