It Happened on Our Doorstep: What the TfL Hack Teaches Canary Wharf Businesses About Cyber Security

One phone call was all it took to breach Transport for London. 

Two men have just received prison sentences of five years and six months each for pulling it off, and the case is a serious warning for Canary Wharf businesses about what cyber security for businesses really needs to cover. 

The target wasn’t some obscure supplier. It was TfL, the network that gets a large share of Canary Wharf to work every morning. 

If a single phone call can cause this much damage to an organisation that size, it’s worth understanding exactly how it happened. The route in had very little to do with technical skill and everything to do with how a business runs its help desk. 

What Actually Happened 

In late August 2024, two attackers connected to the hacking group Scattered Spider gained unauthorised access to TfL’s internal systems. 

Over the weeks that followed, customer-facing services were disrupted. Online accounts stopped working properly and refunds for pay-as-you-go journeys stalled. 

TfL eventually asked around 30,000 staff to attend in-person appointments to verify their identity and reset their passwords. Data belonging to around 10 million customers was taken during the breach, including names and contact details. 

Buses and Tube trains kept running throughout. This was an attack on TfL’s back-office systems and customer data, not the physical transport network itself. 

Nearly two years later, in July 2026, Owen Flowers and Thalha Jubair were sentenced for their role in the attack. As Computer Weekly reported, the incident has cost TfL close to £40 million to resolve. 

Why This Wasn’t Really a “Hacking” Story 

Here’s the detail that should make every business owner sit up: there was no sophisticated malware involved, no exploited software vulnerability, no dramatic breach of a firewall. 

Reporting on the case describes the attackers building their access by phoning TfL’s IT help desk, impersonating an employee, and persuading a member of staff to reset a password. 

That single phone call was the entry point for one of the costliest cyber incidents in UK corporate history. 

This is the calling card of Scattered Spider and groups like it. Their toolkit is built around people rather than code, using convincing help desk calls, hijacked SIM cards, or repeated MFA prompts sent until someone taps “accept” just to stop the notifications. 

None of it requires writing a line of code. All of it relies on a person making one decision under pressure, often while trying to be helpful. 

For any business that treats passwords and MFA as its main line of defence, that’s worth sitting with. Those tools only work if the person on the other end of the phone follows the process every time, including for a caller who sounds confident, apologetic, or in a genuine hurry. 

What a Cyber-Attack Actually Costs 

The bill for a cyber-attack rarely stops at whatever a ransom note demands, if there’s a ransom note at all. For TfL, and for most businesses that get hit, the costs show up in several places at once: 

  • Operational Disruption: Systems get taken offline while an incident is contained and investigated, sometimes for weeks. TfL’s online services and refund processing stayed affected long after the initial breach. 
  • Financial Cost: Incident response, forensic investigation, legal advice, and the sheer staff time involved (including manually resetting tens of thousands of passwords) all add up. 
  • Reputational Damage: Customers and partners remember who lost their data, particularly when a story runs in the news for months afterwards, as this one has. 
  • Time: Rebuilding processes and restoring trust with staff and customers takes far longer than the breach itself did. 

None of this depends on the size of the organisation. A smaller business faces the same categories of cost, just with a much smaller team to absorb them. 

Could This Happen to a Business in Canary Wharf? 

Canary Wharf has one of the highest concentrations of financial and professional services firms in London, including banks, law firms, consultancies and asset managers that handle sensitive client data every day. 

That mix of sensitive data and comparatively small IT teams is what makes many of these businesses worth targeting. 

Scattered Spider and groups like it don’t need a household name. They go for whichever door opens easiest, whether that’s an outsourced help desk without strict verification or a staff member who’s never seen a social engineering call in action. 

TfL had far more security resources than most Canary Wharf businesses will ever have, and one convincing phone call still got through. Business cyber security is a basic requirement for any business holding data someone else might want. 

What Good Cyber Security Actually Looks Like 

A modern approach to business cyber security assumes credentials will be targeted directly, alongside the usual firewalls and antivirus software. In practice, that means: 

  • Verified identity checks before any password or MFA reset, such as a callback to a number already on file or sign-off from a manager, rather than relying on a date of birth or a security question anyone could guess. 
  • Staff awareness training that covers phone-based social engineering specifically, alongside the email phishing examples most training already includes. 
  • Incident response planning, with an agreed process for containment, communication and recovery already documented before anything goes wrong. 
  • Regular access reviews, so former employees, old contractors and unused accounts don’t sit around as easy targets. 

Getting the Right Support, Close to Home 

If you’re based in Canary Wharf or nearby and would value a second opinion on your current setup, our local IT support team can help. 

A conversation about your help desk verification process, your MFA setup, or your incident response plan doesn’t need to wait until something goes wrong. 

Take a look at our IT support in Canary Wharf page to see how we work with businesses across the Wharf and the rest of London, or book a chat with Dan to talk through where your current setup stands. 

FAQs 

1. What is cyber security for businesses, and why does it matter for smaller companies? 
Cyber security for businesses covers the technical controls and everyday processes a company uses to protect its systems and its people. Smaller companies are just as likely a target as large organisations like TfL, often with fewer resources in place to catch an attack early.

2. How can Canary Wharf businesses protect themselves against help desk social engineering? 
The most effective defence is a verified identity check before any password or MFA reset takes place, alongside staff training that specifically covers phone-based social engineering rather than email phishing alone.

3. What should a business do if it suspects its help desk has been targeted? 
Treat any unusual or urgent-sounding request to reset credentials as a red flag until it’s verified through an agreed process. If a reset has already gone through and something feels off, isolate the affected account and involve your IT support provider immediately. 

4. Do small businesses need the same level of business cyber security as large organisations like TfL? 
Yes, attackers look for the easiest way in rather than the biggest name on the door, and a small business holding sensitive data can be just as attractive a target as a public body with millions of customers.

5. How often should London businesses review their cyber security setup? 
An annual review is a reasonable minimum, with access reviews carried out more frequently, ideally every quarter, so former staff and unused accounts don’t linger as a risk.