The first time the victim clicked the link she would have provided the scammer with just her ID and password to login.
If she wants to do a transfer, she needs to add the unknown account to her list of 3rd party accounts. That will require a manual token that looks like a calculator plus the 2nd key via SMS.
When she is ready to activate the transfer, she needs another key via SMS.
So I don't understand how the scammers managed to collect the SMS code which could only be sent to the victim's mobile phone.