1. The bank won't chase you for what you've done. You have nothing the bank wants. The bank's legal team have bigger fish to fry. It's not cost effective for them.
If you want to walk away from this and forget about it, no-one will ever bring it up.
2. Nothing will happen between the bank and the consulting company. If you want to make life interesting, you could send an anonymous tip to the bank's auditors (likely to be Deloitte or KPMG). There will be a slap on the wrist for the consulting company, and they will be forced to put in some kind of better access control. Which they will then bypass unless the auditors come looking.
3. The only issue for you is getting your contract paid out.
If you and the consulting company's contract can be heard in Australia, you could try small claims court. There might be an equivalent in your own country if not. This is cheaper for the litigant and doesn't require legal representation (in Australia). There will be a process to follow (send a letter of final demand, etc. etc.).
I've never had to execute a small claims court case, because just the threat of it is enough to make most companies behave themselves and act like adults and negotiate sensibly.
In your case, the consulting company doesn't want it announced in court that they are violating the security of their customers (and that the reason you couldn't complete the contract was because you didn't want to be complicit in it). That costs them more than paying out your contract. Therefore they will settle before it gets in front of a judge.
But getting there will take weeks and months of heart-ache and stress. Decide whether it's worth it.
Just my $0.10 from 20 years doing consulting work with large enterprises.