Typically cards are compromised when you swipe the physical card or insert the chip into a transaction terminal at bank ATMs and merchants such as gas stations, grocery stores, convenience stores and restaurants.
Scammers use devices called skimmers and shimmers to copy the data off the card. The copied personal information and card details are sold on the Dark Web. Scammers make counterfeit cards and add the information to Android phones and iPhones to use with Google Wallet and Apple Pay.
Fraud is committed when the scammers use the counterfeit cards or electronic wallets to make purchases online or in person.
How did your card information get put on an electronic wallet? The verification process is managed by the issuing bank and Payment Network Operator (Visa, MasterCard etc.). Apple is not a bank and cannot verify your identity or authenticate the card details. Apple provides basic information such as iPhone model, usage patterns, location and information about Apple Account, iTunes account etc. The PNO and bank use various methods to verify the person trying to add the card and typically go through two or more verification processes.
Once identity is confirmed the bank sends an encrypted dynamic token that represents your card details including account number, expiration date and security codes to Apple servers. Apple then adds the token to the Wallet app along with art work representing the card to the Wallet and the card is authorized for use with Apple Pay.
Please contact the fraud department at the issuing bank by calling the phone number on the back of your card. The bank’s fraud team has processes they go through and will probably request you file a police report. Apple will cooperate when requested with local law enforcement and the bank.
Im sorry to learn of the incident and hope your bank can resolve the issue to your satisfaction.
Apple Pay component security - Apple Support
Apple Pay security and privacy overview - Apple Support
Card provisioning security overview - Apple Support
Legal - Apple Pay & Privacy- Apple