Seems like they clocked his pin and used that to unlock his phone (phone will fall back to pin once facial recognition failed) and his bank account (or found his bank account pin on his device). On discovering it was lost he failed to secure the phone - he could have used any device to do this and gave them 24 hours to play with it.People need to be careful with these, they aren't perfect. Mobile phone fraud: 'They stole £22,500 using my banking app'. He was protected by Facial Recognition on his device and PIN on the app.
But yes, they aren't perfect. However from the PC point of view, I can't log into my bank account without my phone. I have to use 2FA. So anyone hacking my PC will not be able to gain access to my bank account.