ctipilot.ch

Transport for London 2024 intrusion

incident · incident:tfl-scattered-spider-2024

Scattered Spider members plead guilty over the 2024 Transport for London intrusion.

Coverage timeline
2
first 2026-06-23 → last 2026-07-19
Peak priority
high
1 high · 1 notable
Sources cited
6
6 hosts
Sections touched
2
updates, weekly-multi-day
Co-occurring entities
1
see Related entities below
ATT&CK techniques
8
pinned v19.1 · see below
2026-07-172 appearances2026-07-19

ATT&CK techniques

8 techniques observed across 2 entries — derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.1 · compare on the matrix · Navigator layer (JSON)

Reconnaissance TA0043

T1589.001Gather Victim Identity Information: Credentials×1

Adversaries may gather credentials that can be used during targeting. Account credentials gathered by adversaries may be those directly associated with the target victim organization or attempt to take advantage of the tendency for users to use the same passwords across personal and business accounts.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

Initial Access TA0001

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

T1566.004Phishing: Spearphishing Voice×2

Adversaries may use voice communications to ultimately gain access to victim systems. Spearphishing voice is a specific variant of spearphishing. It is different from other forms of spearphishing in that it employs the use of manipulating a user into providing access to systems through a phone call or other forms of voice communications. Spearphishing frequently involves social engineering techniques, such as posing as a trusted source (ex: Impersonation) and/or creating a sense of urgency or alarm for the recipient.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

Persistence TA0003

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

Privilege Escalation TA0004

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

T1098Account Manipulation×1

Adversaries may manipulate accounts to maintain and/or elevate access to victim systems. Account manipulation may consist of any action that preserves or modifies adversary access to a compromised account, such as modifying credentials or permission groups. These actions could also include account activity designed to subvert security policies, such as performing iterative password updates to bypass password duration policies and preserve the life of compromised credentials.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

Stealth TA0005

T1078Valid Accounts×1

Adversaries may obtain and abuse credentials of existing accounts as a means of gaining Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Compromised credentials may be used to bypass access controls placed on various resources on systems within the network and may even be used for persistent access to remote systems and externally available services, such as VPNs, Outlook Web Access, network devices, and remote desktop. Compromised credentials may also grant an adversary increased privilege to specific systems or access to restricted areas of the network. Adversaries may choose not to use malware or tools in conjunction with the legitimate access those credentials provide to make it harder to detect their presence.

Evidence: 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing · ATT&CK page ↗

T1078.004Valid Accounts: Cloud Accounts×1

Valid accounts in cloud environments may allow adversaries to perform actions to achieve Initial Access, Persistence, Privilege Escalation, or Defense Evasion. Cloud accounts are those created and configured by an organization for use by users, remote support, services, or for administration of resources within a cloud service provider or SaaS application. Cloud Accounts can exist solely in the cloud; alternatively, they may be hybrid-joined between on-premises systems and the cloud through syncing or federation with other identity sources such as Windows Active Directory.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Credential Access TA0006

T1528Steal Application Access Token×1

Adversaries can steal application access tokens as a means of acquiring credentials to access remote systems and resources.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

T1606.002Forge Web Credentials: SAML Tokens×1

An adversary may forge SAML tokens with any permissions claims and lifetimes if they possess a valid SAML token-signing certificate. The default lifetime of a SAML token is one hour, but the validity period can be specified in the <code>NotOnOrAfter</code> value of the <code>conditions ...</code> element in a token. This value can be changed using the <code>AccessTokenLifetime</code> in a <code>LifetimeTokenPolicy</code>. Forged SAML tokens enable adversaries to authenticate across services that use SAML 2.0 as an SSO (single sign-on) mechanism.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Lateral Movement TA0008

T1550.001Use Alternate Authentication Material: Application Access Token×1

Adversaries may use stolen application access tokens to bypass the typical authentication process and access restricted accounts, information, or services on remote systems. These tokens are typically stolen from users or services and used in lieu of login credentials.

Evidence: 2026-07-19/weekly-w29-identity-trust-relationship-abuse · ATT&CK page ↗

Story timeline

  1. 2026-07-19The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access
    weekly-multi-dayIdentity attacks converged on abusing trust, not breaking it — OAuth/SSO vishing, a client_id oracle, a Moodle JWT forgery, and helpdesk-vishing resets
  2. 2026-07-17Scattered Spider duo sentenced to 5.5 years each over the 2024 Transport for London intrusion — court evidence details the helpdesk-vishing/MFA-reset chain
    updatesTfL hackers sentenced; court record confirms the credential-purchase → helpdesk-vishing → MFA-reset access chain

Where this entity is cited

  • updates1
  • weekly-multi-day1

Source distribution

  • cps.gov.uk1 (17%)
  • github.com1 (17%)
  • microsoft.com1 (17%)
  • nationalcrimeagency.gov.uk1 (17%)
  • proofpoint.com1 (17%)
  • theregister.com1 (17%)

Co-occurring entities

Derived — referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.

