Desk live·
ForensicPost
Breaches/Identity/File 24-0901

Transport for London Penetrated Over Three Days in August 2024

Transport for London was penetrated over three days at the end of August 2024. The data loss was small and the recovery cost was not.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTransport for London
ActorScattered Spider
D. Kennedy13 min readConfidence: high3 sources reviewed

Transport for London’s network was entered between 31 August and 3 September 2024, with suspicious activity identified on 1 September. TfL wrote to around 5,000 customers whose bank account numbers and sort codes may have been accessed, drawn from its Oyster refund system.

Reported loss and recovery costs were about £29m. Oyster photocard applications for children and young people were suspended, and contactless refunds stopped.

Five Thousand Is A Small Number In This Database

It is four orders of magnitude below the largest 2024 files. If severity were assigned by affected population, this would barely register.

The £29m is not a small number, and neither is a suspended service that families use to get children to school. This corpus argues that availability harm goes uncounted; TfL is the case where the availability cost is documented and the confidentiality count is the footnote.

The Actor Is The One This Corpus Keeps Filing

Those later convicted were described as members of the Scattered Spider collective — the loose grouping behind the identity-led intrusions this database records across the identity theme, in which a phone call replaces an exploit.

A public transport authority sits alongside retailers, casinos and insurers in that pattern. The technique does not select by sector; it selects by whoever restores access to accounts.

A Public Body Cannot Price Its Own Downtime Out Of Existence

A retailer that loses a fortnight loses margin. A transport authority that suspends concessionary travel applications imposes the cost on children and their families, who have no alternative supplier and no compensation route.

The corpus files that under funding: the parties who could fix the problem are not the parties who pay for it. Here the parties who pay could not have influenced the outcome at all.

How we reported this

Compiled from TfL statements, contemporaneous reporting and National Crime Agency material, listed below. Graded high: the intrusion window, the customer notification and the cost figure are stated by the organisation or by the investigating agency. The £29m is a reported loss and recovery figure, not an audited total. Corrections: corrections@forensicpost.com.

Sources
  1. TfL cyber attack: what you need to knowBBC News
  2. TfL writes to 5,000 cyber attack customersBBC News
  3. Two sentenced for hacking Transport for LondonNational Crime Agency
D. Kennedy
Identity and access reporter. Former DFIR consultant. Signal on request.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary