It may not be a perfect system but it has worked for me and I don't worry too much if a large website gets hacked.
This has nothing to do with a debit card. They called int the bank, authenticated using the Experian data, changed my contact info and set up the P2P transfer. How the bank allows all that based on a phone call is beyond me.