INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).

Transport for London's 2024 data breach exposed 7 million customers

| 2026-03-06 10:22 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In March 2026, Transport for London (TfL) confirmed that a breach in 2024 exposed the data of over 7 million customers, contrary to initial warnings of around 5,000 affected individuals. Authorities have linked this incident to Scattered Spider, an English-speaking cybercrime collective known for its social engineering tactics and SIM swapping methods. The attack potentially gave attackers access to a database covering up to 10 million customers who had interacted with the capital's transport network. TfL sent emails informing over 7 million customers about the incident, but only around 58% of those with email addresses received the warning.
Technical Mitigations AI-generated
• Patch the Oyster card refund data vulnerability in TfL's systems, as it was likely accessed by hackers. • Monitor for SIM swapping attacks and implement measures to detect and prevent such tactics used by Scattered Spider. • Implement robust email authentication mechanisms to verify the authenticity of emails sent to customers about the breach.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope
Incident Timeline
‎2026/03/06
Scattered Spider used social engineering and SIM swapping tactics to breach Transport for London's systems in 2024, potentially exposing up to 10 million customers' data.
threat_actor Scattered Spider
victims 10 customers
victims 7 customers
victims 5,000 customers
Tactical Metrics
Metrics
victims
10,000,000
Customers
Metrics
victims
7,000,000
Customers
Metrics
victims
5,000
Customers
Intelligence Sources
The Register - Cybercrime 2026-03-06