AYush Chhabra

The Risk Gap

Perspectives on risk, security, and decisions that matter

Young Hackers Crippled London’s Transit System by Calling the Help Desk, Not Breaking the Code

Two men in their late teens and early twenties pleaded guilty this week to a 2024 attack that disrupted the public transport system across greater London. Court filings tie the same group to a string of intrusions at retailers, hospitals, casinos, and wireless carriers, with victims collectively paying more than a hundred million dollars in ransom. What stands out is not how sophisticated the attacks were. It’s how ordinary they were. These people rarely defeated security technology. They talked their way past the humans operating it.

The group’s signature move was a thing called SIM swapping. Your phone number isn’t permanently bound to the phone in your pocket — it’s an assignment a carrier can move to a different device on request. That flexibility exists for good reasons. People lose phones, upgrade them, switch carriers. So the phone companies built a process where a customer service representative can transfer a number when someone calls and asks. The attackers simply became the people asking, often after phishing a carrier employee’s login so the request came from inside. Once they controlled the number, they received the victim’s text-message security codes — the same codes meant to prove identity. The lock and the key ended up in the same hand.

This is the tradeoff worth sitting with. Every account-recovery process is a deliberate weakening of security in the name of not stranding legitimate users. A company that makes it impossible to recover an account when you lose your phone has a security model nobody can live with. So organizations staff a help desk, give those employees the power to override the front door, and accept the risk that comes with it. The decision is rational. The mistake is treating the help desk as a customer-service function rather than as one of the most powerful and most targeted security controls in the building.

Because that’s what it is. The person who can reset a credential or move a phone number holds more practical access than most administrators. Yet that role is usually the lowest-paid, highest-turnover, most scripted-to-be-agreeable seat in the organization — optimized to resolve calls quickly and keep customers happy. Attackers understood the incentives better than the companies did. They weren’t fighting the security team. They were exploiting the part of the business explicitly built to be helpful under pressure.

A more grounded approach starts by naming the help desk as a security boundary and resourcing it like one: callback verification, limits on what a single representative can do alone, and recovery methods that don’t lean on a text message anyone can hijack. None of that is exotic. It’s just expensive in a place most companies would rather spend nothing.

The question to carry into your own environment isn’t whether your technology is strong. It’s who, on their worst day, can be talked into opening the door — and whether you’ve ever treated that person as the control they actually are.