Desk live·
ForensicPost
Breaches/Fallback/File 24-0905

TfL Required Every Employee to Attend in Person for a Password Reset

TfL required every one of its employees to attend an office in person for a password reset. When you cannot trust remote identity verification, the fallback is a human face.

Constructed geometry · not a chart of case data
JurisdictionUnited KingdomLondonthe affected organisation’s jurisdiction, not the actor’s suspected origin
TargetTransport for London
ActorScattered Spider
S. Rosler12 min readConfidence: high3 sources reviewed

Following the intrusion, all 28,000 TfL employees were required to attend a TfL office in person to have their passwords reset and their identity verified.

It is the single most instructive operational detail in the 2024 files, and it is the exact inverse of how the intrusion happened.

The Technique And The Remedy Are The Same Problem

The identity-led intrusion works by persuading whoever restores access that the caller is the employee. The corpus records it across dozens of files: no vulnerability is used, the system grants legitimate credentials to the wrong person, and everything downstream looks normal.

Once that has happened, an organisation cannot trust any remote assertion of identity — including the ones it would normally use to re-establish trust. A reset performed over the phone is exactly the mechanism it is trying to undo.

So the only remaining verifier is physical presence. That is why 28,000 people had to be in a room.

The Cost Of That Is Enormous And Mostly Invisible

Twenty-eight thousand journeys, appointments, queues and hours away from the actual job, across an organisation that runs a city’s transport. None of it appears as a data-breach figure and most of it will not appear as a line item anywhere.

This corpus records the fallback theme as manual procedures inherited from a pre-automation era that nobody tracks. Here the fallback is the oldest one there is — look at the person — and it worked precisely because it has no technical component to compromise.

The Planning Question This Raises

Almost no organisation knows how long it would take to physically verify its entire workforce, or whether it could. A distributed workforce, a contractor population, a night shift and a set of people on leave each make it harder.

The corpus asked at 24-0720 whether anybody tests time-to-touch-every-machine. This is the same question about people, and this desk has seen no evidence that anybody measures it either.

How we reported this

Based on National Crime Agency material and contemporaneous reporting of the in-person reset requirement, listed below. Graded high: the requirement and the 28,000 figure are stated by the investigating agency and by the organisation. The cost characterisation is this desk’s argument; no figure for the reset exercise has been published. Corrections: corrections@forensicpost.com.

Sources
  1. Two sentenced for hacking Transport for LondonNational Crime Agency
  2. TfL cyber attack: what you need to knowBBC News
  3. Commissioner report, October 2024Transport for London
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary