Even if they did get into the Secure Element and Secure Enclave on your iPhone, they’d get encrypted data. Encryption that your bank used. The key to decrypt the data isn’t in your iPhone/devices, it’s on your bank’s servers, not Apples.
If you want to go with that story that’s great. But the Secret Service doesn’t believe it, the FBI doesn’t believe it, the Office of the Comptroller doesn’t believe it, the Federal Reserve Bank doesn’t believe it, Federal Trade Commission doesn’t believe it, Consumer Financial Protection Bureau doesn’t believe it and people in your bank’s fraud department don’t believe it.
You talked to a tier one support person at American Express, right? But you believe what they told you. Is that right? Because they couldn’t explain it, they said call Apple.
American Express support misinformed you. Apple has no way of know if you're the account owner or the fraudster. Apple will discuss the fraud with the proper legal authorities and your bank. American Express knew that, but they wanted to just get you off the support call.
Apple only has encrypted data, they could not determine the wallet/device used if they wanted to.
American Express can see all the devices the card has been added to. It’s their card, they verified adding it to your iPhone. The bank can remove the cards/tokens from all devices if they want to. Ask their fraud department why they haven’t or won’t do it. Ask their fraud department why they authorized fraudulent charges? Apple didn’t authorize the charges. The encrypted transaction details are sent to American Express and they decrypt it and authorize or decline the transactions. Ask why they authorized fraudulent charges.
This post may come across as if I’m angry or upset. It’s just my writing style. If my post upset you, I’m sorry. That was never my intent. I’m just trying to lead you to a resolution. I'm happy to answer any questions and help anyway I can. 😀