Scattered Spider Duped TfL Helpdesk to Reset 2FA

The Register Security · High sophistication
Last updated July 16, 2026

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer data and disrupted online services, costing TfL about £29 million to remediate.

Key findings

  • Authorities said the attackers bought partial TfL credentials on criminal forums, then targeted account recovery to reset 2FA.
  • They impersonated an employee and persuaded TfL helpdesk staff to reset a password.
  • The attackers maintained access from Aug 31 to Sept 3, 2024 and worked to elevate privileges and reach key internal systems.
  • TfL later said about 7 million users’ data was accessed, and remediation costs reached £29 million.
  • The article explicitly links Scattered Spider to phishing, vishing, and social engineering as their common entry tactics.

Who’s being targeted

  • Commonly targeted roles: IT Helpdesk / Service Desk, IT Operations, Security Operations (SOC), Identity & Access Management (IAM), All employees (especially remote workers).
  • Affected industries: Public transportation, Government/public services, Healthcare (mentioned as other targets).
  • Attack channels: vishing.
  • Impersonated: TfL employee (legitimate staff member).

Awareness takeaways

  • Helpdesk staff should require strong identity verification before any password or 2FA reset, especially when the request comes via phone.
  • Treat repeated 2FA reset attempts as a high-risk signal and escalate to security for review before completing resets.
  • Assume attackers may buy partial credentials on criminal forums; strengthen monitoring and controls around account recovery and “valid account” misuse.
  • Engage law enforcement early during major incidents to improve the chances of identifying and prosecuting offenders.

Red flags to watch for

  • Caller cannot verify identity using established checks but pressures for an immediate reset
  • Repeated or multiple attempts to reset 2FA for the same account
  • Request to bypass normal recovery steps or use an unusual method
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Two guys from Scattered Spider rang TfL’s helpdesk, talked their way past 2FA, and it cost about twenty‑nine million pounds to fix. They’d already bought partial TfL logins on criminal forums, then called saying, “Hi, this is James from operations, I’m locked out, can you reset my password and 2FA so I can log in?” They failed identity checks, pushed for an override, and kept trying until a helpdesk worker finally reset the password and 2FA. That one override let them stay inside TfL systems for days. Your move: if a caller can’t cleanly pass identity checks or keeps pushing to bypass normal steps, stop and escalate that 2FA reset to security, do not override it on the call.

Similar attacks

Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
TfL Help Desk Tricked, Hackers Got “Keys”

TfL Help Desk Tricked, Hackers Got “Keys”

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting remote-access authentication onto a device the attackers controlled. TfL said the intrusion could have caused catastrophic disruption, forced…

July 16, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
ChatGPT Billing Phish and Fake Snap Support Scams

ChatGPT Billing Phish and Fake Snap Support Scams

This roundup describes real-world social engineering, including phishing emails that impersonate ChatGPT billing to steal payment card data and a convicted attacker who posed as Snapchat support to trick people into handing over login codes. The common theme is impersonation of trusted brands to…

July 31, 2026
Fake Install Guides and Helpdesk Calls Drive Attacks

Fake Install Guides and Helpdesk Calls Drive Attacks

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result “install guide,” a recruiter outreach, or a helpdesk phone call. The lures push victims to paste commands, install fake software, or reset MFA,…

July 30, 2026
Defense Supplier Tricked by Fake M365 Share Link

Defense Supplier Tricked by Fake M365 Share Link

IEH Corporation disclosed that an attacker got into its Microsoft 365 email environment after an employee clicked what looked like a legitimate Microsoft file-sharing link from a supposed new business contact. The fake link led to a phony login page that captured the employee’s credentials, letting…

August 7, 2026