Between 31 August and 3 September 2024, Scattered Spider got into Transport for London with partial employee credentials from criminal marketplaces, then pushed social engineering until a two-factor authentication reset stuck. According to the National Crime Agency, privilege escalation came next. Public reporting does not name a Temporary Access Pass, a spoofed login page, or an adversary-in-the-middle kit. What is documented is ugly enough: 148 systems inoperable, customer-refund paths hit, about £29 million in loss and recovery costs, and every one of TfL’s 27,000 employees marched in for an in-person password reset. Owen Flowers and Thalha Jubair each drew five years and six months. At Flowers’ earlier arrest he was also found hacking SSM Health Care Corporation and Sutter Health systems.

If you want the prevention angle, read the related article on mfa2point0.com.

FAQ

How did Scattered Spider get into Transport for London?

Scattered Spider entered Transport for London by combining marketplace-sourced partial employee credentials with social engineering that produced a two-factor authentication reset after multiple attempts. According to the National Crime Agency, the network was infiltrated between 31 August and 3 September 2024, and privilege escalation followed the 2FA reset. Public reporting does not establish helpdesk call scripts, exact reset mechanics, or what the marketplace listings contained.

Did legacy MFA fail, or was the helpdesk the weak point?

Both credential-phase paths failed in sequence on the TfL intrusion. Marketplace or reused employee secrets were still useful enough to start authentication and justify recovery contact. The recovery or helpdesk path then re-issued or reset 2FA after social engineering without strong proof it was the real employee. That is the same industrial class as other workforce helpdesk resets, including the later M&S helpdesk password-reset case: a live human is coached into handing over a transferable recovery factor. Public reporting does not name TAP issuance or an AiTM page for TfL.

Once the 2FA reset landed, what could MFA still stop?

Nothing useful in the later phases. After attackers held reset factors and a trusted TfL workforce identity, privilege escalation and access to operational and customer-refund systems were post-authentication work. MFA does not revoke a session the IdP already accepted, and it does not undo lateral movement or data access after that point. Closing the phishable login and recovery path is the prevention claim. Cleanup after a trusted identity is already inside is a harder, separate problem.

Why did all 27,000 TfL employees need in-person password resets?

According to the National Crime Agency, the TfL response forced every employee to attend a TfL office for a password reset because the intrusion had reached deep enough that remote credential hygiene was not trusted. One hundred forty-eight systems were inoperable, including critical paths that needed manual workarounds. Disruption hit Dial-a-Ride, concessionary travel cards, a digital payments channel, contactless ticketing extension work, and Oyster photocard applications. Reported loss and recovery costs reached £29 million. The NCA also cited an estimate of up to £56 billion in UK economy cost if the transport network had shut down.

Who was sentenced, and how does this fit Scattered Spider’s pattern?

Thalha Jubair and Owen Flowers pleaded guilty and were each sentenced to five years and six months’ imprisonment. NCA Deputy Director Paul Foster called it the largest cyber crime prosecution ever brought before the UK courts and described Scattered Spider as the most significant cybercrime threat to the UK in recent years. FBI Cyber Division Assistant Director Brett Leatherman said the group has repeatedly relied on data extortion, SIM-swap attacks, and other social engineering techniques. Those FBI remarks describe the group pattern. Public reporting on this page does not establish TfL-specific SIM-swap steps.