TfL Help Desk Tricked, Hackers Got “Keys”

Guardian Data Security · High sophistication
Last updated July 30, 2026

Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting remote-access authentication onto a device the attackers controlled. TfL said the intrusion could have caused catastrophic disruption, forced 27,000 staff to reset passwords, and led to theft of data from about 7 million people.

How the Attack Worked

The intrusion into Transport for London's systems began with a single phone call. An attacker called the TfL help desk and pretended to be an employee struggling to access the network remotely. This simple pretext, presenting as a frustrated colleague in need of quick help, was enough to get a call handler to reset the authentication process onto a device that was actually controlled by the attackers.

From that single foothold, the attackers escalated their access and created a domain admin account, described in court as the keys to the kingdom. That level of access allowed them to move deep into TfL's environment, well beyond what a single remote-access reset would normally suggest.

Why It Succeeded

The attack succeeded because a routine support interaction, restoring remote access for a supposed employee, was treated as low risk when it should have been treated as a high-risk identity change. Resetting authentication onto a new device is functionally similar to re-enrolling someone's MFA, and that kind of change deserves stronger scrutiny than a simple password reset.

Time pressure and confusion likely played a role too. Employees who call in with access problems are often stressed and want a fast fix, and that urgency can push support staff toward resolving the issue quickly rather than pausing to verify identity more rigorously.

What to Watch For

  • A caller requesting that authentication or MFA be reset to a new or different device during a support call
  • Identity verification that feels rushed or superficial under pressure to restore access quickly
  • Requests that go beyond restoring access and instead change the authentication method itself

Building Resistance

Organizations can reduce this risk by training help desk and IAM support staff to flag any authentication or device re-enrollment request as a high-risk change. This can include requiring manager approval or a call-back to a previously known phone number before making the change.

Building a simple stop-and-verify step for urgent access issues also helps, since attackers frequently rely on time pressure and confusion to bypass careful checks. Finally, limiting what a single support interaction can change without additional approvals reduces the chance that one successful social engineering call turns into full-system compromise, as it reportedly did in this case, with attackers gaining domain admin access shortly after the initial reset.

Key findings

  • Initial access came through a phone call to the TfL help desk where the caller impersonated an employee having trouble with remote access.
  • The help desk was tricked into “resetting the authentication process to a device in control of” the attackers.
  • Attackers escalated privileges and created a “domain admin” account described as “the keys to the kingdom.”
  • TfL said the incident (31 Aug–3 Sep 2024) could have caused “catastrophic damage” and “significant and extended transport service degradation and disruption.”
  • Operational impacts included temporary issues with disabled passenger dial-a-ride bookings, loss of live arrival data, and inability to process Oyster/contactless app payments during the response.
  • About 7 million people’s data was stolen and 27,000 staff were forced to reset passwords.

Who’s being targeted

  • Commonly targeted roles: IT Service Desk / Help Desk, IAM / IT Operations, All employees who may call support for remote access.
  • Affected industries: Public transportation, Government / public sector services.
  • Attack channels: vishing.
  • Impersonated: Internal employee calling the TfL help desk.

Red flags to watch for

  • Caller requests an authentication reset to a new or different device during a support call
  • Identity verification is weak or rushed (pressure to fix access quickly)
  • Request results in changing the MFA/authentication device rather than just restoring access
Try Mirage

Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.

Get a demo

Frequently asked questions

How did attackers gain initial access to TfL's systems?

A caller phoned the TfL help desk pretending to be an employee struggling to access the network remotely, and the call handler was tricked into resetting the authentication process onto a device controlled by the attackers.

What did the attackers do after gaining access?

They escalated privileges and created a domain admin account, described in court as "the keys to the kingdom," giving them broad control over TfL's systems.

What was the impact of the TfL breach?

TfL said the incident could have caused catastrophic damage and significant transport service disruption. About 7 million people's data was stolen and 27,000 staff had to reset their passwords.

How can help desks defend against this kind of attack?

Help desks should treat authentication resets and device re-enrollment requests as high-risk changes requiring stronger identity verification, such as manager approval or a call-back to a known number.

Read the video transcript

Three days. One phone call. And TfL nearly had to shut London’s transport down. Two teenagers called the TfL help desk, pretended to be an employee struggling with remote access, and got the agent to reset authentication onto a device they controlled. That one reset let them create a new domain admin account, literally the keys to the kingdom, risking catastrophic disruption and data on around 7 million people. If anyone asks you to move MFA or authentication to a new device, stop and verify with a known manager or callback number before you touch that reset button.

Similar attacks

Scattered Spider Duped TfL Helpdesk to Reset 2FA

Scattered Spider Duped TfL Helpdesk to Reset 2FA

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk into resetting an employee password and 2FA. The attackers kept access for several days, escalated privileges, and ultimately exposed customer…

July 16, 2026
Redact Rebrand Uses IT Helpdesk Vishing

Redact Rebrand Uses IT Helpdesk Vishing

Google says the BlackFile extortion group (UNC6671) rebranded to “Redact” while keeping the same core scam: phone calls that impersonate IT helpdesk staff and push “urgent security migrations.” Victims are directed to spoofed login pages that steal passwords and MFA codes, enabling attackers to…

August 7, 2026
Vishing and Device-Code Tricks Drive Cloud Takeovers

Vishing and Device-Code Tricks Drive Cloud Takeovers

CrowdStrike reports attackers increasingly bypass security tools by using trusted login paths, phone-based IT impersonation, and abuse of legitimate cloud and AI services. The report highlights real intrusions where vishing led to single sign-on takeovers and rapid data theft, and where attackers…

August 6, 2026
Brinks Home Hit via Microsoft Entra Vishing

Brinks Home Hit via Microsoft Entra Vishing

Brinks Home says it is investigating a cybersecurity incident after the ShinyHunters group claimed it broke in by calling employees and tricking them into approving Microsoft Entra authentication actions. The attacker is threatening to publish data it claims to have stolen, including alleged…

July 31, 2026
Defense Supplier Tricked by Fake M365 Share Link

Defense Supplier Tricked by Fake M365 Share Link

IEH Corporation disclosed that an attacker got into its Microsoft 365 email environment after an employee clicked what looked like a legitimate Microsoft file-sharing link from a supposed new business contact. The fake link led to a phony login page that captured the employee’s credentials, letting…

August 7, 2026
Voicemail Phish Steals Microsoft 365 Sessions

Voicemail Phish Steals Microsoft 365 Sessions

Researchers describe an active, widespread email campaign that tricks employees with voicemail-themed messages and steals Microsoft 365 login sessions (including MFA codes). After taking over accounts, attackers quietly search and collect payroll/HR/finance emails and identify people involved in…

August 7, 2026