Scattered Spider Duped TfL Helpdesk to Reset 2FA

The Register Security · High sophistication
Last updated July 16, 2026

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer data and disrupted online services, costing TfL about £29 million to remediate.

Key findings

  • Authorities said the attackers bought partial TfL credentials on criminal forums, then targeted account recovery to reset 2FA.
  • They impersonated an employee and persuaded TfL helpdesk staff to reset a password.
  • The attackers maintained access from Aug 31 to Sept 3, 2024 and worked to elevate privileges and reach key internal systems.
  • TfL later said about 7 million users’ data was accessed, and remediation costs reached £29 million.
  • The article explicitly links Scattered Spider to phishing, vishing, and social engineering as their common entry tactics.

Who’s being targeted

  • Commonly targeted roles: IT Helpdesk / Service Desk, IT Operations, Security Operations (SOC), Identity & Access Management (IAM), All employees (especially remote workers).
  • Affected industries: Public transportation, Government/public services, Healthcare (mentioned as other targets).
  • Attack channels: vishing.
  • Impersonated: TfL employee (legitimate staff member).

Awareness takeaways

  • Helpdesk staff should require strong identity verification before any password or 2FA reset, especially when the request comes via phone.
  • Treat repeated 2FA reset attempts as a high-risk signal and escalate to security for review before completing resets.
  • Assume attackers may buy partial credentials on criminal forums; strengthen monitoring and controls around account recovery and “valid account” misuse.
  • Engage law enforcement early during major incidents to improve the chances of identifying and prosecuting offenders.

Red flags to watch for

  • Caller cannot verify identity using established checks but pressures for an immediate reset
  • Repeated or multiple attempts to reset 2FA for the same account
  • Request to bypass normal recovery steps or use an unusual method
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo
Read the video transcript

Two guys from Scattered Spider rang TfL’s helpdesk, talked their way past 2FA, and it cost about twenty‑nine million pounds to fix. They’d already bought partial TfL logins on criminal forums, then called saying, “Hi, this is James from operations, I’m locked out, can you reset my password and 2FA so I can log in?” They failed identity checks, pushed for an override, and kept trying until a helpdesk worker finally reset the password and 2FA. That one override let them stay inside TfL systems for days. Your move: if a caller can’t cleanly pass identity checks or keeps pushing to bypass normal steps, stop and escalate that 2FA reset to security, do not override it on the call.

Similar attacks

QR-Code PDFs Steal Microsoft 365 Logins

QR-Code PDFs Steal Microsoft 365 Logins

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

July 28, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026