2024 Transport for London — Scattered Spider; ~10M contact records; subset (~5k) Oyster refund / banking fields
Data compromised
Broadly: names, emails, phone numbers, postal addresses; heightened cohort: possible bank account number and sort code via Oyster refund records
Technical writeup
Between late August and early September 2024 TfL detected intrusion attributed in UK reporting to the financially motivated “Scattered Spider” cluster, with significant disruption to online services and public estimates of roughly £39m impact. Customer data exfiltration was characterized as a large contact database: BBC reporting (March 2026) described verification of a stolen file on the order of ten million people with names, email addresses, fixed and mobile phone numbers, and physical addresses; TfL publicly cautioned that roughly 5,000 customers with Oyster card refund workflows faced heightened risk where bank account numbers and sort codes might also have been accessed. The UK ICO closed its regulatory review in February 2025 without further enforcement in the circumstances TfL presented.
Root cause
Criminal intrusion into TfL enterprise systems (detailed forensic attribution beyond press summaries not duplicated here)