Transport for London confirms personal data of 10 million customers stolen in 2024 cyber-attack
In 2024, Transport for London (TfL) suffered one of the largest cyber-attacks in British history, affecting around 10 million people. Initially, TfL only acknowledged that ‘some’ customers were impacted, but a full review has revealed the extensive scale of the breach. Hackers from the Scattered Spider crime group accessed internal systems, disrupting online services and causing an estimated £39 million in damages. The stolen database contained names, email addresses, phone numbers and physical addresses. Despite notifying over 7 million customers via email, many affected individuals may not have read the alerts or did not have an email registered, leaving them unaware of the breach. TfL identified about 5,000 customers at higher risk due to potential access to Oyster card refund data, including bank details, and provided them with support. Experts highlight that transparency is critical after such incidents to help protect against fraud, yet UK law does not require full disclosure of affected individuals. Comparatively, companies in other countries have publicly shared breach details to assist customers. The Information Commissioner’s Office (ICO) reviewed the case and found TfL’s handling appropriate, deciding that no further action was necessary. The trial of two British teenagers accused of the hack is due to begin in June 2026. The risk to individuals remains low, but stolen data may increase vulnerability to scams in the future.
