Err...
re: How did this get through this year... It's a man in the middle attack - the target is at one end, the bank is at the other, the criminal is in the middle. The auth details are passed from the bank via the fake web site to the victim. What happens at the bank end is controlled by the man in the middle, with a fake web site being shown to the victim. Easy. Well, not that easy, but very hard to defend against.
re: Why electronic fraud isn't easy to track: If you take your cash and move it to a country where they have tight banking secrecy laws you've made it disappear. Again, it's fairly easy and very hard to defend against.