I wonder what the security flaw was? It is interesting that all the customers are still allowed to use their cards for cash withdrawals and payments, and they can all still log in to their online accounts. There doesn't seem to be any mention of a system-wide password reset. So... it sounds like there wasn't a widespread theft of account credentials, and that the attack was some kind of weakness in the bank's online…
The types of 2FA vary dramatically between banks. Some use an SMS OTP but as we know phone numbers aren't secure [0]. Most use a card reader but they often do this differently. Some use the 'identify' function to log on and the 'sign' function for payments (as designed) but others use the 'respond' function for everything. The danger in using 'respond' for payments is that the account and amount aren't entered into the card reader so you don't know what you are authorising.
If Tesco have a flaw in how they are using 2FA, by only using 'respond', then local malware could intercept genuine payments, alter the account/amount details, and get the user to authorise this. Or Android malware could intercept SMS messages. N.B. This assumes the issue is in the faster payments system but it could be in the payment card system. It appears cash points still work but this is a separate system to debit card payments.
From what I've read no one will lose money but having transactions frozen is still a big inconvenience. As mentioned elsewhere here, this is why it's a good idea to have many different bank accounts from various parent institutions (also important from a deposit guarantee position). Some banks share the same infrastructure and liability. Always have some cash available too, although that is getting harder to spend everywhere [1].
[0]: https://unop.uk/phone-numbers-for-examples-and-user-identifi...