Teenage hacker arrested over TfL hack — as thousands of customer bank details confirmed stolen

(Image credit: Transport for London)

The effects of the Transport for London (TfL) cyberattack continue to rumble on, with news of thousands of customer banking details confirmed to have been accessed, and a potential culprit arrested by police.

On Sunday September 1, Transport for London (TfL) detected suspicious activity within its systems, sending an email alert to TfL accounts stating that it was "currently dealing with an ongoing cyber security incident."

Now, a second email, sent on September 12, stated TfL's "investigations have identified that certain customer data has been accessed," such as Oyster card refund data which could include "bank account numbers and sort codes for a limited number of customers (around 5,000)."

TfL customer data accessed

New applications for Oyster photocards and Zip cards have been temporarily suspended as a result of the cyberattack, with some Live Tube arrival information remaining unavailable.

According to TfL, additional data including "some customer names and contact details, including email addresses and home addresses" were accessed during the attack.

TfL’s chief technology officer Shashi Verma said (via BBC), "As a precautionary measure, we will be contacting these customers directly as soon as possible to advise them of the support we can provide and the steps they can take," adding, "We continually monitor who is accessing our systems to ensure only those authorised can gain access."

"We will continue to keep our customers and our staff updated. I would like to apologise for the inconvenience this incident may cause customers and I thank everyone for their patience as we respond to this incident," he concluded.

The company is still working with the National Crime Agency and the National Cyber Security Centre to conduct an investigation into the attack. TfL also said in it's email that it will be doing an "all-staff IT identity check."

The National Crime Agency has also said on September 5, a 17 year old boy was arrested in connection with the cyberattack in Walsall, West Midlands, and questioned on suspicion of Computer Misuse Act offences. He has since been bailed following the questioning.

"Attacks on public infrastructure such as this can be hugely disruptive and lead to severe consequences for local communities and national systems," noted Paul Foster, head of the NCA's National Cyber Crime Unit.

"We have been working at pace to support Transport for London following a cyber attack on their network, and to identify the criminal actors responsible."

"The swift response by TfL following the incident has enabled us to act quickly, and we are grateful for their continued co-operation with our investigation, which remains ongoing."

More from TechRadar Pro

Benedict Collins
Staff Writer (Security)

Benedict has been writing about security issues for over 7 years, first focusing on geopolitics and international relations while at the University of Buckingham. During this time he studied BA Politics with Journalism, for which he received a second-class honours (upper division), then continuing his studies at a postgraduate level, achieving a distinction in MA Security, Intelligence and Diplomacy. Upon joining TechRadar Pro as a Staff Writer, Benedict transitioned his focus towards cybersecurity, exploring state-sponsored threat actors, malware, social engineering, and national security. Benedict is also an expert on B2B security products, including firewalls, antivirus, endpoint security, and password management.

Read more
The British Museum main entrance
British Museum forced to partly close following cyberattack by ex-worker
Password
Millions of airline customers possibly affected by OAuth security flaw
A graphic showing fleet tracking locations over a city.
Lost & Found tracking site hit by major data breach - over 800,000 could be affected
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
A computer being guarded by cybersecurity.
Wacom warns users their data may have been stolen in breach
An illustration of a silhouetted thief in motion running while carrying a stolen fingerprint
The 5 worst cyberattacks of 2024
Latest in Pro
An American flag flying outside the US Capitol building against a blue sky
Five Eyes "cannot replace US intel in Ukraine", claims former US Cyber Command Chief
Pirate skull cyber attack digital technology flag cyber on on computer CPU in background. Darknet and cybercrime banner cyberattack and espionage concept illustration.
Criminals are using a virtual hard disk image file to host and distribute dangerous malware
Oracle
Oracle unveils multi-billion dollar investment in UK cloud and AI
WordPress on a laptop
Over 20,000 WordPress sites hit by damaging malware campaign
AI model distillation
Why you almost certainly have a shadow AI problem
A representative abstraction of artificial intelligence
Researchers want to give some common sense to AI to turn it into artificial general intelligence
Latest in News
A image of Saros character Arjun
Housemarque’s boss is surprisingly positive about Sony’s acquisition – and it’s good news for Saros
Oura Ring 4
One of Apple's top health execs is ditching the company for Oura, and I've never been more convinced smart rings are the future
Nvidia logo
Nvidia RTX 5060 Ti could be delayed to mid-April and RTX 5060 to mid-May – is AMD starting to look like a clear winner in the battle of Blackwell vs RDNA 4 GPUs?
The A Minecraft Movie Meal from McDonald's.
McDonald's reveals A Minecraft Movie meal with a bizarre set of collectibles and the most sinister sounding sauce ever
Apple iPhone 16e REVIEW
The iPhone 16e’s 5G performance seemingly has the iPhone 16’s beat
Assassin's Creed Shadows
I was already sold on Assassin's Creed Shadows on PS5 Pro, but now the devs are teasing that the game will soon get a boost from PSSR