
Scattered Spider Duped TfL Helpdesk to Reset 2FA
UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk…
Two teen hackers linked to the Scattered Spider collective gained deep access to Transport for London (TfL) by tricking the TfL help desk into resetting remote-access authentication onto a device the attackers controlled. TfL said the intrusion could have caused catastrophic disruption, forced 27,000 staff to reset passwords, and led to theft of data from about 7 million people.
The intrusion into Transport for London's systems began with a single phone call. An attacker called the TfL help desk and pretended to be an employee struggling to access the network remotely. This simple pretext, presenting as a frustrated colleague in need of quick help, was enough to get a call handler to reset the authentication process onto a device that was actually controlled by the attackers.
From that single foothold, the attackers escalated their access and created a domain admin account, described in court as the keys to the kingdom. That level of access allowed them to move deep into TfL's environment, well beyond what a single remote-access reset would normally suggest.
The attack succeeded because a routine support interaction, restoring remote access for a supposed employee, was treated as low risk when it should have been treated as a high-risk identity change. Resetting authentication onto a new device is functionally similar to re-enrolling someone's MFA, and that kind of change deserves stronger scrutiny than a simple password reset.
Time pressure and confusion likely played a role too. Employees who call in with access problems are often stressed and want a fast fix, and that urgency can push support staff toward resolving the issue quickly rather than pausing to verify identity more rigorously.
Organizations can reduce this risk by training help desk and IAM support staff to flag any authentication or device re-enrollment request as a high-risk change. This can include requiring manager approval or a call-back to a previously known phone number before making the change.
Building a simple stop-and-verify step for urgent access issues also helps, since attackers frequently rely on time pressure and confusion to bypass careful checks. Finally, limiting what a single support interaction can change without additional approvals reduces the chance that one successful social engineering call turns into full-system compromise, as it reportedly did in this case, with attackers gaining domain admin access shortly after the initial reset.
Mirage safely runs attacks like this one against your own team, so you find out what happens before a real adversary does.
A caller phoned the TfL help desk pretending to be an employee struggling to access the network remotely, and the call handler was tricked into resetting the authentication process onto a device controlled by the attackers.
They escalated privileges and created a domain admin account, described in court as "the keys to the kingdom," giving them broad control over TfL's systems.
TfL said the incident could have caused catastrophic damage and significant transport service disruption. About 7 million people's data was stolen and 27,000 staff had to reset their passwords.
Help desks should treat authentication resets and device re-enrollment requests as high-risk changes requiring stronger identity verification, such as manager approval or a call-back to a known number.
Three days. One phone call. And TfL nearly had to shut London’s transport down. Two teenagers called the TfL help desk, pretended to be an employee struggling with remote access, and got the agent to reset authentication onto a device they controlled. That one reset let them create a new domain admin account, literally the keys to the kingdom, risking catastrophic disruption and data on around 7 million people. If anyone asks you to move MFA or authentication to a new device, stop and verify with a known manager or callback number before you touch that reset button.

UK authorities said two Scattered Spider members accessed Transport for London (TfL) by buying partial employee credentials and then tricking TfL’s helpdesk…

Cisco Talos incident responders reported phishing as the most common initial entry method in recent real-world incidents, including an ongoing QR-code phishing…

This weekly roundup describes multiple real-world campaigns where attackers trick people using familiar brands and “verification” prompts to steal credentials…

This bulletin describes multiple real-world social engineering campaigns where attackers trick people into trusting a familiar screen, like a search result…

The article describes real-world ways attackers get around multifactor authentication (MFA), including “push bombing” (MFA fatigue), phishing pages that relay…

Okta says it gained an inside look at “Work Panel,” a polished SaaS-style dashboard that helps voice-phishing (vishing) crews rapidly set up fake login sites…