Scattered Spider talks help desk agents into password resets and MFA changes. The same method links the TfL case to M&S, Harrods, and Jaguar Land Rover.
Browser-delivered malware rides on search ads, fake update prompts, and spoofed pages. The user starts every step, which is exactly why perimeter tools miss it.
Attackers often call the help desk instead of breaching it, talking agents into resets and MFA changes. Least privilege for support staff limits the damage.