Transport for London Data Breach History
WebsiteTransport for London provides transportation or logistics services.
This page shows all data breaches of Transport for London. View the complete breach timeline, records exposed, root causes, and AI breach risk score. BreachHistory tracks disclosed data breaches worldwide.
Data Breach Timeline — All Transport for London Breaches
- 2024 2024 Transport for London — Scattered Spider; ~10M contact records; subset (~5k) Oyster refund / banking fields 10.0M records Share
- 2024 2024 Transport for London — 10M customers (Scattered Spider) 10.0M records Share
- 2023 2023 TfL — ~13,000 Ulez / Congestion Charge records via supplier MOVEit (Clop) 13.0K records Share
Transport for London Data Breach Summary
This page tracks the Transport for London data breach history and cybersecurity incidents affecting Transport for London (United Kingdom). BreachHistory currently indexes 3 publicly disclosed or catalogued incidents spanning 2023 through 2024, with approximately 20.0 million records reported as exposed across all indexed events. These totals may include overlapping datasets or third-party estimates and should not be interpreted as unique affected users.
The Transport for London breach timeline includes major data breaches, cyber attacks, data leaks, credential exposures, API abuse, and other security incidents. Each incident provides details on the estimated records exposed, attack method, affected data types, and supporting public sources. Currently, 0 incidents are company-confirmed.
Largest Transport for London Data Breaches
The largest indexed incidents include the 2024 Transport for London — 10M customers (Scattered Spider), the 2024 Transport for London — Scattered Spider; ~10M contact records; subset (~5k) O…, and the 2023 TfL — ~13,000 Ulez / Congestion Charge records via supplier MOVEit (Clop). Record counts originating from threat actors or leak sites should be treated as estimates unless confirmed by Transport for London or a regulator. Below is the list of large data breaches:
- 2024 2024 Transport for London — 10M customers (Scattered Spider) — about 10.0M records exposed · Catalogued incident
- 2024 2024 Transport for London — Scattered Spider; ~10M contact records; subset (~5k) Oyster refund / banking fields — about 10.0M records exposed · Catalogued incident
- 2023 2023 TfL — ~13,000 Ulez / Congestion Charge records via supplier MOVEit (Clop) — about 13.0K records exposed · Catalogued incident
What Information Was Exposed?
Depending on the incident, exposed data may include email addresses, phone numbers, names, physical addresses, bank account details, and other personal information (PII). The exact data varies between incidents, so review each breach page before assuming your information was affected.
Transport for London Data Breach 2026
At the time of this update, no Transport for London data breach has been catalogued for 2026. New incidents are added as official disclosures, regulatory filings, or credible cybersecurity reports become available.
What To Do If You Were Affected
If you believe your account may have been involved in a Transport for London data breach, change any reused passwords, enable multi-factor authentication (MFA), monitor your account for suspicious activity, and be cautious of phishing emails or fake breach notifications.
This Transport for London breach history is maintained by BreachHistory using public disclosures, regulatory filings, security research, and clearly labelled third-party claims. For the complete breach timeline, records exposed, incident details, and AI Breach Risk Score, explore the sections on this page.