TfL Help Desk Tricked, Hackers Got “Keys”

Guardian Data Security · High sophistication
Last updated July 30, 2026

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting remote-access authentication onto a device the attackers controlled. TfL said the intrusion could have caused catastrophic disruption, forced 27,000 staff to reset passwords, and led to theft of data from about 7 million people.

How the Attack Worked

The intrusion into Transport for London's systems began with a single phone call. An attacker called the TfL help desk and pretended to be an employee struggling to access the network remotely. This simple pretext, presenting as a frustrated colleague in need of quick help, was enough to get a call handler to reset the authentication process onto a device that was actually controlled by the attackers.

From that single foothold, the attackers escalated their access and created a domain admin account, described in court as the keys to the kingdom. That level of access allowed them to move deep into TfL's environment, well beyond what a single remote-access reset would normally suggest.

Why It Succeeded

The attack succeeded because a routine support interaction, restoring remote access for a supposed employee, was treated as low risk when it should have been treated as a high-risk identity change. Resetting authentication onto a new device is functionally similar to re-enrolling someone's MFA, and that kind of change deserves stronger scrutiny than a simple password reset.

Time pressure and confusion likely played a role too. Employees who call in with access problems are often stressed and want a fast fix, and that urgency can push support staff toward resolving the issue quickly rather than pausing to verify identity more rigorously.

What to Watch For

  • A caller requesting that authentication or MFA be reset to a new or different device during a support call
  • Identity verification that feels rushed or superficial under pressure to restore access quickly
  • Requests that go beyond restoring access and instead change the authentication method itself

Building Resistance

Organizations can reduce this risk by training help desk and IAM support staff to flag any authentication or device re-enrollment request as a high-risk change. This can include requiring manager approval or a call-back to a previously known phone number before making the change.

Building a simple stop-and-verify step for urgent access issues also helps, since attackers frequently rely on time pressure and confusion to bypass careful checks. Finally, limiting what a single support interaction can change without additional approvals reduces the chance that one successful social engineering call turns into full-system compromise, as it reportedly did in this case, with attackers gaining domain admin access shortly after the initial reset.

Key findings

  • Initial access came through a phone call to the TfL help desk where the caller impersonated an employee having trouble with remote access.
  • The help desk was tricked into “resetting the authentication process to a device in control of” the attackers.
  • Attackers escalated privileges and created a “domain admin” account described as “the keys to the kingdom.”
  • TfL said the incident (31 Aug–3 Sep 2024) could have caused “catastrophic damage” and “significant and extended transport service degradation and disruption.”
  • Operational impacts included temporary issues with disabled passenger dial-a-ride bookings, loss of live arrival data, and inability to process Oyster/contactless app payments during the response.
  • About 7 million people’s data was stolen and 27,000 staff were forced to reset passwords.

Who’s being targeted

  • Commonly targeted roles: IT Service Desk / Help Desk, IAM / IT Operations, All employees who may call support for remote access.
  • Affected industries: Public transportation, Government / public sector services.
  • Attack channels: vishing.
  • Impersonated: Internal employee calling the TfL help desk.

Red flags to watch for

  • Caller requests an authentication reset to a new or different device during a support call
  • Identity verification is weak or rushed (pressure to fix access quickly)
  • Request results in changing the MFA/authentication device rather than just restoring access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain initial access to TfL's systems?

A caller phoned the TfL help desk pretending to be an employee struggling to access the network remotely, and the call handler was tricked into resetting the authentication process onto a device controlled by the attackers.

What did the attackers do after gaining access?

They escalated privileges and created a domain admin account, described in court as "the keys to the kingdom," giving them broad control over TfL's systems.

What was the impact of the TfL breach?

TfL said the incident could have caused catastrophic damage and significant transport service disruption. About 7 million people's data was stolen and 27,000 staff had to reset their passwords.

How can help desks defend against this kind of attack?

Help desks should treat authentication resets and device re-enrollment requests as high-risk changes requiring stronger identity verification, such as manager approval or a call-back to a known number.

Read the video transcript

Three days. One phone call. And TfL nearly had to shut London’s transport down. Two teenagers called the TfL help desk, pretended to be an employee struggling with remote access, and got the agent to reset authentication onto a device they controlled. That one reset let them create a new domain admin account, literally the keys to the kingdom, risking catastrophic disruption and data on around 7 million people. If anyone asks you to move MFA or authentication to a new device, stop and verify with a known manager or callback number before you touch that reset button.

Similar attacks

QR-Code PDFs Steal Microsoft 365 Logins

QR-Code PDFs Steal Microsoft 365 Logins

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

July 28, 2026
How Attackers Bypass MFA in the Real World

How Attackers Bypass MFA in the Real World

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

July 29, 2026