Adding a card to a new device generates a notification of use of OTP. If all they purchased was a subscription, they could have added your compromised card details to their Apple ID and not add it to their Wallet. So, Apple Pay is not the issue.
The issue is your data on your card was skimmed or shimmed when you swiped or inserted the chip. They manually entered the card details into their Apple ID and charged a subscription. Your bank approved the transaction.
Does your bank or Payment Network (Mastercard, Visa etc.) offer fraud protection? Consumer law limits the total liability of charges you’re responsible for to $50, I believe.
The other thing is banks and payment networks offer a service called Automatic Billing Updater (that’s what Mastercard calls it, but they all offer it) and that automatically updates the merchant to the new numbers that the bank issues. You’ll continue to be charged until the ABU is off and new numbers issued.