Mind the password gap: what the TfL Oyster breach tells us about the state of password management in the commuting population

We all rely on Oyster cards to get us around the city – but for some TfL customers, password duplication has led to suspended service on all lines…
Oyster card

Share this article:

Tim Galligan, general manager of EMEA operations at SailPoint explains what happens what password duplication can mean for commuters

We all rely on Oyster cards to get us around the city – but for some TfL customers, password duplication has led to suspended service on all lines. Despite the £2.3bn commuters spend on TfL journeys each year using Oyster, some are still tempted enough to reuse their passwords from other sites and leave their personal credentials (and data) vulnerable.

User credentials are the new attack vector. Once one is cracked, there is the potential to take over the rest of someone’s digital logins, too. This is particularly troubling if users are sharing passwords between work and personal accounts as they could unknowingly be exposing their employer in the process.

Hackers are all over that fact – identity fraud is often the result of poor ‘password hygiene’ with individuals using the same user logins and passwords across numerous accounts – a very common occurrence. In our surveys, a whopping 65% of employees admit to routinely reusing passwords across multiple applications and websites. With such weak passwords in place, cyber criminals are able to easily access account information and steal personal credentials, off the back of just a few phishing emails or SMSing, with the latter being is a form of fraud that uses mobile phone text messages.

The good news is that 54% of organisations have an identity programme. That figure suggests the scales are tipping in favour of a comprehensive corporate approach to security, which must include identity. The bad news is, you can’t govern what you can’t see, and so for some organisations their employees’ Oyster passwords have become a security blind spot.

And what if they signed up with a password they used in their previous job? Keeping up with employees and their access is incredibly complex for IT teams. It becomes even more challenging when you think about the number of organisational changes that happen on a daily basis, as users join or leave the organisation or change job responsibilities and roles. In many cases, permanent employees may still have their former access privileges long after they have left the company. These ‘orphaned’ accounts, still technically active but with no signed owner, are particularly dangerous as their access to systems and files appears to be legitimate and within an organisation’s normal day-to-day access pattern.

With many of us topping up our Oyster credit in the office before the evening commute, we all need to mind the password gap. While passwords can be changed if compromised, organisations must more diligently prepare to safeguard data, that can’t be replaced if compromised. With breaches reported already, the surest form of protecting digital identities today is by governing well, to reduce uncertainty and risk.

About Security Buyer

Security Buyer is the leading authority in global security content, delivering expert news, in-depth articles, exclusive interviews, and industry insights across print, digital, and event platforms. Published 10 times a year, the magazine is a trusted resource for professionals seeking updates and analysis on the latest developments in the security sector.

To submit an article, or for sponsorship opportunities, please contact our team below.

Rebecca Spayne Picture

Rebecca Spayne

Group Managing Editor

Georgina Turner Picture

Georgina Turner

Sales Manager

Afua Akoto Picture

Afua Akoto

Marketing Manager

Related News

Ai Solution of the year - securitybuyer.com

Have your say: vote for AI Solution of the Year

Voting is open for AI Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited to select their winner
Access control of the year - securitybuyer.com

Have you voted for Access Control Solution of the Year?

Voting is open for Access Control Solution of the Year at the Security Buyer Readers’ Awards 2026, with readers invited
PaxLock Pro2 - securitybuyer.com

Paxton officially launches PaxLock Pro2

Paxton the security technology manufacturer has launched a brand-new re-engineered PaxLock which is built to protect straight
KentixONE data centre - securitybuyer.com

Data centre security with KentixONE

Prior1 develops container data centers to meet the highest security and energy efficiency standards. Their containers require
Chubbsafes - securitybuyer.com

Chubbsafes explores certified storage for jewellery and precious metals

Chubbsafes, part of Gunnebo Safe Storage, has launched a new technical discussion guide examining when certified
Mercury trends report - securitybuyer.com

New Mercury Research Finds Growing Cybersecurity Gap

2026 Trends in Access Controllers Report finds interoperability, cloud connectivity and AI are reshaping long-term controller strategies.
Chris Carroll - securitybuyer.com

Comelit-PAC Promotes Chris Carroll as Sales Director

Comelit-PAC has appointed Chris Carroll as Sales Director, following an 18 year career with the company, seeing him progress
Jason Bezuidenhout - securitybuyer.com

Zygal Appoints Jason Bezuidenhout

Zygal has appointed Jason Bezuidenhout as Chief Revenue Officer (CRO), strengthening its leadership team as the company continues
Eun-Kyung-Hong_- securitybuyer.com

How AI Manages Mixed Surveillance Workloads

Eun-Kyung Hong, HDD Product Manager at Toshiba Electronics Europe GmbH discusses AI optimisation in mixed surveillance workloads
ASSA ABLOY - securitybuyer.com

ASSA ABLOY Door Group highlights importance of BS 8214:2026

ASSA ABLOY Door Group is supporting Fire Door Safety Week 2026 by raising awareness of the latest update to BS 8214:2026
Scroll to Top