
TfL Help Desk Tricked, Hackers Got “Keys”
Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting…
UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer data and disrupted online services, costing TfL about £29 million to remediate.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
Two guys from Scattered Spider rang TfL’s helpdesk, talked their way past 2FA, and it cost about twenty‑nine million pounds to fix. They’d already bought partial TfL logins on criminal forums, then called saying, “Hi, this is James from operations, I’m locked out, can you reset my password and 2FA so I can log in?” They failed identity checks, pushed for an override, and kept trying until a helpdesk worker finally reset the password and 2FA. That one override let them stay inside TfL systems for days. Your move: if a caller can’t cleanly pass identity checks or keeps pushing to bypass normal steps, stop and escalate that 2FA reset to security, do not override it on the call.

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…