One thing I don't see mention regarding the existing US ACH (or whatever interbank) system is that there is absolutely no verification or security in this system. Just like verification of paper check signature and a whole lot of other financial items - most banks allow anything until questioned. The easiest and cost effective way is to let it happen and reimburse for failures.
1. I have linked a non-joint account in my name at bank A to another (non-joint) account of my wife at bank B (accidentally) without any verification of any kind. I call BS on anyone claiming they magically checked the home address link or know we are married.
2. I have walked in to my bank and did a wire transfer of a large amount without any kind of verification. They didn't check my ID. I am not kidding. I did enter my ATM card and PIN. Then why do they have a $500 or $1000 limit at ATM. If someone did get my ATM card and PIN, they just had to appear confident and walk in to the branch. This is one of the largest banks in the US.
3. Because my wife doesn't like to deal with customer service of various financial items (credit-cards, 401k etc). I regularly call and just say I am her (clearly feminine name) and the conversation carries on as if nothing is surprising/suspicious.
4. On the other extreme, IRS's "MyIRS" site let us authenticate yourself (first time setup) using a security question that allows one to type any financial account number. CC, Bank, 401k, whatever. I mean how tf did they get all that data on me? legally? Why does IRS need my CC number?
IMHO, the only thing keeping us secure is that nobody from outside US has really tried to mess around with US banks.