Hackers who gained access to heart of London transport network jailed


The data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords.

Over four days in 2024 a pair of teenage hackers had London’s transport network at their mercy. The hackers had burrowed into the heart of Transport for London’s IT systems and held the “keys to the kingdom”.

While the main tube and bus networks were not directly affected, the dial-a-ride service for disabled passengers was unable to process bookings for a period. The head of TfL, Andy Lord – a veteran of British Airways – said the attack was the worst incident he had faced in his career.

Read more…
Source:  The Guardian


Sign up for the Cyber Security Review Newsletter
The latest cyber security news and insights delivered right to your inbox


Related:

  • UK: Contact details and national security numbers could have been stolen from Southern Water customers following cyber attack

    February 12, 2024

    The announcement, which went live on Southern Water’s website earlier today (February 12), confirms that ‘a limited part’ of the company’s server estate is at risk following an illegal intrusion earlier this year. Apologising for the breach, a spokesperson confirmed that the company is working with “expert technical advisers to confirm who is at risk,” and ...

  • Deputy Prime Minister hosts first global conference targeting ‘hackers for hire’ and malicious use of commercial cyber tools

    February 6, 2024

    UK, and France, hosting 35 nations at inaugural conference to tackle proliferation and irresponsible use of commercial cyber intrusion tools and services. Deputy Prime Minister Oliver Dowden will launch new international agreement, signed by participants, to take joint-action – the ‘Pall Mall Process’. States will be joined by big tech leaders, legal experts, and human rights defenders, ...

  • UK: Thousands of EU citizens ‘wrongly fined for breaching Ulez rules’ in potential record data breach

    January 26, 2024

    Hundreds of thousands of EU citizens were wrongly fined for driving in London’s Ultra Low Emission Zone (Ulez), amid claims of a record data breach. Several EU countries have accused Transport for London (TfL) of illegally obtaining the names and addresses of their citizens to issue the penalties, The Guardian reports. The paper said more than ...

  • UK councils remain downed by cyberattack

    January 26, 2024

    Three local councils in the United Kingdom continue to experience disruption to their online services, a week after confirming a cyberattack had knocked some systems offline. The councils for Canterbury, Dover, and Thanet — all of which are based in the U.K. county of Kent and have a combined population of almost 500,000 residents — said ...

  • UK: Cybercriminals claim to have stolen data from Southern Water

    January 24, 2024

    Cybercriminals claim they have stolen data from a water company’s IT systems. Southern Water, which has hundreds of thousands of customers in Kent, says it has detected suspicious activity and launched an investigation led by cybersecurity experts. But it says there is no evidence to suggest “customer relationships or financial systems” have been affected. In a ...

  • New TTPs observed in Mint Sandstorm campaign targeting high-profile individuals at universities and research orgs

    January 17, 2024

    Since November 2023, Microsoft has observed a distinct subset of Mint Sandstorm (PHOSPHORUS) targeting high-profile individuals working on Middle Eastern affairs at universities and research organizations in Belgium, France, Gaza, Israel, the United Kingdom, and the United States. In this campaign, Mint Sandstorm used bespoke phishing lures in an attempt to socially engineer targets into downloading ...