Credential theft
Transport for London (TfL) Scattered Spider Attack
Primary Source βIncident Details
Scattered Spider attacked Transport for London on 31 August 2024, ultimately exposing data of approximately 10 million customers β one of the largest breaches in British history. Stolen data included names, email addresses, phone numbers, and home addresses. Two UK teenagers, Thalha Jubair (19) and Owen Flowers (18), were arrested by the NCA and charged. The breach caused an estimated Β£39 million in damages and was not fully disclosed publicly until early 2026, 18 months after the incident.
Technical Details
- Initial Attack Vector
- Social engineering / MFA bypass by Scattered Spider members; attacker gained internal access via compromised employee credentials
Timeline
- 2024-08-31 Breach occurred
- 2024-09-02 Publicly disclosed
- 2024-09-05 Customers notified