In August 2024, Transport for London, the agency that runs the Tube, the buses, and most of how nine million people get around the capital, watched its internal systems seize up. No nation-state zero-day. No exotic firewall bypass. This week two men pleaded guilty in a UK court on the first day of what was meant to be a six-week trial, and the court details confirm what plenty of people in cybersecurity already suspected: the crew that pulled this off mostly talked their way in.

The two were named as members of Scattered Spider, the loose, English-speaking cybercrime collective that has spent the past two years dismantling casinos, insurers, retailers, and now public infrastructure. Their best weapon is a phone and a convincing story. That should change how you think about where your real perimeter sits.

How a Phone Call Crippled London’s Transit Network

Scattered Spider’s playbook is depressingly simple to describe and brutally effective to run. Identify an employee. Gather enough personal detail to sound legitimate. Call the IT help desk, or the help desk’s outsourced provider, and ask for a password reset or an MFA re-enrollment on a device the attacker controls. Once that request goes through, the attacker is inside with valid credentials and a registered authenticator.

From there it’s lateral movement, privilege escalation, and access to whatever the compromised identity could reach. At TfL that meant internal systems, staff data, and enough disruption to knock out online services for weeks. The agency spent a reported fortune on recovery, and a teenager was arrested in connection with the intrusion not long after.

What’s worth sitting with is the absence of anything you’d call hacking in the Hollywood sense. There was no payload that your endpoint agent could quarantine, no malicious binary to hash and block. The login looked legitimate because, by the time it happened, it was legitimate. The help desk handed over the keys.

Why Cybersecurity Tools Didn’t Touch This Attack

Here’s the uncomfortable part for anyone who’s signed a seven-figure security budget. Most of that stack is tuned to catch malicious code and network anomalies. A firewall inspecting traffic, an EDR agent watching for suspicious process trees, threat detection rules hunting for known indicators. None of that fires when an authenticated user logs in through the front door and behaves like an employee, because that’s exactly what the attacker has arranged to look like.

The inputs to this kind of attack are also absurdly cheap. Malwarebytes researchers recently spent 48 hours inside dark web markets and found full stolen identities selling for as little as 95 cents, alongside malware kits and scams-for-hire. Credential dumps, stealer logs, and brute-force wordlists are commodity goods now. An attacker doesn’t need to be clever; they need to be patient and have a credit card with two figures of headroom.

That’s the thread connecting a transit shutdown in London to a market stall on the dark web. Cyber security spending keeps climbing, yet the most damaging breaches of the past two years leaned on social engineering and cheap, pre-stolen data rather than novel exploits. When your defenses grade trust by pedigree, valid-but-stolen credentials walk right past them. Defense in depth has to extend to the humans answering the phones, not just the boxes in the rack.

Hardening the Help Desk: What to Do Now and Ongoing

The good news is that the controls that stop Scattered Spider are mostly procedural and cheap relative to the breach they prevent. Treat your identity and help desk processes as a security hardening project in their own right.

Immediate actions you can take this week:

  • Require strong, scripted caller verification for any password reset or MFA change. Knowledge questions like employee ID or manager’s name are not enough; use a callback to a number on record or an in-person/manager-approved check.
  • Move to phishing-resistant MFA (FIDO2 hardware keys or passkeys) for privileged and IT staff first. It removes the push-fatigue and SIM-swap paths Scattered Spider relies on.
  • Put brute-force controls and rate limits on every authentication endpoint, including VPN and webmail, so credential lists bought for pennies don’t get unlimited attempts.
  • Alert on high-risk identity events: MFA device re-enrollment, password resets for privileged accounts, and impossible-travel logins.

Ongoing work that actually moves the needle:

  • Run social-engineering drills against your own help desk, not just phishing tests against end users. Score how often a caller can force a reset without proper verification.
  • Tighten the blast radius with least privilege and just-in-time admin access, so a single compromised identity can’t reach the whole estate.
  • Build threat detection around identity behavior, not only malware signatures. A legitimate account doing illegitimate things is the signal you need.
  • Rehearse incident response for the “valid credentials, no malware” scenario. Your playbook should answer how you revoke sessions, force re-authentication, and rotate secrets at speed when the intruder looks exactly like staff.

Threat-protection here is less about buying another appliance and more about closing the gap between the trust your processes assume and the verification they actually perform. A thirty-second callback policy would have made the TfL attacker’s job dramatically harder.

Sources

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.

Stay up to date with the latest news, releases and more.

Take Control of Your Server Security

Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.

Secure. Automated. Lightweight.