October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsSlow PC?RecommendedPC slow today? Run a repair scan before it gets worseResolve common Windows issues and optimize system performance.Scan NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
The Finance Base
The Money Desk · Blog
Re:

Scattered Spider’s TfL Cyberattack: What Happened and Who Was Affected

The NCA says two Scattered Spider members infiltrated TfL in 2024. The often-cited 10 million affected figure is a BBC-reported estimate, not an independently confirmed official total.
From TheFinanceBase Team4 min to read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The 2024 cyberattack on Transport for London disrupted customer services and exposed data from its Oyster refunds system. A figure of around 10 million people affected was reported by the BBC and repeated in a London Assembly question, but the reviewed official sources do not independently confirm that total. TfL’s transport network kept running; the attack’s effects were felt in digital services, refunds and customer administration.

What happened in the TfL cyberattack?

The National Crime Agency (NCA) says Thalha Jubair and Owen Flowers infiltrated TfL’s network between 31 August and 3 September 2024. On 16 July 2026, the NCA said both men had pleaded guilty and were each sentenced to five years and six months in prison. It identified them as members of the online criminal collective Scattered Spider. NCA sentencing announcement

The attack affected customer-facing TfL systems and required the transport operator to shut down some service elements to limit access. Public information does not establish a detailed, verified account of the attackers’ entry method or every action they took inside TfL’s network, so claims about a specific exploit or security weakness should be treated cautiously.

How many people were affected—and what does that number mean?

A London Assembly question in 2026 says the BBC reported that 10 million people had their data stolen. That is a BBC-reported estimate recorded by the Assembly, not a total independently confirmed in the official sources reviewed here. The Assembly page separately records TfL saying it emailed more than 7 million customers; an email count is not the same measure as the number of people whose data was accessed. London Assembly question

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Other figures describe different groups or recovery work, not the number of affected customers:

  • 27,000: TfL employees who, according to the NCA, had to attend a TfL office for a password reset.
  • More than 350,000: photocards processed by March 2025, as recorded in a Greater London Authority (GLA) oversight report. This is a recovery figure, not a count of people whose data was stolen. GLA Oversight Committee report
  • 9 million: average daily journeys, cited by the Crown Prosecution Service (CPS) as context for the potential harm to a major transport network—not a count of people affected by the breach. CPS sentencing statement

The available information confirms access to data from TfL’s Oyster refunds system, but does not establish a complete, independently verified breakdown of the data taken or the total number of people affected. The sources reviewed do not establish that payment card numbers were stolen.

Rank #2
Sale
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
  • Ideal for Gifting
  • Ideal for a bookworm
  • Compact for travelling

What TfL services and customers were affected?

Oyster refunds and online services

The NCA says data from TfL’s Oyster refunds system was accessed. The incident also affected TfL’s customer refund system and led to the closure of the application system for Oyster photocards for children and young people. The GLA oversight report records temporary effects on live Tube information, online journey history and payments through the Oyster app.

Photocard applications and other services

The NCA lists disruption to Dial-a-Ride bookings, concessionary travel cards, digital payments and the planned extension of contactless ticketing. The GLA report says TfL paused new applications for concessionary photocards while it carried out security checks, then reopened applications during November 2024. It later reported clearing remaining backlogs and processing more than 350,000 photocards by March 2025.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Trains and buses continued to run

The attack disrupted digital information and customer services, but it did not stop London’s public transport network. The GLA report says the Tube, buses and other public transport continued running after TfL’s response, although live Tube information was unavailable for a time.

What did the attack cost TfL?

The NCA reports that 148 TfL systems became inoperable, including critical systems that required manual workarounds and caused delays. It also reports £29 million in loss and recovery costs. These figures describe operational and financial impact; they do not indicate how many individual customers suffered a direct financial loss.

Timeline: from the intrusion to sentencing

Date What happened
31 August–3 September 2024 The period during which the NCA says the network was infiltrated.
2 September 2024 TfL contacted customers with registered email addresses about the incident, according to the London Assembly’s record.
12 September 2024 TfL sent a further update based on what it understood about the data taken and duplicate records, as recorded by the Assembly.
16 September 2024 The NCA and City of London Police arrested Jubair and Flowers at their home addresses.
18 September 2025 The NCA announced charges. At that point, it described the Scattered Spider connection as investigators’ belief.
22 June 2026 The defendants changed their pleas to guilty on the day they were due to stand trial at Woolwich Crown Court, according to the NCA.
16 July 2026 Jubair and Flowers were each sentenced to five years and six months in prison.

What can customers do if they are concerned?

TfL’s recorded customer notifications were sent on 2 and 12 September 2024. If you have questions about your own account or information, use TfL’s official contact channels and refer to any incident notice you received. Be cautious of unexpected calls, texts or emails claiming to be from TfL or offering help: a breach can create opportunities for impersonation, but the sources do not establish that every customer received the same data exposure.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What the case says about Scattered Spider—and what it does not

A joint advisory from the FBI, CISA, RCMP, Australia’s ASD/ACSC and AFP, Canada’s CCCS, and the UK’s NCSC describes Scattered Spider tactics across multiple investigations. These include social engineering, impersonating company help-desk staff, credential theft, SIM swaps and attempts to bypass multifactor authentication. The advisory’s updated 29 July 2025 edition includes tactics identified through investigations as recently as June 2025. It is general guidance, not a forensic report on the TfL incident, and does not prove which method was used against TfL. Joint government advisory

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Sale
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
  • It can be a gift option
  • Comes with secure packaging
  • Helpful in various ways

For organizations, the advisory recommends phishing-resistant multifactor authentication, regularly tested offline backups kept separately, and application controls that manage which software can run. These are general security measures, not evidence of TfL’s particular controls or proof that any single product would have prevented this attack.

Quick Recap

SaleBestseller No. 1
SaleBestseller No. 2
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
The Psychology of Money: Timeless lessons on wealth, greed, and happiness
Ideal for Gifting; Ideal for a bookworm; Compact for travelling
$10.99
SaleBestseller No. 5
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
I Will Teach You to Be Rich: No Guilt. No Excuses. Just a 6-Week Program That Works (Second Edition)
It can be a gift option; Comes with secure packaging; Helpful in various ways
$9.15

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More post from the Money Desk

  1. The Money DeskBlogTheFinanceBase07 MAR 2625 minWhat Is a 457 Plan?
  2. The Money DeskBlogTheFinanceBase07 MAR 2621 minTime Value of Money: What It Is and How It Works
  3. The Money DeskBlogTheFinanceBase07 MAR 2627 minAre You Living in One of These Top 10 Most Expensive Cities to Retire?
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.