Transport Hackers Jailed, Russian Cybercrime Bust, & 23andMe Settles for $18M

by The Creator | Jul 16, 2026

A social engineering attack bypasses passwords by manipulating employees into granting access, as demonstrated when the Scattered Spider gang breached London Transport for £29 million in damages. The same technique enabled Russian cybercrime networks to compromise 42 victims across 21 states, proving that technical controls alone cannot stop attackers who exploit human trust.

Today's cyber news highlights major enforcement actions and emerging threats. Two young British hackers from the Scattered Spider gang have been sentenced to five and a half years in prison for attacking London's Transport network, costing £29 million and exposing data on 7-10 million users. In the U.S., the DOJ indicted three Russian nationals and two bulletproof hosting companies for enabling cybercrime that caused tens of millions in losses across 42 victims in 21 states. Genetic testing company 23andMe agreed to pay $18 million to settle claims it failed to protect customers' genetic data.

The attacks demonstrate how criminals are bypassing traditional defenses through social engineering and trust manipulation. From WhatsApp device-linking scams to AI agents fooled by fake data, password protection alone is insufficient. Security experts recommend regularly reviewing linked devices, enabling two-step verification, and never approving security requests under pressure.

How does a social engineering attack differ from traditional hacking for small businesses?

Social engineering attacks target the person, not the system. Scattered Spider used WhatsApp device-linking scams and fake data to fool AI agents and employees, while Russian nationals operated through bulletproof hosting to mask their activity. For SMBs in manufacturing and professional services, the risk is acute: one employee approving a device link under pressure or clicking a spoofed login page can expose customer data, financial systems, and intellectual property. CISA repeatedly warns that trust-based attacks succeed because they require no zero-day exploits. The single most important action: audit all linked devices on company accounts monthly, enforce two-step verification on all cloud services, and train staff to pause before approving access requests, especially when urgent language is used.

Key takeaways

  • Scattered Spider gang targeted London Transport via employee pressure and device-linking tricks, costing £29 million and exposing millions of user records.
  • Two-step verification and regular device audits stop most social engineering attacks by adding a second checkpoint that attackers cannot bypass without physical access.
  • Russian cybercrime networks operated through bulletproof hosting providers to hide their identity; three nationals and two companies were indicted by the DOJ for causing tens of millions in losses across 42 victims.
  • 23andMe paid $18 million in damages because customer data protection failed, signaling regulators will hold companies liable for weak access controls.

Frequently asked questions

What is a social engineering attack and why did it work against London Transport?

Social engineering uses deception to manipulate employees into granting access instead of attacking systems directly. Scattered Spider pressured London Transport staff to approve device links and trust requests, bypassing technical defenses. The attack cost £29 million in damages and exposed 7-10 million user records.

How can my small business stop social engineering attacks?

Enable two-step verification on all cloud and email accounts, audit linked devices monthly, and train staff to never approve security requests under pressure. Require a verbal callback to verify urgent access requests. These three steps stop the majority of social engineering attacks because they force attackers to compromise more than one control.

What happened to the hackers and Russian cybercrime network?

Two British members of Scattered Spider received five-and-a-half-year prison sentences for the London Transport breach. The DOJ indicted three Russian nationals and two bulletproof hosting companies for enabling cybercrime across 42 victims in 21 states. Law enforcement action shows regulators are prioritizing prosecutions, but prevention is still your responsibility.

Why did 23andMe pay $18 million in damages?

23andMe failed to protect customer genetic data after a social engineering attack compromised user accounts. The company did not enforce two-step verification and did not detect unauthorized access quickly. The settlement signals that regulators expect companies to implement basic access controls, and SMBs should expect similar liability if customer data is breached due to preventable controls.

Sources

Keep reading