TfL requires in-person password resets for 30,000 employees after hack

Share:

​Transport for London (TfL) says that all staff (roughly 30,000 employees) must attend in-person appointments to verify their identities and reset passwords following a cybersecurity incident disclosed almost two weeks ago.

“Resetting 30,000 colleague passwords in person will take some time and we will be prioritising the allocation of appointments centrally,” TfL said on the TfL employee hub.

“This means everyone will be required to attend an appointment at a specified TfL location to reset their password and be verified in-person for access to TfL applications and data,” it added.

The same approach was taken by DICK’S Sporting Goods’ IT staff after an August cyberattack, manually validating employees’ identities on camera before allowing them to regain access to internal systems.

The London public transportation agency first informed the public on September 2 about the cybersecurity breach, assuring customers that there was no evidence of compromised data.

Although the attack did not affect London’s transportation services, it disrupted internal systems, online services, and the agency’s ability to process refunds. As of last Friday, TfL staff continued to face outages and system disruptions, impacting their ability to respond to customer requests and issue refunds for contactless journeys.

This week, an update on TfL’s incident status page revealed that customer data, including names, contact details, and addresses, had been compromised during the attack.

“Some customers may ask questions about the security of our network and their data. First and foremost, we must reassure that our network is safe,” the transport agency added on the TfL employee hub. “Secondly, we’re contacting customers directly about steps being taken regarding their data.”

TfL also confirmed that attackers accessed employee and customer directory data, including email addresses, job titles, and employee numbers. However, it said there was no evidence that other sensitive data, such as banking details, dates of birth, or home addresses, had been compromised.

Suspect arrested by UK’s National Crime Agency

On Thursday, the United Kingdom’s National Crime Agency arrested a 17-year-old Walsall teenager suspected of being connected to the cyberattack on the city’s public transportation agency. The teenager was later released on bail after being questioned by NCA officers.

The NCA also arrested a 17-year-old male from Walsall in July for a possible link to the MGM Resorts ransomware attack. This attack was attributed to the Scattered Spider hacking collective, which acted as an affiliate of the BlackCat ransomware gang.

BleepingComputer asked the NCA if the same individual was arrested again in September but has not yet received a response.

TfL serves more than 8.4 million Londoners through its surface, underground, and Crossrail (jointly managed with the UK’s Transport Department) transport systems.

In May 2023, the agency experienced another data breach when the Clop ransomware gang stole data belonging to approximately 13,000 customers from one of its suppliers’ MOVEit managed file transfer (MFT) servers.

Sergiu Gatlan

Leave a Comment

Your email address will not be published. Required fields are marked *

loader-image
London, GB
10:39 am, Jan 24, 2025
weather icon 10°C
L: 9° | H: 11°
overcast clouds
Humidity: 78 %
Pressure: 996 mb
Wind: 17 mph WSW
Wind Gust: 31 mph
UV Index: 0
Precipitation: 0 mm
Clouds: 97%
Rain Chance: 0%
Visibility: 10 km
Sunrise: 7:49 am
Sunset: 4:35 pm
DailyHourly
Daily ForecastHourly Forecast
Today 9:00 pm
weather icon
9° | 11°°C 0.8 mm 80% 16 mph 78 % 1001 mb 0 mm/h
Tomorrow 9:00 pm
weather icon
3° | 6°°C 1 mm 100% 9 mph 94 % 1009 mb 2.83 mm/h
Sun Jan 26 9:00 pm
weather icon
3° | 8°°C 1 mm 100% 18 mph 97 % 1008 mb 0 mm/h
Mon Jan 27 9:00 pm
weather icon
4° | 6°°C 1 mm 100% 17 mph 90 % 987 mb 0 mm/h
Tue Jan 28 9:00 pm
weather icon
5° | 7°°C 1 mm 100% 13 mph 96 % 999 mb 0 mm/h
Today 12:00 pm
weather icon
9° | 10°°C 0.8 mm 80% 16 mph 78 % 997 mb 0 mm/h
Today 3:00 pm
weather icon
8° | 10°°C 0 mm 0% 13 mph 70 % 998 mb 0 mm/h
Today 6:00 pm
weather icon
6° | 8°°C 0 mm 0% 8 mph 66 % 1000 mb 0 mm/h
Today 9:00 pm
weather icon
6° | 6°°C 0 mm 0% 6 mph 68 % 1001 mb 0 mm/h
Tomorrow 12:00 am
weather icon
5° | 5°°C 0 mm 0% 5 mph 85 % 1000 mb 0 mm/h
Tomorrow 3:00 am
weather icon
5° | 5°°C 0 mm 0% 4 mph 93 % 998 mb 0 mm/h
Tomorrow 6:00 am
weather icon
5° | 5°°C 0.52 mm 52% 3 mph 94 % 998 mb 0 mm/h
Tomorrow 9:00 am
weather icon
3° | 3°°C 1 mm 100% 9 mph 84 % 1003 mb 2.83 mm/h
Name Price24H (%)
Bitcoin(BTC)
€100,200.62
3.17%
Ethereum(ETH)
€3,233.70
5.76%
XRP(XRP)
€3.03
2.37%
Tether(USDT)
€0.95
0.06%
Solana(SOL)
€251.07
6.68%
Dogecoin(DOGE)
€0.341548
2.31%
USDC(USDC)
€0.95
0.00%
Shiba Inu(SHIB)
€0.000019
1.14%
Pepe(PEPE)
€0.000014
4.27%
Peanut the Squirrel(PNUT)
€0.330956
-4.27%
Scroll to Top