Back to blog
TfL cyber attack forced 28000 staff to reset passwords

TfL cyber attack forced 28000 staff to reset passwords

20 July 2026

 

The TfL cyber attack demonstrates that even a large organisation with extensive security technology can be compromised when criminals successfully manipulate people and identity-recovery procedures.

Between 31 August and 3 September 2024, attackers linked to the Scattered Spider cybercrime collective gained unauthorised access to Transport for London’s computer network. The incident disrupted customer services, affected Oyster-related systems and forced thousands of employees to complete password resets.

The criminals did not reportedly begin the intrusion with an exotic zero-day vulnerability or highly advanced custom malware. Instead, the available evidence indicates that they relied primarily on stolen account information, social engineering and persistent attempts to expand their access. The uploaded report summarises the central weakness clearly: the attackers relied on stolen credentials, social engineering and persistence, while trust and permissive systems helped them move through the network.

This makes the TfL cyber attack an important identity-security case study for businesses, government bodies and critical infrastructure operators.

TfL Cyber Attack: What Happened to Transport for London?

The National Crime Agency identified Thalha Jubair and Owen Flowers as members of Scattered Spider, a loosely organised online criminal collective. Both admitted participating in the TfL cyber attack and were each sentenced to five years and six months in prison on 16 July 2026.

According to the NCA, the pair compromised TfL’s network and caused significant operational disruption. All approximately 28,000 employees had to attend a TfL location to complete password resets. The incident also affected the Oyster refund system and temporarily closed the application service for children’s and young people’s Oyster photocards.

The CPS stated that more than 140 systems became inoperable and placed TfL’s losses and recovery costs at approximately £29 million. Some media reports use a higher £39 million figure when describing the broader financial impact, but £29 million is the figure published by the NCA and CPS for losses and remediation.

Although London’s trains and buses continued operating, the TfL cyber attack created a serious risk to an organisation responsible for millions of journeys each day. TfL disconnected parts of its network to prevent the attackers from creating wider disruption. Prosecutors said that a more destructive outcome could have caused damage worth billions of pounds to the UK economy.

What information and services were affected?

Investigators confirmed that information from TfL’s Oyster refund system was accessed. Reporting about the case also indicated that the attackers reached sensitive customer and operational environments.

The uploaded source states that sensitive systems containing information connected with millions of Oyster card holders were accessed. It also explains that TfL had to “pull the plug” on its own network to protect the transport system from wider disruption.

The uploaded source states that sensitive systems containing information connected with millions of Oyster card holders were accessed. It also explains that TfL had to “pull the plug” on its own network to protect the transport system from wider disruption.

The incident affected:

  • Oyster customer refund processing
  • Photocard applications for children and young people
  • Employee access to internal systems
  • Numerous connected business applications
  • Customer service and administrative operations
  • TfL’s ability to trust existing employee credentials

The scale of the response shows why the TfL cyber attack was not simply a website outage. It became an organisation-wide identity and network-containment emergency.

TfL Cyber Attack: How the Attackers Penetrated the System

Publicly available accounts indicate that the initial entry point involved compromised employee information and impersonation rather than the direct exploitation of a previously unknown software flaw.

The attackers reportedly obtained partial or stolen employee credentials from criminal sources. They then used those details to present themselves as a legitimate TfL employee while contacting technical support. By exploiting the account-recovery process, they persuaded support personnel to change or restore access to an employee account.

This approach is sometimes described as helpdesk social engineering or voice phishing, also known as vishing.

Stolen credentials and account impersonation

Stolen credentials gave the attackers enough personal or organisational information to make their story appear credible. However, possession of a username, password fragment or employee detail does not always provide immediate access, particularly when multifactor authentication is enabled.

The criminals therefore targeted the human-controlled recovery process surrounding the account.

Rather than defeating the mathematical protection behind multifactor authentication, they allegedly convinced support staff to help reset or recover access. In effect, the TfL cyber attack targeted the process used when an employee claims to have lost access to their authentication method.

This distinction is critical. Multifactor authentication can be technically strong while the associated password-reset or account-recovery process remains vulnerable.

Optimise Cyber Solutions provides staff and employees with practical, hands-on training to increase cybersecurity awareness. Cybersecurity training helps businesses reduce the risk of cyberattacks, especially when human vulnerability plays a significant role.

Helpdesk manipulation and vishing

The main social engineering technique associated with the TfL cyber attack was impersonation over the telephone.

The attackers reportedly:

  1. Gathered or purchased information connected with a real employee.
  2. Contacted the organisation’s helpdesk.
  3. Claimed to be the employee represented by the stolen information.
  4. Used known personal or workplace details to increase credibility.
  5. Created urgency around an account-access problem.
  6. Persuaded support personnel to reset or restore access.

This was not a technical bypass of encryption. It was a manipulation of identity verification.

The uploaded report reaches the same conclusion, warning that an attacker who persuades a helpdesk that they are a legitimate employee can obtain access without writing sophisticated code.

For security teams, the lesson from the TfL cyber attack is that the helpdesk effectively controls a secondary entrance to every protected account. When that entrance requires weaker evidence than the normal login process, attackers will target it.

TfL Cyber Attack: Technical Methods Used After Initial Access

Complete forensic details of the intrusion have not been published, so claims about individual commands, software exploits or internal configurations should be treated cautiously. Nevertheless, official findings and court reporting reveal several broad technical methods.

Credential-based network access

Once the criminals controlled a legitimate employee account, their activity could initially resemble normal user behaviour. Valid credentials can allow attackers to pass through standard login pages, remote-access services or cloud applications without triggering alerts associated with malware exploitation.