Entries about Transport for London 2024 intrusion (2)

2026-07-19 · view entry permalink →

HIGHNATOA1

The week's identity intrusions all abused a trusted relationship rather than breaking authentication — OAuth consent and secret reuse, forged and unverified tokens, and helpdesk process abuse turned valid trust into valid-account access

The prior weekly documented M365 account-takeover converging on auth flows Conditional Access rarely gates — device-code, ROPC and AiTM. This week the pattern moved one layer up: the intrusions abused trust that had already been granted rather than the authentication event itself, and each left detection thin in a different way.

Two strands are the same actor. Microsoft Threat Intelligence documented a year of ShinyHunters-associated (UNC6240) tradecraft against Salesforce-integrated SaaS through three paths — vishing-driven malicious OAuth consent (a fake Data Loader app), SaaS supply-chain OAuth-secret reuse (Salesloft Drift, Gainsight, and Storm-3138's Klue compromise), and guest-access Aura abuse — none of which exploited a Salesforce vulnerability; each instead abused trusted OAuth relationships (Microsoft, 2026-07-13); the same vishing-to-Entra-SSO tradecraft then appeared in Abbott's confirmed intrusion into its Cancer Diagnostics (Exact Sciences) systems. Proofpoint showed a subtler variant: an attacker POSTing credentials to the Entra ID ROPC token endpoint with an arbitrary unregistered client_id reads the differential AADSTS errors as a credential-validity oracle — AADSTS700016 ("application not found") is returned only when both username and password are correct — while the unregistered id leaves a blank application name in the sign-in log, defeating detections that correlate by app (Proofpoint, 2026-07-13).

The token-trust failure reached its extreme in Moodle's official Microsoft 365 integration: CVE-2026-54733 authenticated users from a JWT's upn claim "without ever verifying the JWT signature," so knowing or enumerating any email — an administrator's included — yielded that user's session and "effectively full site takeover" (Microsoft o365-moodle GHSA, 2026-07-06). And the human-process layer got its case-law record: at the Scattered Spider TfL sentencing, the court heard the pair purchased partial TfL credentials from "well-known criminal forums" and socially engineered a TfL helpdesk worker into resetting an employee account's password and, over multiple attempts, its 2FA, then used that access (The Register, 2026-07-16).

Builds on: 2026-07-14/microsoft-maps-shinyhunters-salesforce-oauth-abuse · 2026-07-18/abbott-exact-sciences-shinyhunters-entra-sso-vishing · 2026-07-15/proofpoint-oauth-client-id-spoofing-entra-id-evasion · 2026-07-18/moodle-local-o365-jwt-forgery-admin-takeover-cve-2026-54733 · 2026-07-17/scattered-spider-tfl-sentencing-helpdesk-vishing

synthesis19 Jul 23:46Zmulti-sourceOpen finding ↗

2026-07-17 · view entry permalink →

NOTABLEupdateNATOA1

Scattered Spider duo sentenced to 5.5 years each over the 2024 Transport for London intrusion — court evidence details the helpdesk-vishing/MFA-reset chain

UPDATE · originally covered Two Scattered Spider members plead guilty over the 2024 Transport for London intrusion (2026-06-23)

the guilty-plea entry recorded that two Scattered Spider members admitted the 2024 TfL intrusion but did not carry the access mechanics. The 2026-07-16 sentencing (five years six months each, at Woolwich Crown Court) put the chain on the court record, and it is the reason to revisit this. The pair bought partial TfL employee credentials from criminal forums, then "impersonated an employee and socially engineered a TfL helpdesk worker into resetting the password for their account" and, over multiple attempts, reset the account's 2FA, using the reset credentials for initial and sustained access (The Register, 2026-07-16). The NCA confirmed the impact scale — "a total of 148 systems became inoperable, including critical ones that required significant manual workarounds and delays" (NCA, 2026-07-16) — and TfL later established that data on roughly 7 million users had been accessible, far beyond the ~5,000 initially believed (The Register, 2026-07-16). The CPS put the remediation cost at £29 million (CPS, 2026-07-16).

a total of 148 systems became inoperable, including critical ones that required significant manual workarounds and delays.

UK National Crime Agency

Flowers and Jubair purchased partial TfL credentials from "well-known criminal forums" and used those to reset the 2FA on employee accounts, a process that took multiple attempts.

Woolwich Crown Court heard that the pair impersonated an employee and socially engineered a TfL helpdesk worker into resetting the password for their account.

The Register 2026-07-16
incident17 Jul 04:35Zmulti-sourceOpen finding ↗