INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Transport for London's 2024 data breach exposed 7 million customers
| 2026-03-06 10:22 CRITICAL LOW DATA BREACH
Executive Summary
AI-generated
In March 2026, Transport for London (TfL) confirmed that a breach in 2024 exposed the data of over 7 million customers, contrary to initial warnings of around 5,000 affected individuals. Authorities have linked this incident to Scattered Spider, an English-speaking cybercrime collective known for its social engineering tactics and SIM swapping methods. The attack potentially gave attackers access to a database covering up to 10 million customers who had interacted with the capital's transport network. TfL sent emails informing over 7 million customers about the incident, but only around 58% of those with email addresses received the warning.
Technical Mitigations AI-generated
• Patch the Oyster card refund data vulnerability in TfL's systems, as it was likely accessed by hackers.
• Monitor for SIM swapping attacks and implement measures to detect and prevent such tactics used by Scattered Spider.
• Implement robust email authentication mechanisms to verify the authenticity of emails sent to customers about the breach.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
Global Scope
Incident Timeline
2026/03/06
Scattered Spider used social engineering and SIM swapping tactics to breach Transport for London's systems in 2024, potentially exposing up to 10 million customers' data.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
Authorities have linked the attack to the cybercrime collective known as Scattered Spider, an English-speaking crew that has built a reputation for breaching major organizations using social engineering, SIM swapping, and other decidedly low-glamou…
victims
10 customers
The BBC
reported
on Friday that the 2024 intrusion into TfL's systems potentially gave attackers access to a database covering as many as 10 million customers who had interacted with the capital's transport network.
victims
7 customers
Transport for London says 2024 breach affected 7M customers, not 5,000.
It confirmed it had sent emails informing more than 7 million customers about the incident, though noted an open rate of 58 percent – suggesting millions actually saw the warning in their inbox.
victims
5,000 customers
Transport for London says 2024 breach affected 7M customers, not 5,000.
"At the time of the incident, we identified around 5,000 customers requiring support as we knew that some of their Oyster card refund data may also have been accessed, which could include bank account numbers and sort codes," a TfL spokesperson tol…
Tactical Metrics
Metrics
victims
10,000,000
Customers
Click for context!
The BBC
reported
on Friday that the 2024 intrusion into TfL's systems potentially gave attackers access to a database covering as many as 10 million customers who had interacted with the capital's transport network.
Metrics
victims
7,000,000
Customers
Transport for London says 2024 breach affected 7M customers, not 5,000.
It confirmed it had sent emails informing more than 7 million customers about the incident, though noted an open rate of 58 percent – suggesting millions actually saw the warning in their inbox.
Metrics
victims
5,000
Customers
Transport for London says 2024 breach affected 7M customers, not 5,000.
"At the time of the incident, we identified around 5,000 customers requiring support as we knew that some of their Oyster card refund data may also have been accessed, which could include bank account numbers and sort codes," a TfL spokesperson tol…
Intelligence Sources
The Register - Cybercrime
2026-03-06
Transport for London says 2024 breach affected 7M customers, not 5,000
The Register - Cybercrime
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:52
Comprehensive Tactical Telemetry
Highly Correlated Entities
6x
organisation
Identified Entity
The Register
's
entity
3x
timeline
Temporal Reference
2026-03-06
date
3x
victims
Customers
10,000,000
customers
Contextual Telemetry
Context Block
6 METRICS
tactic
Cyber Operation Type
Social Engineering
tactic
threat actor
APT Group
Scattered Spider
actor
attribution
Attributing Entity
SIM
authority
general metric
Breach
2,024
breach
general metric
People
7,000,000
people
general metric
Percent
58
percent
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.