Scattered Spider Duped TfL Helpdesk to Reset 2FA

The Register Security · High sophistication
Last updated July 16, 2026

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer data and disrupted online services, costing TfL about £29 million to remediate.

Key findings

  • Authorities said the attackers bought partial TfL credentials on criminal forums, then targeted account recovery to reset 2FA.
  • They impersonated an employee and persuaded TfL helpdesk staff to reset a password.
  • The attackers maintained access from Aug 31 to Sept 3, 2024 and worked to elevate privileges and reach key internal systems.
  • TfL later said about 7 million users’ data was accessed, and remediation costs reached £29 million.
  • The article explicitly links Scattered Spider to phishing, vishing, and social engineering as their common entry tactics.

Who’s being targeted

  • Commonly targeted roles: IT Helpdesk / Service Desk, IT Operations, Security Operations (SOC), Identity & Access Management (IAM), All employees (especially remote workers).
  • Affected industries: Public transportation, Government/public services, Healthcare (mentioned as other targets).
  • Attack channels: vishing.
  • Impersonated: TfL employee (legitimate staff member).

Awareness takeaways

  • Helpdesk staff should require strong identity verification before any password or 2FA reset, especially when the request comes via phone.
  • Treat repeated 2FA reset attempts as a high-risk signal and escalate to security for review before completing resets.
  • Assume attackers may buy partial credentials on criminal forums; strengthen monitoring and controls around account recovery and “valid account” misuse.
  • Engage law enforcement early during major incidents to improve the chances of identifying and prosecuting offenders.

Red flags to watch for

  • Caller cannot verify identity using established checks but pressures for an immediate reset
  • Repeated or multiple attempts to reset 2FA for the same account
  • Request to bypass normal recovery steps or use an unusual method
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Two guys from Scattered Spider rang TfL’s helpdesk, talked their way past 2FA, and it cost about twenty‑nine million pounds to fix. They’d already bought partial TfL logins on criminal forums, then called saying, “Hi, this is James from operations, I’m locked out, can you reset my password and 2FA so I can log in?” They failed identity checks, pushed for an override, and kept trying until a helpdesk worker finally reset the password and 2FA. That one override let them stay inside TfL systems for days. Your move: if a caller can’t cleanly pass identity checks or keeps pushing to bypass normal steps, stop and escalate that 2FA reset to security, do not override it on the call.

Similar attacks

Fake IT Calls Steal Microsoft 365 Access

Fake IT Calls Steal Microsoft 365 Access

Microsoft reports a real-world campaign where attackers call or text employees’ personal phones while posing as internal IT. Victims are pushed to “update” passkeys/MFA/SSO and click a link to a fake Microsoft sign-in page, letting attackers get into Microsoft 365 and quietly pull email and files…

September 10, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
TfL Help Desk Tricked, Hackers Got “Keys”

TfL Help Desk Tricked, Hackers Got “Keys”

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting remote-access authentication onto a device the attackers controlled. TfL said the intrusion could have caused catastrophic disruption, forced…

July 16, 2026
Passkey Helpdesk Scam Hijacks Microsoft 365

Passkey Helpdesk Scam Hijacks Microsoft 365

Microsoft reports active intrusions where attackers trick employees with “passkey/SSO update” helpdesk pretexts delivered by phone, SMS, or even Microsoft Teams. Victims are sent to lookalike Microsoft sign-in pages or guided through device-code sign-in, letting attackers capture session access and…

September 9, 2026
ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ShinyHunters Impersonation Call Tricked ReliaQuest MFA

ReliaQuest disclosed a real social engineering incident where attackers registered a lookalike domain, hosted a fake ReliaQuest SSO page, and called employees while impersonating a named security employee. One employee entered credentials and approved an MFA push, briefly giving the attacker…

August 25, 2026
Phish Adds Passkey That Survives Reset

Phish Adds Passkey That Survives Reset

Researchers described iAuthFlow v2, a phishing toolkit that steals a live Google login session and then uses that access to enroll an attacker-controlled passkey. Because passkeys are separate login methods, the attacker can often get back into the account even after the victim changes their…

August 24, 2026