it seems to be money transferred from accounts (£600 mentioned as an amount). But to set up 20,000 new transfers, and extract money from them, without 2FA, and without tripping any number of alarms is a terrible failure in security. This will massively affect their provider fiserv, their internal team will almost certainly have to be replaced and I would be surprised if they don't throw their hands up and go back to…
I don't think encryption levels are anything to do with the fraud problems (at the customer facing end, at least, which I guess you are referring to because of the talk of OTP)