• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

TfL Cyber Security Incident

Hadders

Veteran Member
Associate Staff
Senior Fares Advisor
Joined
27 Apr 2011
Messages
18,097
I’ve just had an email saying that TfL are dealing with a cyber security incident.

Has anybody else been contacted?

Dear Mr Hadders,

We are currently dealing with an ongoing cyber security incident. At present, there is no evidence that any customer data has been compromised and there has been no impact on TfL services.

The security of our systems and customer data is very important to us, and we have taken immediate action to prevent any further access to our systems.

We are working closely with the relevant government agencies to respond to the incident.

You can get the latest information on our website.

We will update you further when the incident has been resolved.​
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Mcr Warrior

Veteran Member
Joined
8 Jan 2009
Messages
17,152
BBC reporting on the issue just now...


Extract(s)...
BBC said:
Transport for London's (TfL) computer systems have been targeted in an ongoing cyber attack.

It said there was no evidence customer data had been compromised and there was currently no impact on TfL services.
Insiders have told BBC London they have been asked to work at home if possible, and that it is the transport provider's backroom systems at the corporate headquarters that are mainly affected.

TfL’s chief technology officer Shashi Verma said: “We have introduced a number of measures to our internal systems to deal with an ongoing cyber security incident."
 

RailAleFan

Member
Joined
2 Jul 2014
Messages
337
Location
Midlands
Is being under an ongoing cyber attack really a great time to be emailing your entire customer base about it?
 

Blindtraveler

Established Member
Joined
28 Feb 2011
Messages
10,544
Is being under an ongoing cyber attack really a great time to be emailing your entire customer base about it?
I had the exact same thought when my version of that email came in. I'm not particularly worried about it. To be honest, I don't work for them and the details they have about me are minimal best thing that can come out of it as far as I'm concerned is that someone stops the London mayor accessing his emails and social media for a while, I have no time for him and so would be quite contented with this
 

Thirteen

Established Member
Joined
3 Oct 2021
Messages
1,888
Location
London
I had the exact same thought when my version of that email came in. I'm not particularly worried about it. To be honest, I don't work for them and the details they have about me are minimal best thing that can come out of it as far as I'm concerned is that someone stops the London mayor accessing his emails and social media for a while, I have no time for him and so would be quite contented with this
I don't think that a cyberattack on TfL would any impact on the Mayor
 

1D54

Established Member
Joined
1 Jun 2019
Messages
1,463
Also received this at 18:54 yesterday but AFAIK I'm not even on their database so find it very strange.
 

londonbridge

Established Member
Joined
30 Jun 2010
Messages
1,868
Not sure if it’s me but journey and payment history won’t load in the app, just sits there with spinning circle and nothing loading.
 

sor

Member
Joined
15 Nov 2013
Messages
779
Is being under an ongoing cyber attack really a great time to be emailing your entire customer base about it?
If the system that handles mass emails (probably outsourced anyway) is functional, why not?

from a security perspective, while TfL currently don't think there's been a data breach, it makes sense to warn customers in case they start getting emails or calls purporting to be from them.
 

Tetchytyke

Veteran Member
Joined
12 Sep 2013
Messages
17,443
Location
Isle of Man
Is being under an ongoing cyber attack really a great time to be emailing your entire customer base about it?
Yes. If your bulk email provider is online, it makes perfect sense to email your customers to tell them that your systems are affected and it might be difficult to complete transactions.

Otherwise you just get everyone ringing up to ask why they can't log in...
 

signed

Established Member
Joined
13 May 2024
Messages
2,369
Location
ROI
Is being under an ongoing cyber attack really a great time to be emailing your entire customer base about it?
There it's more of a courtesy/honesty act

But if any personal data were to have been compromised then they have 72h to inform under GDPR
 

Mcr Warrior

Veteran Member
Joined
8 Jan 2009
Messages
17,152
So, what has been the impact, if any, to the travelling public on London's travel network? They can't currently access journey and payment history? Anything else?
 

dub

Member
Joined
21 Jul 2022
Messages
72
Location
London
So, what has been the impact, if any, to the travelling public on London's travel network? They can't currently access journey and payment history? Anything else?
Live tube data is missing from journey planning apps
 

N/100

Member
Joined
9 Jan 2016
Messages
54
So, what has been the impact, if any, to the travelling public on London's travel network? They can't currently access journey and payment history? Anything else?

The over 60+ oyster application process appears to be completely suspended with no explanation of when it will be restarted or any alternative. No prizes for guessing who would qualify for one from next week.
 
Last edited:

Mawkie

Established Member
Joined
17 Feb 2016
Messages
1,242
Is being under an ongoing cyber attack really a great time to be emailing your entire customer base about it?
Yes, this is exactly the time you need to tell your customers about something on-going that may impact them in order to reassure them that it's business as usual as far as possible. People will have been reading the news about a cyber attack and perhaps be worried that TfL hold a lot of their personal and financial details. It's entirely appropriate for the business to comment on that as early as possible.
... as far as I'm concerned is that someone stops the London mayor accessing his emails and social media for a while, I have no time for him and so would be quite contented with this
I didn't understand this weird rant, but you do you as they say.

