It's possible to split the responsibility. If the bank were responsible for, say, half the loss, both sides would still have plenty of incentive to do the right thing.
(That's not to say that 50% is the right split, but 0% seems too low.)
What 'right thing' should the bank have done in the example case? Should they not have transferred the money to the account the customer told them to send it to?
Additional verification? Call the customer, email them, put a BIG RED notice at the top of e-banking for each login, delay the transaction a reasonable time(hell, it's probably only executed at midnight).
Can't imagine that KYC only works for governement investigations.
HSBC started trying that - asking customers withdrawing large unusual sums what it was for, and suggesting those customers be aware for scams. It got quite a lot of pushback from people saying "It's my money, I can do what I want with it".
That's a shame, because giving people warnings about common scams when they're transferring large sums of money might reduce the amount of successful scamming.
And this is the whole point of anti-money laundering and fraud detection controls within banks.
There's not enough information in the story to tell if the customer turned controls off, if a transfer of this type was unusual, if the customer confirmed an alert, etc.
Reporting in the story is horrendous, almost to the point it appears it is intentionally exploiting the victim and misinforming the public.
Banks in Europe use SWIFT, which is much faster, often instant. Scammer in this story appears to have received the funds and transfed them out within less than 20-mins of the victim clicking send.
Actually being available on the weekend when the customer calls in a panic to reverse the transaction. If the bank has some skin in the game, they have incentive to be responsive.
(That's not to say that 50% is the right split, but 0% seems too low.)