It's a pretty clever idea for the scammers to exploit the in-app notification to fool the end-user. I wouldn't blame them for being scammed in this manner. However, the post then goes on to say:
> Then he asked me to confirm the last 12 digits of my card number, cvv and expiry date.
That to me is a big red flag, and I hope that I would have spotted it if I was the one being scammed. If it was really someone from the bank, they would already have access to this information and wouldn't need an end-user to give it to them.
Although in this case, it may have been too late by that time to limit the damage. They may have been asking for this info as just the cherry on top. I'm assuming that responding to the in-app notification was probably the main thing they needed to extract the savings.