TfL requires in-person password resets for 30,000 employees after hack

Share:

​Transport for London (TfL) says that all staff (roughly 30,000 employees) must attend in-person appointments to verify their identities and reset passwords following a cybersecurity incident disclosed almost two weeks ago.

“Resetting 30,000 colleague passwords in person will take some time and we will be prioritising the allocation of appointments centrally,” TfL said on the TfL employee hub.

“This means everyone will be required to attend an appointment at a specified TfL location to reset their password and be verified in-person for access to TfL applications and data,” it added.

The same approach was taken by DICK’S Sporting Goods’ IT staff after an August cyberattack, manually validating employees’ identities on camera before allowing them to regain access to internal systems.

The London public transportation agency first informed the public on September 2 about the cybersecurity breach, assuring customers that there was no evidence of compromised data.

Although the attack did not affect London’s transportation services, it disrupted internal systems, online services, and the agency’s ability to process refunds. As of last Friday, TfL staff continued to face outages and system disruptions, impacting their ability to respond to customer requests and issue refunds for contactless journeys.

This week, an update on TfL’s incident status page revealed that customer data, including names, contact details, and addresses, had been compromised during the attack.

“Some customers may ask questions about the security of our network and their data. First and foremost, we must reassure that our network is safe,” the transport agency added on the TfL employee hub. “Secondly, we’re contacting customers directly about steps being taken regarding their data.”

TfL also confirmed that attackers accessed employee and customer directory data, including email addresses, job titles, and employee numbers. However, it said there was no evidence that other sensitive data, such as banking details, dates of birth, or home addresses, had been compromised.

Suspect arrested by UK’s National Crime Agency

On Thursday, the United Kingdom’s National Crime Agency arrested a 17-year-old Walsall teenager suspected of being connected to the cyberattack on the city’s public transportation agency. The teenager was later released on bail after being questioned by NCA officers.

The NCA also arrested a 17-year-old male from Walsall in July for a possible link to the MGM Resorts ransomware attack. This attack was attributed to the Scattered Spider hacking collective, which acted as an affiliate of the BlackCat ransomware gang.

BleepingComputer asked the NCA if the same individual was arrested again in September but has not yet received a response.

TfL serves more than 8.4 million Londoners through its surface, underground, and Crossrail (jointly managed with the UK’s Transport Department) transport systems.

In May 2023, the agency experienced another data breach when the Clop ransomware gang stole data belonging to approximately 13,000 customers from one of its suppliers’ MOVEit managed file transfer (MFT) servers.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:57 pm, Jan 24, 2025
weather icon 8°C
L: 6° | H: 9°
scattered clouds
Humidity: 86 %
Pressure: 1000 mb
Wind: 6 mph S
Wind Gust: 0 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 40%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:49 am
Sunset: 4:35 pm
DailyHourly
Daily ForecastHourly Forecast
Tomorrow 9:00 pm
weather icon
6° | 9°°C 1 mm 100% 7 mph 91 % 1010 mb 0 mm/h
Sun Jan 26 9:00 pm
weather icon
2° | 8°°C 1 mm 100% 16 mph 91 % 1009 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
6° | 8°°C 1 mm 100% 23 mph 92 % 983 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
8° | 9°°C 1 mm 100% 20 mph 84 % 995 mb 0 mm/h
Wed Jan 29 9:00 pm
weather icon
5° | 8°°C 1 mm 100% 19 mph 90 % 1000 mb 0 mm/h
Tomorrow 12:00 am
weather icon
7° | 8°°C 0 mm 0% 5 mph 86 % 1000 mb 0 mm/h
Tomorrow 3:00 am
weather icon
6° | 7°°C 0 mm 0% 4 mph 88 % 1000 mb 0 mm/h
Tomorrow 6:00 am
weather icon
3° | 5°°C 1 mm 100% 7 mph 91 % 1001 mb 0 mm/h
Tomorrow 9:00 am
weather icon
5° | 5°°C 0.59 mm 59% 6 mph 73 % 1004 mb 0 mm/h
Tomorrow 12:00 pm
weather icon
6° | 6°°C 0.22 mm 22% 7 mph 55 % 1006 mb 0 mm/h
Tomorrow 3:00 pm
weather icon
6° | 6°°C 0 mm 0% 4 mph 56 % 1008 mb 0 mm/h
Tomorrow 6:00 pm
weather icon
4° | 4°°C 0 mm 0% 3 mph 70 % 1009 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 3°°C 0 mm 0% 4 mph 73 % 1010 mb 0 mm/h
Name Price24H (%)
Bitcoin(BTC)
€99,932.45
0.96%
Ethereum(ETH)
€3,170.31
0.75%
XRP(XRP)
€2.95
-0.59%
Tether(USDT)
€0.95
-0.02%
Solana(SOL)
€243.40
2.09%
USDC(USDC)
€0.95
0.00%
Dogecoin(DOGE)
€0.334790
-0.10%
Shiba Inu(SHIB)
€0.000019
-0.27%
Pepe(PEPE)
€0.000014
0.65%
Peanut the Squirrel(PNUT)
€0.341611
3.03%
Scroll to Top