GoFirm
Back to Blog
Case Studies·4 min read

Password resets are execution events. Two teenagers turned one into a £29 million shutdown of London's transport network.

By GoFirm

Owen Flowers, 18, and Thalha Jubair, 20, were sentenced at Woolwich Crown Court on 16 July 2026 for the August 2024 hack of Transport for London (TfL), the authority that runs an average of nine million journeys a day across London's buses, Underground, and Overground. Both pleaded guilty on 22 June 2026 to an offence under Section 3ZA of the Computer Misuse Act 1990, the Act's most serious provision, on the basis that they were reckless as to whether they created a significant risk of serious damage to human welfare. The Crown Prosecution Service says it is the first successful prosecution of its kind, and the National Crime Agency (NCA) is calling it the biggest cybercrime prosecution the UK courts have seen.

The attack itself required no exploit and no malware. According to reporting on the case, Flowers and Jubair bought partial TfL employee credentials on criminal forums, then placed a call to TfL's IT helpdesk, impersonating the credential owner and talking a support agent into resetting the account's password and re-registering its multi-factor authentication. That single reset opened a path into Microsoft Entra ID, the identity platform underpinning staff authentication across TfL's systems. From there, prosecutors say the pair spent the night working through the network, moving between systems while messaging each other on Telegram and sharing a live workspace, recording video of one another's progress as they went.

The intrusion ran from 31 August to 3 September 2024. TfL detected it and pulled its own network offline to contain the pair, a decision the NCA credits with avoiding what it estimates could have been a full shutdown costing the UK economy up to £56 billion. Even contained, the damage was severe: 148 TfL systems were taken out of service. The Dial-a-Ride service that gets vulnerable Londoners around the city stopped running. Digital payments, concessionary travel card issuance, and new Oyster photocard applications all went down, and refund processing slowed to a crawl. Names, email addresses, and home addresses held on TfL customers were accessed, along with Oyster refund data, including bank account numbers and sort codes, for around 5,000 people. All 27,000 TfL staff were required to attend an office in person to have their passwords reset by hand. The NCA and CPS put the total cost of recovery at £29 million.

TfL is not an under-resourced target. It runs a modern identity platform, a 24/7 operational security function, and the scale of infrastructure that comes with moving nine million people a day. None of that mattered at the point of failure, because the point of failure was not a system. It was a support agent on the phone, empowered to reset a password based on a plausible voice and partial information the attacker had bought for the purpose. Flowers was arrested on 6 September 2024 and found by investigators mid-attack against two US healthcare organisations, using the identical playbook. Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, has run this exact method against dozens of organisations since, and the FBI ties the group broadly to data extortion, SIM swapping, and social engineering.

A password reset or MFA device re-enrolment for any staff account is a high-consequence execution event, not an administrative task. Under GoFirm, that event cannot complete on a helpdesk agent's judgement alone. Before the reset executes, a real-time push confirmation goes out to the account holder's own registered device, and biometric confirmation from that person is required before the change takes effect. No confirmation, no reset.

That control sits precisely where Flowers and Jubair succeeded: a helpdesk agent deciding, on the strength of a phone call, whether the person on the line was who they claimed to be. GoFirm removes that judgement call from the interaction entirely. The decision no longer depends on how convincing the caller sounds. It depends on whether the actual employee, on the device already registered to them, confirms the request. A voice on the phone, however convincing, cannot produce that confirmation through a separate channel on someone else's device. The execution boundary holds regardless of how credible the impersonation appears.

GoFirm is The Authority Platform. Stop unauthorised action. Every time.

In association with Osinto.ai, the collective intelligence platform for Security, Resilience & Defence.
Osinto's AI-enabled open-source network and governed collaborative operational environment help mitigate the growing security, resilience and governance obligation in seconds, not days.

References

1. Khandelwal, S. 2026. Two Scattered Spider hackers get 5.5 years each for £29 million TfL hack. The Hacker News, 16 July 2026.
2. National Crime Agency. 2026. Two sentenced for hacking Transport for London in UK's biggest ever cyber crime case. NCA, 16 July 2026.
3. Crown Prosecution Service. 2026. Cyberhackers who targeted TfL jailed for more than five years each. CPS, 16 July 2026.

Share this article