{"meta":{"database":"Global Social Engineering Impact Database","license":"CC BY 4.0 — attribute to Netarx Social Engineering Incident Database","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion"},"incident":{"title":"Transport for London hit by Scattered Spider teens in a £29m intrusion","date":"2024-09-01","date_precision":"day","victim_org":"Transport for London","sector":"Transportation & Logistics","country":"United Kingdom","primary_vector":"Help Desk Impersonation","secondary_vectors":["Vishing (Voice Phishing)"],"ai_involvement":"No AI reported","ai_notes":"No AI involvement reported.","outcomes":["Service Disruption","Data Breach","Credential Theft"],"loss_usd":39000000,"loss_note":"TfL put the cost at about £29 million (roughly $39 million); prosecutors said a complete shutdown could have caused up to £56 billion of economic damage.","records_affected":null,"threat_actor":"Scattered Spider; Thalha Jubair and Owen Flowers were each sentenced to five and a half years in July 2026","summary":"Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.","how_it_worked":"TfL has not published the entry vector, and the prosecution described Scattered Spider's general reliance on phone, email and SMS social engineering rather than a specific script for this intrusion. What the response reveals is the assumption TfL made about the attackers' capability: the organisation judged that remote password resets could themselves be abused, and required roughly 27,000 staff to attend in person with identity documents to re-establish credentials. That is the signature countermeasure to help-desk impersonation, adopted precisely because remote identity proofing could no longer be trusted.","lessons":"In-person or strongly verified credential re-issuance for staff, and phishing-resistant MFA for remote administrative access, are the controls TfL was forced to adopt reactively.","confidence":"Reported","sources":[{"title":"Transport for London (TfL) is dealing with an ongoing cyberattack","url":"https://securityaffairs.com/167946/hacking/transport-for-london-tfl-ongoing-cyberattack.html","publisher":"Security Affairs"},{"title":"Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack","url":"https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html","publisher":"Security Affairs"}],"entry_type":"incident","slug":"2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion","year":2024,"loss_kind":"business_impact","url":"https://global-social-engineering-impact-da.vercel.app/incidents/2024-transport-for-london-hit-by-scattered-spider-teens-in-a-29m-intrusion"}}