ACH & SEPA are payments rails, which facilitate the interbank transfer of money. So for example, the app you have given permissions to make transfers to will request a transfer through the open banking APIs to your bank, then the bank itself will use the payments rails to process the transfer.
GSM, SS7, etc. are massive privacy holes _by design_.
The whole purpose of mobile networks is to track a devices location (so you can route data to/from it!). Of course its easy to do it if your the operator or someone who has compromised it.