Skip to content
TFL hack that cost £39m saw 10million people have their data stolen

TFL hack that cost £39m saw 10million people have their data stolen

Dailymail • March 6, 2026

Some ten million people had their data stolen when Transport for London suffered one of the UK's biggest ever hacks in 2024.

The cyberattack, which was launched by members of the Scattered Spider group, gained access to TfL 's computer systems, disrupted online services and took customers' personal data.

It caused mayhem for Oyster card users, who were unable to use their cards to pay, and TfL was also left unable to register the cards to users' accounts.

It is estimated that TfL suffered a £39 million loss as a result of the attack.

TfL said at the time that 'some' people had been affected, but a copy of the stolen data seen by the BBC has revealed the true number to be around ten million.

The hackers are understood to have downloaded a database holding customer information which contained 15 million lines of data - although it is believed some of these are duplicate entries.

The attack took place in August and September 2024, and while it did not impact transport itself, it did cause many online services and information boards to go offline.

According to the BBC , data stolen includes names, phone numbers, email addresses and addresses.

The cyberattack, which was launched by members of the Scattered Spider group, gained access to TfL's computer systems, disrupted online services and took customers' personal data

TfL said at the time of the attack that 'some' customers had been affected

TfL has now said that it informed 7,113,429 people who had an email address linked to their TfL account the incident.

At the time, it admitted that 5,000 customers were at heightened risk as a result of the hack because their Oyster refund data, containing details such as bank account numbers and sort codes, could have been accessed.

The cyberattack is believed to be one of the largest in British history, although it is difficult to know the exact scale of many hacks because there is no legal obligation for companies to reveal details of any attacks.

But last year Co-op - which suffered a cyberattack that led to weeks of food distribution disruption to its stores - revealed some 6.5 million customers had been affected.

Two teenagers, Thalha Jubair, 19, and Owen Flowers, 18, are awaiting trial over the hack. They have both denied conspiring to commit an authorised act against computer systems belonging to TfL.

Jubair, of Bow, east London, also denied failing to comply with a notice to disclose pins or passwords to devices seized by the police.

Flowers, of Walsall, West Midlands, denied conspiring to commit unauthorised acts against computer systems belonging to SSM Health Care Corporation causing a risk of serious damage to human welfare, and attempting to commit unauthorised acts against computer systems belonging to Sutter Health.

The pair await a four to six-week trial, scheduled to take place from June 8.

Following the 2024 attack, TfL was cleared of any wrongdoing by the UK watchdog, the Information Commissioner's Office.

A Transport for London (TfL) spokesperson said: 'The security of our systems and customer data is extremely important to us and we continually monitor our systems to ensure only those authorised can gain access and continue to take all the necessary actions to protect them.

'At the time of the incident, we identified around 5,000 customers requiring support as we knew that some of their Oyster card refund data may also have been accessed, which could include bank account numbers and sort codes.

'As a precautionary measure, we contacted those customers directly as soon as possible to offer our support and the steps they could take.

'In addition, we publicised that information on customer names and details may have been taken - including email addresses and addresses, where provided. We have kept our customers informed throughout this incident and will continue to take all necessary action.'