This is why credential-based attacks are difficult to detect. The network sees an authorised account, even though the person controlling it is unauthorised.

Privilege escalation and administrative access

Reporting from the sentencing indicated that the attackers eventually obtained powerful administrative access. Administrative privileges can allow an intruder to access additional systems, change configurations, create accounts or interfere with security controls.

The exact privilege-escalation path used during the TfL cyber attack has not been fully disclosed publicly. However, the evidence indicates that the attackers repeatedly searched for additional routes through the network rather than relying on one successful login.

Lateral movement and persistence

After establishing an initial foothold, the pair reportedly moved between connected systems and continued looking for new access opportunities. In cybersecurity, this is known as lateral movement attack.

Lateral movement may involve abusing trusted accounts, existing administrative tools, shared services or poorly segmented systems. Discussing the case defensively, the important point is not the sequence of commands but the organisational weakness: one compromised identity was able to provide a route towards multiple sensitive resources.

The uploaded report describes this behaviour as persistent movement through the network, enabled partly because people trusted the attackers and systems permitted their activity.

Data access and remote collaboration

The NCA found videos showing Jubair accessing TfL systems during the incident. Investigators also found that the defendants communicated over Telegram and used an online collaborative workspace while the intrusion was taking place. A laptop seized during the investigation contained evidence of connectivity to TfL infrastructure and access to a service selling breached credentials.

These details suggest that the TfL cyber attack combined identity abuse, remote coordination, credential acquisition and persistent exploration of internal systems.

TfL Cyber Attack: Security Lessons for Organisations

The most important lesson is that cybersecurity cannot rely exclusively on firewalls, endpoint software and multifactor authentication. Identity verification procedures must be at least as strong as the technology they are designed to recover or replace.

Strengthen helpdesk identity verification

Helpdesk staff should not approve sensitive account changes using information that may be available through previous data breaches, social media or criminal credential markets.

Organisations should require stronger verification for password resets, MFA changes and privileged-account recovery. Suitable safeguards may include manager confirmation through a trusted internal channel, verified video identification, secure recovery codes or in-person checks for highly privileged accounts.

Protect multifactor authentication resets

Resetting multifactor authentication should be treated as a high-risk security event. Organisations should record the request, verify the user independently and notify the account holder through an existing trusted channel.

A newly reset account should also be subjected to temporary restrictions and enhanced monitoring.

Apply least-privilege access

An ordinary employee account should not provide a direct path to sensitive administrative systems. Access should be limited according to the employee’s responsibilities, and privileged actions should require separate, tightly controlled accounts.

This reduces the potential damage when one identity is compromised.

Monitor unusual identity activity

Security teams should investigate warning signs such as:

A password reset followed by immediate access from a new device Authentication from an unusual location Rapid access to multiple unrelated systems Sudden attempts to obtain administrative privileges Changes to multifactor authentication settings Large or unusual data queries

Access outside the employee’s normal working pattern.

Combining identity, endpoint and network monitoring can reveal a compromised account before an attacker expands their control.

Train staff against social engineering

Employees should understand that convincing attackers may already possess accurate personal and organisational information. Knowing an employee’s name, department, manager or identification number does not prove identity.

Training should include realistic vishing exercises and clear procedures that give helpdesk employees permission to delay or reject suspicious requests.

Optimise Cyber Solutions provide staff and employees with practical hands-on training for increasing cyber security awarenesss. cyber security training helps businesses to reduce the risk of cyber attacks specially when human vulnerability plays an important role.

The Innovate UK TechLocal AI and Cyber Talent Programme can help organisations train new employees and upskill existing team members in artificial intelligence and cybersecurity

The training explores the rapid development of AI and the growing importance of cybersecurity as hackers and cybercriminals use AI to make social engineering, impersonation and other attack techniques more sophisticated and convincing. Incidents such as the TfL cyberattack demonstrate why employees must be equipped to recognise suspicious behaviour, verify identities and respond appropriately to emerging cyber threats.

Conclusion: Why the TfL Cyber Attack Matters

The TfL cyber attack was not successful simply because the criminals possessed advanced technical knowledge. Its initial effectiveness came from the combination of stolen credentials, persuasive impersonation and weaknesses in identity-recovery procedures.

After gaining access, the attackers reportedly used legitimate accounts, moved through connected systems, pursued greater privileges and coordinated their activity remotely. Their persistence turned a manipulated helpdesk interaction into an incident affecting more than 140 systems and costing TfL tens of millions of pounds.

For other organisations, the message is clear: the password-reset process, helpdesk and identity-recovery workflow are part of the security perimeter. Strong authentication offers limited protection when an attacker can persuade someone to replace it.

The TfL cyber attack therefore provides a powerful warning for every organisation. Before investing only in more complex security software, businesses should examine whether a convincing caller with stolen employee information could still enter through the front door.

 

More from the blog

How to Use AI Safely at Work: Practical Guide and +3 solutions
Post

How to Use AI Safely at Work: Practical Guide and +3 solutions

If you are unsure how to use AI safely, this guide will help you evaluate any AI service. It outlines what to check when using AI tools and what to do if you are at risk or experience a cyberattack.

13 July 2026Read more
How AI Is Changing Cybersecurity for UK Businesses
Post

How AI Is Changing Cybersecurity for UK Businesses

Artificial intelligence is reshaping cybersecurity for UK businesses, creating new risks and making cyber resilience more important than ever. This blog from Optimise Cyber Solutions explains why staff awareness, secure processes and practical training are essential in a changing threat landscape.

17 April 2026Read more