The Register Home Page

back to article Transport for London says 2024 breach affected 7M customers, not 5,000

Transport for London has confirmed that a 2024 breach exposed the data of more than 7 million people – a far larger crowd than the few thousand customers originally warned that their details might be at risk. The BBC reported on Friday that the 2024 intrusion into TfL's systems potentially gave attackers access to a database …

  1. PCScreenOnly Silver badge

    Make 'em pay

    If you drive your car and are about to get into the lane after a bus lane has finished and your rear left wheel touches that fat bus lane line - fine - no getting off

    you go to a box junction, when at the time you start you can get your car across and then another on the wrong lane races in and cuts in front leaving you in the box junction - fine. And even if you have the dashcam footage to show that - Fine.

    Let them have some of their own medicine

    1. Like a badger Silver badge

      Re: Make 'em pay

      TfL is a state owned statutory corporation, fine them as much as you want because its all public money and would be a zero sum transfer from TfL to the Treasury. If TfL have less to spend as a result, that only affects the service users, and as usual nobody within TfL will be personally held to account.

      1. LucreLout Silver badge

        Re: Make 'em pay

        That's precisely the problem though, isn't it? Lessons won't be learned until heads have rolled.

        For this level of data breach it would be impossible for all the senior folks to stay in harness in the real world, and its time public bodies like TFL were made to take accountability. Lose millions of records in a hack, your CISO gets sacked and your CEO gets warned. Second hack the CISO number 2 gets sacked and the CEO with them. Rinse and repeat until secure.

        1. lordminty Bronze badge

          Re: Make 'em pay

          Like that's ever going to happen! This is the public sector. They'd get promoted, not fired!

        2. Anonymous Coward
          Anonymous Coward

          Re: Make 'em pay

          Maybe the author would like to inquire at TfL and question them about what they have done to prevent this from happening again? I think it would be inspiring.

        3. An_Old_Dog Silver badge

          CISO == Potential Scapegoat

          It's not cut-and-dried that a breach is the CISO's fault.

          If the CISO makes security recommendations, and the board of directors refuses them, or budgets insufficient money and staff time to implement them properly, or budgets no funds and time at all (whilst saying, "Yes, please do implement that."), it's not the CISO's fault, it is the Board's fault, and they are the ones who should be sacked, sans golden parachutes.

  2. Anonymous Coward
    Anonymous Coward

    Seven Million Citizens....................

    ......so that would be EVERYONE in London?

    1. ChrisC Silver badge

      Re: Seven Million Citizens....................

      Not quite everyone, I'm sure at least *some* of those customer records refer to people living outside of London who make use of TfL services in a way which requires their details to be on record... But even just thinking about those of us who reside in one of the boroughs, it wouldn't surprise me if enough of us do have our details on record with TfL such that we could come fairly close to filling that total regardless. They really are a *huge* organisation.

      1. tiggity Silver badge

        Re: Seven Million Citizens....................

        Sort of thing that makes me happy that when I go down South to London & buy tube tickets I use that quaint old thing called cash & so no PII in TfL databases.

  3. VoiceOfTruth Silver badge

    As usual, the ICO

    >> Information Commissioner's Office looked into the breach but ultimately decided not to take enforcement action against TfL, concluding the authority's response was proportionate.

    This damp squib rubber dick organisation is pointless.

  4. MorningLightMountain

    Funny how some TfL pages have been edited after the fact

    Looking at the The Reg's article from 2024 on this, it links to a TfL news post about the initial incident, and quotes TfL as stating that around 5k accounts were affected and so on. Looking at the linked TfL news post today, that quoted bit is now no longer there and the page says it's been last updated in September 2025. So they've clearly tried to amend their statements well after the fact to make it seems like they weren't desperately downplaying this breach at all.

  5. ThatOne Silver badge
    Coat

    Eleanor Rigby

    > contactless users

    Also known as "lonely people"?

POST COMMENT House rules

Not a member of The Register? Create a new account here.

  • Enter your comment

  • Add an icon

Anonymous cowards cannot choose their icon