I wonder what the security flaw was? It is interesting that all the customers are still allowed to use their cards for cash withdrawals and payments, and they can all still log in to their online accounts. There doesn't seem to be any mention of a system-wide password reset. So... it sounds like there wasn't a widespread theft of account credentials, and that the attack was some kind of weakness in the bank's online…
Disclaimer : I don't use Tesco Bank so this is just speculation and some observations. The types of 2FA vary dramatically between banks. Some use an SMS OTP but as we know phone numbers aren't secure [0]. Most use a card reader but they often do this differently. Some use the 'identify' function to log on and the 'sign' function for payments (as designed) but others use the 'respond' function for everything. The dang…
If tested systems that allow you to transfer money between accounts, if you can bypass the initial authentication you can transfer money without needing to use 2FA or generating a TUN code.
And these systems can be breached.