2023 TfL — ~13,000 Ulez / Congestion Charge records via supplier MOVEit (Clop)
Data compromised
Driver / charge-account contact and scheme data as described in TfL supplier narratives and trade press (categories not fully uniform in first-wave reporting)
Technical writeup
In mid-June 2023 Transport for London stated a third-party supplier using Progress MOVEit Transfer was caught up in the global Clop ransomware zero-day campaign (CVE-2023-34362). UK press summarized impact to TfL as on the order of 13,000 people with data from Ultra Low Emission Zone (Ulez) and Congestion Charge–related processing; the incident was distinct from TfL’s later 2024 direct enterprise intrusion.
Root cause
Third-party supplier compromise of MOVEit Transfer; mass exploitation by Clop affiliates