The fundamental reason why this is a big deal is that in the UK, the repercussions of fraud are skewed towards customers rather than the banks. The relevant legal standard is that customers must exercise "reasonable care" with their PIN if the bank is to bear the cost of fraud. Of course, banks always insist that their systems are secure, and that it was the customer's fault. http://www.timesonline.co.uk/tol/money/consumer_affairs/arti...
The Cambridge team has been investigating vulnerabilities in the EMV standard underlying Chip and PIN (ubiquitous in the UK) for a long time.
From 2006: http://www.lightbluetouchpaper.org/2006/03/15/chip-and-skim/
If I understand correctly they first started to find serious vulnerabilities in 2009.
Blog post: http://www.lightbluetouchpaper.org/2009/08/25/defending-agai...
Paper: "Optimised to Fail: Card Readers for Online Banking" http://www.cl.cam.ac.uk/~sd410/papers/optimised_fail.pdf
Media: http://www.youtube.com/watch?v=U1QAnb-wnTs
They escalated that attack in 2010. http://www.lightbluetouchpaper.org/2010/02/11/chip-and-pin-i...
Paper: http://www.cl.cam.ac.uk/~sjm217/papers/oakland10chipbroken.p...