
Transport for London admitted to BBC that it suffered a data breach as a result of the Clop ransomware group exploiting a zero-day vulnerability in the MOVEit Transfer web application.Transport for London (TfL), which operates public transport in the capital city, recently confirmed that the security incident compromised the sensitive personal details of around 13,000 drivers whose information was listed either in London’s Congestion Charge or in the Ultra Low Emission Zone (ULEZ) database.In a statement shared with BBC, TfL said, “The issue has been fixed and the IT systems have been secured. The data in question did not include banking details and we are writing to all of those involved to make them aware of the incident.”TFL said the compromised database doesn’t include passenger data. It said the Information Commissioner’s Office has been notified about the incident and it is working with the information security watchdog to resolve the incident.The Clop ransomware gang gave a deadline of June 14 to the affected organisations to contact the group and avoid the publication of their compromised data. Now that the deadline has expired, more companies are reporting being impacted by the exploitation of the zero-day vulnerability in the MOVEit Transfer web application.Accountancy firm Ernst & Young (EY) also said that it has been targeted by the Clop ransomware gang. EY added that as soon as it became aware of the vulnerability in the MOVEit application, it “immediately launched an investigation into our use of the tool and took urgent steps to safeguard any data”.“We are manually and thoroughly investigating systems where data may have been accessed. Our priority is to first communicate to those impacted, as well as the relevant authorities. Our investigation is ongoing,” the company added.Commenting on the news, Oliver Tavakoli, CTO at Vectra, said, “It’s concerning to see more organisations emerging as victims, and TfL certainly won’t be the last UK organisation to have its employee or customer data exposed. The scale of this attack is eye-opening and should send a clear warning to organisations that an attack on any service provider to which they entrust confidential data can result in a breach and that the security practices of such service providers require constant review.“Organisations must factor security into their decisions when selecting third-party providers. But security doesn’t stop after supplier selection. Firms also need to drastically improve visibility into their own IT environments so they can identify supply chain security events that target their environments as they occur. This means using AI to identify attacker behaviours, enabling firms to spot the signs that vendor-supplied software has been compromised and stop the attack before it becomes a breach.”
Winston House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543