In the Swedish supreme court case I quoted above:
Background information:
- Sweden has a public personal identification number for every citizen (except for like 10k people with protected identities)
- The four main banks in Sweden have collaborated to create something called "Bank Id". It's often used as a secure authentication tool combined with the personal identification number (something you have - the cert in the mobile app, something you know - PIN or face id).
Someone convinced an elderly person over the phone to authorize the creation of a new Bank Id on the attacker's phone. This was fairly complicated and required the old person to use their physical RSA SecurID token. The court found that the elderly person had behaved reasonably well and that the attacker was very competent.
Still, the supreme court felt that the bank should have been more careful about letting strangers steal their money.