Both men, who are linked to the notorious Scattered Spider hacking group, had successfully infiltrated TfL’s network between 31 August and 3 September 2024, which resulted in £29 million of damage and recovery costs and rendered more than 140 systems inoperable. The NCA also commented that one laptop contained a screen shot showing network connectivity to TfL infrastructure.

The men’s actions resulted in them accessing sensitive systems to extract personal data for which they were prosecuted under section 3ZA of the Computer Misuse Act 1990.

What can be learned from this cyberattack?

Although the attack was conducted remotely, and was limited so that it did not cause major disruption to the network and UK economy, it still caused major damage and required significant remedial work for TfL. Key takeaways for organisations to ensure they implement robust data protection practices include:

  • Strong passwords: All 28,000 of TfL’s employees were forced to attend a TfL office for a password reset. The attackers relied on stolen credentials to gain access to the network, so ensuring that strong passwords are in place which are protected will reduce risks of a cyberattack. It is good practice to also include secondary protection measures, such as Multi Factor Authentication, to safeguard such data;
  • Identity checks: The attackers were able to pose as genuine employees. If attackers can appear as legitimate members of staff, then this is an easier way  for them to infiltrate systems and steal personal data. Staff should have regular awareness training on how to identify a phishing attack and if unsure on the identity of a sender, to check this before allowing them access to the organisation’s systems;
  • Staff training/awareness: If staff are not trained on identifying attacks and data breaches, then this causes a vulnerability in the organisation’s network to cyberattacks. Ultimately, regular and thorough training on cybersecurity and data breaches will safeguard data and greatly reduce the risks of a cyberattack; and
  • Law enforcement: TfL was able to limit the damage of the attack by contacting law enforcement early. Such attacks could be part of a wider, international network so it is critical to contact law enforcement in a timely manner to ensure that specialist teams can be engaged to support with advising on the cause/s of the attack along with the remedial process.

ICO reports a sharp rise in the number of data breaches and complaints reported

Earlier this month, the ICO reported that it had received 76,743 data protection complaints during 2025/26, an increase of more than 80% on the previous year. It also reported in its published annual report that personal data breach reports rose from 12,412 to 17,43.. It is notable that the rise in cybersecurity attacks, children’s privacy and online tracking are areas which the public was particularly concerned about.

In January 2026, the ICO signed an important Memorandum of Understanding (MOU) with the UK Government which sets out a commitment to raise data protection standards. It seeks to provide clarity on “advice, scrutiny and challenge at all levels” whilst ensuring greater transparency and public accountability with respect to handling personal data and data breaches.

In its annual report, the ICO emphasised its focus on delivering timely regulatory interventions to raise data protection standards. This includes undertaking the following steps to address its aims:

  • Using the MOU outlined above;
  • Producing guidance and advice;
  • Engaging upstream with companies; and
  • Leading criminal prosecutions.

The ICO stated that in June 2025 it issued a £2,310,000 fine to 23andMe following a data breach that affected customers globally. A hacker exploited reused login credentials stolen from previous unrelated data breaches. The company did not have additional verification steps for users to access and download their raw genetic data. The example demonstrates the ICO’s stamp down on lack of protections to respond to a cyberattack.

In October 2025, the ICO fined Capita £14,000,000 following a cyberattack which resulted in the removal of one terabyte of data. This data breach affected over 6 million people. This attack involved someone downloading a malicious file on to an employee device. Although a security alert was raised within 10 minutes, Capita had not quarantined the device for over 58 hours. This left the organisation more susceptible to the breach infiltrating the system further and demonstrated a lack of appropriate technical and organisational measures to protect data.

How can you best prepare?

The ICO’s focus on raising data protection standards and issuing (publishable) high fines to organisations demonstrates the direction of travel. No matter the size of the organisation, holding organisations to account for safeguarding data, particularly in the rising number of cyberattacks and use of AI, is a key aim on the ICO’s agenda.

Organisations can take a number of steps to reduce the risk of data breaches and handle data in accordance with the UK data protection legislation, whilst protecting their reputation:

  • Ensure not only that data protection policies cover data management practices, but also that these are fit for purpose (particularly in relation to data retention and privacy notices) and are embedded into the workforce;
  • Ensure your record keeping system is fit for purpose – keep your records up to date, clearly organised and labelled to enable you to access information quickly and efficiently;
  • Ensure that your IT infrastructure is robust against cyberattacks with regular training on phishing and penetration testing on IT infrastructure to ensure that software and hardware remain up-to-date and not vulnerable to such attacks;
  • Meet your obligations as joint controllers and processors – ensure that it is clear what the parties need to do in the event of a data breach and that liabilities and indemnities are clearly set out in commercial agreements; and
  • Ensure a complaints procedure is in place for data protections complaints, where data protection complaints are responded to in the requisite timeframe and individuals are kept informed of the status and outcome of their complaint. Organisations should also inform individuals of their right to submit a complaint to the ICO and provide their contact details.

 

Please do not hesitate to contact a member of our Data Protection team if you require guidance or advice on any of the matters mentioned above.

Next