Hell not just that. SMS is one small step of internet banking. You still need the banks userID and password to log into online banking before you even make use of the SMS transaction confirmations. There's also a lot of requirements for number porting as it is too - accountID and details with the old provider and there's SMS notices sent when the porting is attempted too.
So this woman was socially engineered out of the following - Her real name, address and DOB (fair enough, this is publically available), her old mobile providers details and accountID (someone go through her bin?), her banks clientID and password (she fall for a fake bank email?), she didn't notice the SMS announcements that she'd be ported to a new provider next month (wtf?) and finally she didn't notice a lack of calls coming in.
At some point you have to say fuck it, there's no way to protect people like this. Even if it was made more difficult to port numbers she's clearly stupid enough to give away any and all information asked of her.