Here's an example of two factor authentication being exploited with serious end results. Something you have (ATM Card) and something you know (PIN). The criminals apparently exploited the something you have by creating counterfit cards (remember the second Terminator movie where the John O'Conner kid used a fake ATM card to pull 300 bucks out of an ATM?). And got the PIN numbers to peoples accounts from some poorly protected systems holding the information (third party). This will be another interesting one to see how it plays out in court.
http://www.msnbc.msn.com/id/11731365/