Rather than having strict regulations to require password or OTP, the US has strict regulations that require banks to reimburse consumers for any credit card fraud.
I’ve had it happen a couple of times. It’s a minor inconvenience to switch over any subscriptions to a new card, but it has never cost me a penny.