TfL is a large organisation, and not without its issues, however I really think sometimes that TfL don't actually get the credit they deserve in these situations. It has caused chaos internally - from my own point of view the rostering, and other admin, has reverted to old school hand written paper. I hear it's been quite difficult for some staff in other parts of the business to gain access to some of the software they need to do their jobs.

However, the actual truly vital systems such as power control, and signalling, and a million other things have proven to be absolutely robust under a week-long, sustained, relentless attack. And that is down to the dedication and forward thinking of staff having the skills, experience, and knowledge to anticipate and manage a (suspected by me) state sponsored cyber attack of this magnitude and install systems to protect the network.

The fact that the travelling public have been so minorly inconvenienced (and so far, the only impact has been some apps not working correctly, and a some applications not being processed) then that is a credit to TfL and they should be commended for that.
 

Steelman

Member
Joined
30 Oct 2023
Messages
22
Location
Essex
This cyber attack is still ongoing and staff are still being told to work from home. In conventional warfare an attach stops when you take out the enemy, with a cyber attack there is nothing you can do until the other party stops, gets bored, is paid off or targets someone else. This could go on for weeks.
 

Mawkie

Established Member
Joined
17 Feb 2016
Messages
1,242
This cyber attack is still ongoing and staff are still being told to work from home.
Thank goodness TfL is so well set up for working from home - just as many other businesses are, post covid.
This could go on for weeks.
It was always described to me as potentially taking 4 weeks to resolve. So this is no surprise.

It should be stated I guess that "the attack" has only had a minor impact and most of that impact is caused indirectly by that attack. By that I mean the systems that have been affected have been turned off by TfL, rather than forced to close.

It's worth repeating that, as of today, there is still no evidence of customer (or staff) details being compromised.
 

londonbridge

Established Member
Joined
30 Jun 2010
Messages
1,868
So how long is journey and payment history going to be down for then? Came back from Great North Run today, got back to Kings X at 2.00pm and got Thameslink train and the bus home, the app is still showing “no record of any travel on this card today”. Payments are still being taken as my outward travel from home to Kings X on Friday was debited correctly, but whilst this continues you can’t check how much you’ve been charged for specific journeys.
 

Robski

Member
Joined
15 May 2016
Messages
333
Around 5,000 bank account numbers and sort codes have been compromised. https://tfl.gov.uk/campaign/cyber-security-incident
We identified some suspicious activity on Sunday 1 September and took action to limit access. We are conducting a thorough investigation into the incident, alongside the National Crime Agency and the National Cyber Security Centre.

Although there has been very little impact on our customers so far, the situation is evolving and our investigations have identified that certain customer data has been accessed. This includes some customer names and contact details, including email addresses and home addresses where provided.

Some Oyster card refund data may have been accessed. This could include bank account numbers and sort codes for a limited number of customers (around 5,000).

If you are affected, we will contact you directly as soon as possible as a precautionary measure, and will offer you support and guidance.
 

Mcr Warrior

Veteran Member
Joined
8 Jan 2009
Messages
17,152
If you are affected, we will contact you directly as soon as possible as a precautionary measure, and will offer you support and guidance.
Cue any number of (spoof TfL) moody e-mails hitting in-boxes offering to help transfer money to a 'safe' account.
 

Thirteen

Established Member
Joined
3 Oct 2021
Messages
1,888
Location
London
A seventeen year old has been arrested, that's fairly quick that they found the perpetrator or ever so slightly concerning that someone so young could hack TfL's systems.
 

Mojo

Forum Staff
Staff Member
Administrator
Joined
7 Aug 2005
Messages
21,168
Location
0035
A seventeen year old has been arrested, that's fairly quick that they found the perpetrator or ever so slightly concerning that someone so young could hack TfL's systems.
Press release from the NCA:
A teenager has been arrested in Walsall by the National Crime Agency, as part of the investigation into a cyber security incident affecting Transport for London (TfL).

The 17-year-old male was detained on suspicion of Computer Misuse Act offences in relation to the attack, which was launched on TfL on 1 September.

The NCA is leading the law enforcement response, working closely with the National Cyber Security Centre and TfL to manage the incident and minimise any risks.

The teenager, who was arrested on 5 September, was questioned by NCA officers and bailed.

Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, said: “We have been working at pace to support Transport for London following a cyber attack on their network, and to identify the criminal actors responsible.

“Attacks on public infrastructure such as this can be hugely disruptive and lead to severe consequences for local communities and national systems.

“The swift response by TfL following the incident has enabled us to act quickly, and we are grateful for their continued co-operation with our investigation, which remains ongoing.

“The NCA leads the UK’s response to cybercrime. We work closely with partners to protect the public by ensuring cyber criminals cannot act with impunity, whether that be by bringing them before the courts or through other disruptive and preventative action.”
 

londonbridge

Established Member
Joined
30 Jun 2010
Messages
1,868
The news report I’ve just read says he was arrested last Thursday! Also that other hackers may still be at large.

The bank account details are believed to have come from Oyster card refund data. I’ve still got a card somewhere but haven’t used it in years since I went contactless. Also can’t remember the last time I had a refund so I may be okay on that score.
 

Top