But then... Direct Debit guarantee... so everyone would get their money back.
You'll get it back. Eventually. Meanwhile the loss of money from your account could cause other regular payments to fail incurring charges (and hassle) that you won't be able to claim back.
Remember Clarkson's boast that publishing his account number and sort-code wouldn't lead to any problems? https://www.theguardian.com/money/2008/jan/07/personalfinancenews.scamsandfraud
No, I meant that with account number and sort code PLUS with the other personally identifiable details, hackers could use this set of data in social engineering scams for direct debits or whatever. Not the attack itself but what the combination of data could be used for.