Header image

Toll of Transport for London hack reaches nearly 10M


Transport for London had data from almost 10 million individuals compromised following a cyberattack in 2024, which was initially reported to have impacted only "some" customers, according to the BBC, which has established the figure after viewing the stolen database.

The attack, attributed to the Scattered Spider crime group, caused £39 million in damages and disrupted TfL's online services. The database contains names, email addresses, phone numbers, and physical addresses. TfL admitted it emailed notifications to over 7 million customers with registered email addresses, but acknowledged a 58% open rate, leaving potentially millions unaware their data was stolen. The company has refused to provide an official total figure. Data protection experts criticized the lack of transparency, with consultant Carl Gotleib stating "it's essential that individuals are informed exactly what has happened to their data." UK companies face no legal requirement to publicly disclose breach totals, unlike in countries such as Japan and South Korea. Security researcher Kevin Beaumont called such disclosure "the most basic requirement for transparency."

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Kelley Damore
Kelley Damore Chief Content Officer CyberRisk Alliance

Kelley Damore is Chief Content Officer at CyberRisk Alliance, where she leads content strategy across the company’s digital brands, research, communities and live events serving CISOs and security practitioners. At CyberRisk Alliance, she is focused on delivering 365-day engagement, trusted journalism and actionable insights to help security leaders navigate an increasingly complex threat landscape.

Upcoming Events

No events found.