What happened
Transport for London disclosed an ongoing cyberattack on 2 September 2024 that forced 148 systems offline and required about 27,000 employees to reset passwords in person. Customer data from the Oyster refunds system was exposed, and Dial-a-Ride, concessionary travel cards, digital payments and contactless ticketing rollout were disrupted. TfL put the cost at roughly £29 million. Two Scattered Spider members, Thalha Jubair and Owen Flowers, were sentenced in the UK in July 2026.
How the deception worked
TfL has not published the entry vector, and the prosecution described Scattered Spider's general reliance on phone, email and SMS social engineering rather than a specific script for this intrusion. What the response reveals is the assumption TfL made about the attackers' capability: the organisation judged that remote password resets could themselves be abused, and required roughly 27,000 staff to attend in person with identity documents to re-establish credentials. That is the signature countermeasure to help-desk impersonation, adopted precisely because remote identity proofing could no longer be trusted.
AI involvement · No AI reported
No AI involvement reported.
The control that would have caught it· our reading, not a claim from the sources
In-person or strongly verified credential re-issuance for staff, and phishing-resistant MFA for remote administrative access, are the controls TfL was forced to adopt reactively.
Sources (2)
- Transport for London (TfL) is dealing with an ongoing cyberattackSecurity Affairs·securityaffairs.comOpen ↗
- Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL CyberattackSecurity Affairs·securityaffairs.comOpen ↗
This entry summarises public reporting. It is not a legal finding, and details can change as investigations conclude. Found an error? Send a correction.