Hackers who gained access to heart of London transport network jailed


The data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords.

Over four days in 2024 a pair of teenage hackers had London’s transport network at their mercy. The hackers had burrowed into the heart of Transport for London’s IT systems and held the “keys to the kingdom”.

While the main tube and bus networks were not directly affected, the dial-a-ride service for disabled passengers was unable to process bookings for a period. The head of TfL, Andy Lord – a veteran of British Airways – said the attack was the worst incident he had faced in his career.

Read more…
Source:  The Guardian


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • Northern Ireland: Two people charged over alleged New IRA activity after PSNI data breach

    February 13, 2025

    Two men have appeared in court charged with terrorism offences linked to a major PSNI data breach. Brian Francis Cavlan, 49, from Coronation Park, Aughnacloy and Rory Martin Logan, 43, with an address given as HMP Maghaberry, appeared before court on Thursday. They were arrested on Tuesday as part of an ongoing police investigation into the ...

  • Gambling firms are secretly sharing your data with Facebook

    February 12, 2025

    While you might think you’re hitting the jackpot, whether you’ve consented to it or not, online gambling sites are playing with your data. Users’ data, including details of webpages they visited and buttons they clicked, are being shared with Meta, Facebook’s parent company. The Observer reports that over 150 UK gambling websites have been extracting visitor ...

  • Paris AI summit: Why won’t US, UK sign global artificial intelligence pact?

    February 12, 2025

    The United States and United Kingdom have refused to sign an Artificial Intelligence Action Summit declaration calling for policies “ensuring AI is open, inclusive, transparent, ethical, safe, secure and trustworthy”. The summit in Paris on Monday and Tuesday brought together representatives from more than 100 countries to discuss how to reach a consensus on guiding the ...

  • US, UK crack down on Russian bulletproof hosting service ZServers for LockBit partnership

    February 12, 2025

    Russia-based bulletproof hosting services provider (BPH) ZServers has been sanctioned by the United States, Australia, and the United Kingdom for its alleged involvement with the LockBit ransomware group. In a press release, the Australian Federal Police (AFP) said ZServers was providing services to threat actors responsible for the Medibank Private breach that happened in October 2022. ...

  • U.K. orders Apple to let it spy on users’ encrypted accounts

    February 7, 2025

    Security officials in the United Kingdom have demanded that Apple create a back door allowing them to retrieve all the content any Apple user worldwide has uploaded to the cloud, people familiar with the matter told The Washington Post. The British government’s undisclosed order, issued last month, requires blanket capability to view fully encrypted material, not ...

  • UK: “Cyber warriors” to be fast-tracked to battle on “a new front line”

    February 7, 2025

    “Cyber warriors” are being fast-tracked into the armed forces after Britain faced more than 90,000 online attacks in the last two years. Specialist recruits will see their basic training cut from 10 weeks to a month and be offered starting salaries of £40,000, one of the highest in the armed forces, as the UK looks to ...