> Me: (that number, by itself, is useless).
and
> Once I gave my member number, the attacker used the password reset flow to trigger a text message from the bank. > They used this to gain access to the account.
What happened here? How does an exposed useless member number trigger a password reset? Would the reset request not have come to an email account, presumably a well-protected one?