In this case, the company is more at fault for having their system completely compromised that the hackers could use their credentials to take the money out of the bank.
I agree somewhat the bank don't have to reimburse the company but they at least should be required to do an audit for their banking system.
It's the same story everywhere. Companies try to cut cost and the place they cut first and most is the IT portion.







