I wonder what the security flaw was? It is interesting that all the customers are still allowed to use their cards for cash withdrawals and payments, and they can all still log in to their online accounts. There doesn't seem to be any mention of a system-wide password reset. So... it sounds like there wasn't a widespread theft of account credentials, and that the attack was some kind of weakness in the bank's online…
could be entirely a software bug? Though I tend to agree that it looks worse than that.
/transfer_money?from_account=NNNN&to_account=MMMM&amount=$$$$
It would actually be really interesting if they faxed in transfer forms or something.