There was also this example that floated around last year:
This is a VA/PT report for a fictitious bank called eClipse Bank PLC carried
out by another fictitious company Cynergi Solutions Inc. All names, URLs,
IPs, etc are fictitious. Some of the vulnerabilities discussed have actually
occurred for real but i have replaced all the pesky details.
The report is attached or it can be downloaded at:
http://digitalencode.net/ossar/ossar_v0.5.pdf and this one from OWASP (way old i know) for hacme Bank:
http://lists.owasp.org/pipermail/owasp-london/attachments/20060430/01d79928/attachment.pdf all good references though =)