One of the specific attacks was getting the last four digits of a credit card from one company's CSR and using it to authenticate to another company's CSR - I think that happened in a couple of other high-profile attacks around the same time frame and major companies decided that the last four digits wasn't actually a meaningful authenticator.