Transport for London (TfL) disclosed that it was dealing with a cyber incident. Trains and buses kept running, but staff systems and several online customer services were disrupted for months while systems were rebuilt.
What happened
- TfL later confirmed that customer names and contact details had been accessed, along with Oyster refund data including bank account numbers and sort codes for around 5,000 customers. In March 2026 TfL was reported to have put the total number of customers affected at around 7 million.
- Around 30,000 staff were asked to attend in-person appointments to reset their passwords.
- The National Crime Agency (NCA) arrested a 17-year-old in Walsall on 5 September 2024 on suspicion of Computer Misuse Act offences.
- In September 2025 two young men whom the NCA believed to be part of the Scattered Spider collective were charged; both pleaded guilty and were sentenced in July 2026 to five and a half years each. TfL put its losses and recovery costs at around £29m.
Why it mattered
The NCA described it as the largest cyber crime prosecution ever brought before UK courts. The attack showed the long tail of recovery costs for public bodies and the threat from young, English-speaking cybercriminals in groups such as Scattered Spider.
Lessons for organisations
Protect help desks and identity systems against social engineering, since password resets are a common entry route. Plan for extended recovery, including how to rebuild identity infrastructure and communicate with affected customers.
Sources: The Register, The Register (2026), National Crime Agency
Part of our Top stories archive of headline-making events in information security, privacy, and AI. If you would like help applying the lessons to your organisation, contact us.