Earlier quoted context omitted.
Doubt over 5 people log in to a single bank from most starbucks over a 24 hour period. If it's a big enough bank, the threshold should be higher. But they can easily pull the data and set a threshold that cuts off only the peak of the distribution
You'd certainly better hope so. A national bank going down is national news. You're gonna end up sending some muckety muck out to the press to bob their heads and apologize. They'd don't take kindly to that. My prior investigations suggest that this strategy is ineffective. You suss out a ratelimit then pick a CSP and start spawning instances. Bonus points if it's a CSP that has a contract with that bank, they'll be…
A lot of the measures taken to prevent fraud also block proxies and the like.
Re customer service: they say "here's how you can download your statements in pdf format", or for many banks in quickbooks/excel/etc format as well
I don't know how many of them had mandatory 2FA then, but I think many more have now. It would be far less risky to invalidate cookies on those high-volume IPs and force a new 2FA validation. Then legitimate users could reverify.