If the user used a simple password, or gave the password to someone else, or gave the password to the bank customer service people, or replied to a fraud email with the password, or entered the username and password at a phising site etc etc, then that is not really a bank security issue.
That is different from saying the bank system has been compromised. If there was such a security breach, many more acounts would be affected and much more money would have been lost.
The message you posted above, is it a fraud message received and the users followed the instruction and gave away their username and password and thus they lost money from their accounts?
I guess it is because this link does not work.
OpenDNS
So it looks like someone setup a phising site and users provided login information there. If so, again, this is not the bank site being hacked. Please correct me if I am wrong.