Two men pleaded guilty in June 2026 to offences connected to the cyberattack on Transport for London, which caused months of disruption and an estimated £39 million in damage. As The Guardian reported, the attack affected millions of customers and disrupted digital services including payments, refunds, live arrival data, and Oyster photocard processes. The lesson for organizations is clear: cyber incidents are not only technical events. They interrupt daily life, public trust, and the people who keep services running.
Transport for London was hit by a major cyberattack in 2024, but the story returned to the news in June 2026 when two British men pleaded guilty at Woolwich Crown Court to offences connected to the incident. According to The Times, the attack caused around £39 million in damages and disrupted online access to services such as Oyster cards, Citymapper, and Dial-a-Ride.
The attack did not stop the Tube or buses from operating, which is important context. But it did create a long tail of disruption across customer-facing and internal systems. Reporting described delays in refunds, problems with Oyster photocard services, disruption to digital payments and customer systems, and staff being forced into password resets and manual processes.
The Guardian reported that the incident affected about 10 million customers, while The Times reported that about 5,000 customers had sensitive data exposed, including banking details. Those figures reflect different parts of the impact: broad customer disruption on one side, and more sensitive data exposure for a smaller group on the other.
Either way, this was not an abstract “systems issue.” It was a cyberattack that spilled into public services, customer support, staff workload, and trust.
The TfL case is useful because it shows what cyber disruption looks like when the affected organization is part of everyday life. When a transport authority has digital systems disrupted, the impact is not limited to IT dashboards. People cannot access services. Refunds are delayed. Disabled passengers may lose access to essential booking support. Staff have to move from normal work into recovery mode. Customer-service teams absorb the frustration.
That is the operational reality of cyber risk. It becomes a people problem very quickly.
For business leaders, the lesson applies well beyond transport. Many organizations now rely on digital services to make basic customer interactions work: bookings, payments, support tickets, account changes, refunds, identity checks, delivery updates, appointment systems, and access requests. When those systems fail, employees become the fallback infrastructure.
That means cyber resilience depends on human readiness. Do teams know what to do when normal systems are unavailable? Can staff verify customers safely without shortcuts? Are manual workarounds documented? Can leaders communicate clearly under pressure? Do employees know how to reset, recover, report, and support customers without creating new risk?
If the answer is “we’ll figure it out in the moment,” the moment will be generous enough to make that expensive.
Cyber incidents often begin with technical compromise, but they unfold through human decisions. During disruption, people face pressure, confusion, frustration, and urgency. That is when mistakes multiply.
Employees may be asked to use unfamiliar backup processes. Customers may be angry or anxious. Managers may push for speed. Attackers may exploit the chaos with follow-on phishing, fake support messages, impersonation, or credential scams. Staff may be tempted to bypass controls to help people faster.
That is not a criticism of employees. In a crisis, helpful people try to help. The job of a good cyber culture is to make safe helpfulness easier than risky helpfulness.
This is where human risk management matters. It helps organizations prepare people for the moments where policy meets reality: service outages, manual processes, identity checks, customer communications, recovery tasks, and high-pressure decisions. It also helps leaders understand where the organization is culturally ready, and where it is relying on luck wearing a high-vis jacket.
Organizations should use the TfL case as a resilience exercise. Ask what would happen if core customer systems were unavailable for days or weeks. Which teams would be affected? What manual processes would be used? Who would approve exceptions? How would customer identity be verified? What would employees say to customers? What data would be most exposed during workarounds?
Then test the human side of incident response. Run tabletop exercises that include customer service, operations, communications, HR, legal, finance, security, and frontline managers. Practice not just the technical recovery, but the human recovery: messages, scripts, escalation paths, stress points, staffing, and decision ownership.
Organizations should also prepare employees for post-incident social engineering. After a public cyberattack, criminals often use confusion to target customers and staff. Fake refund messages, phishing emails, bogus support calls, and credential-reset scams can all appear when people are already worried.
Finally, leadership communication needs rehearsal. In a public-service or customer-facing incident, trust is shaped by clarity, honesty, timing, and empathy. People can tolerate disruption better when they understand what is happening and what they should do next.
The TfL cyberattack pleas are a human risk management story because the consequences landed on people: customers, employees, support teams, leaders, and the public who depend on reliable services.
Cyber culture is not only about preventing incidents. It is also about how an organization behaves when something goes wrong. Do people escalate quickly? Do teams coordinate well? Do employees know how to support customers safely? Do leaders communicate with confidence and care? Do staff feel empowered to slow down risky shortcuts during recovery?
For Cybermaniacs, this is why human risk management has to include resilience, responsiveness, and culture under pressure. The best organizations do not just teach people to avoid mistakes. They prepare people to recover well when the digital floor gets slippery.
Cyberattacks do not stay in the server room. They end up at the ticket counter, the help desk, the call center, the boardroom, and, occasionally, in someone’s very delayed refund queue.
In June 2026, two men pleaded guilty to offences connected to the cyberattack on Transport for London. The attack caused months of disruption and around £39 million in damages.
Public reporting says the attack did not stop Tube or bus services from operating, but it disrupted digital and customer-facing services including payments, refunds, Oyster photocard processes, and live travel information.
The Guardian reported that the attack affected about 10 million customers. The Times reported that about 5,000 customers had sensitive data exposed, including banking details.
Because cyber disruption affects how employees, customers, leaders, and support teams behave under pressure. Safe recovery depends on communication, escalation, manual workarounds, identity checks, and a culture that supports good decisions during stress.
Prepare people as well as systems. Test manual processes, train teams for outage scenarios, rehearse customer communications, watch for post-incident scams, and build a cyber culture that supports calm, safe recovery.