The Tool Desk
Outbyte PC Repair FREEClear out junk files and repair common Windows errorsFree Scan →Outbyte Driver Updater FREEScan for outdated or missing drivers - takes under a minuteDriver Scan →The 2024 cyberattack on Transport for London disrupted customer services and exposed data from its Oyster refunds system. A figure of around 10 million people affected was reported by the BBC and repeated in a London Assembly question, but the reviewed official sources do not independently confirm that total. TfL’s transport network kept running; the attack’s effects were felt in digital services, refunds and customer administration.
What happened in the TfL cyberattack?
The National Crime Agency (NCA) says Thalha Jubair and Owen Flowers infiltrated TfL’s network between 31 August and 3 September 2024. On 16 July 2026, the NCA said both men had pleaded guilty and were each sentenced to five years and six months in prison. It identified them as members of the online criminal collective Scattered Spider. NCA sentencing announcement
The attack affected customer-facing TfL systems and required the transport operator to shut down some service elements to limit access. Public information does not establish a detailed, verified account of the attackers’ entry method or every action they took inside TfL’s network, so claims about a specific exploit or security weakness should be treated cautiously.
How many people were affected—and what does that number mean?
A London Assembly question in 2026 says the BBC reported that 10 million people had their data stolen. That is a BBC-reported estimate recorded by the Assembly, not a total independently confirmed in the official sources reviewed here. The Assembly page separately records TfL saying it emailed more than 7 million customers; an email count is not the same measure as the number of people whose data was accessed. London Assembly question
#1 Best Overall
Other figures describe different groups or recovery work, not the number of affected customers:
- 27,000: TfL employees who, according to the NCA, had to attend a TfL office for a password reset.
- More than 350,000: photocards processed by March 2025, as recorded in a Greater London Authority (GLA) oversight report. This is a recovery figure, not a count of people whose data was stolen. GLA Oversight Committee report
- 9 million: average daily journeys, cited by the Crown Prosecution Service (CPS) as context for the potential harm to a major transport network—not a count of people affected by the breach. CPS sentencing statement
The available information confirms access to data from TfL’s Oyster refunds system, but does not establish a complete, independently verified breakdown of the data taken or the total number of people affected. The sources reviewed do not establish that payment card numbers were stolen.
Rank #2
- Ideal for Gifting
- Ideal for a bookworm
- Compact for travelling
What TfL services and customers were affected?
Oyster refunds and online services
The NCA says data from TfL’s Oyster refunds system was accessed. The incident also affected TfL’s customer refund system and led to the closure of the application system for Oyster photocards for children and young people. The GLA oversight report records temporary effects on live Tube information, online journey history and payments through the Oyster app.
Photocard applications and other services
The NCA lists disruption to Dial-a-Ride bookings, concessionary travel cards, digital payments and the planned extension of contactless ticketing. The GLA report says TfL paused new applications for concessionary photocards while it carried out security checks, then reopened applications during November 2024. It later reported clearing remaining backlogs and processing more than 350,000 photocards by March 2025.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteRank #3
Trains and buses continued to run
The attack disrupted digital information and customer services, but it did not stop London’s public transport network. The GLA report says the Tube, buses and other public transport continued running after TfL’s response, although live Tube information was unavailable for a time.
What did the attack cost TfL?
The NCA reports that 148 TfL systems became inoperable, including critical systems that required manual workarounds and caused delays. It also reports £29 million in loss and recovery costs. These figures describe operational and financial impact; they do not indicate how many individual customers suffered a direct financial loss.
Rank #4
Timeline: from the intrusion to sentencing
| Date | What happened |
|---|---|
| 31 August–3 September 2024 | The period during which the NCA says the network was infiltrated. |
| 2 September 2024 | TfL contacted customers with registered email addresses about the incident, according to the London Assembly’s record. |
| 12 September 2024 | TfL sent a further update based on what it understood about the data taken and duplicate records, as recorded by the Assembly. |
| 16 September 2024 | The NCA and City of London Police arrested Jubair and Flowers at their home addresses. |
| 18 September 2025 | The NCA announced charges. At that point, it described the Scattered Spider connection as investigators’ belief. |
| 22 June 2026 | The defendants changed their pleas to guilty on the day they were due to stand trial at Woolwich Crown Court, according to the NCA. |
| 16 July 2026 | Jubair and Flowers were each sentenced to five years and six months in prison. |
What can customers do if they are concerned?
TfL’s recorded customer notifications were sent on 2 and 12 September 2024. If you have questions about your own account or information, use TfL’s official contact channels and refer to any incident notice you received. Be cautious of unexpected calls, texts or emails claiming to be from TfL or offering help: a breach can create opportunities for impersonation, but the sources do not establish that every customer received the same data exposure.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the case says about Scattered Spider—and what it does not
A joint advisory from the FBI, CISA, RCMP, Australia’s ASD/ACSC and AFP, Canada’s CCCS, and the UK’s NCSC describes Scattered Spider tactics across multiple investigations. These include social engineering, impersonating company help-desk staff, credential theft, SIM swaps and attempts to bypass multifactor authentication. The advisory’s updated 29 July 2025 edition includes tactics identified through investigations as recently as June 2025. It is general guidance, not a forensic report on the TfL incident, and does not prove which method was used against TfL. Joint government advisory
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Best Value
- It can be a gift option
- Comes with secure packaging
- Helpful in various ways
For organizations, the advisory recommends phishing-resistant multifactor authentication, regularly tested offline backups kept separately, and application controls that manage which software can run. These are general security measures, not evidence of TfL’s particular controls or proof that any single product would have prevented this attack.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




