Scattered Spider teen hackers sentenced over £29 million Transport for London cyberattack

Share On LinkedIn
Share on X

Two young members of the Scattered Spider hacking collective have been sentenced to five years and six months in prison each for orchestrating a cyber attack on Transport for London that cost tens of millions of pounds and disrupted services for thousands of Londoners. Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were sentenced at Woolwich Crown Court on 16 July 2026, following the largest cybercrime prosecution ever brought before UK courts.

Both men pleaded guilty last month, changing their pleas on the day their trial was set to begin. The National Crime Agency and City of London Police traced the intrusion to a three-day window between 31 August and 3 September 2024.

The attackers infiltrated the transport network, forcing all 27,000 employees to attend in-person password resets and knocking 148 systems offline, some of which required manual workarounds for weeks. Disrupted services included the Dial-a-Ride booking system for vulnerable residents, concessionary travel card issuance, digital payments and the rollout of contactless ticketing.

Attackers also accessed the Oyster refunds system and disabled the application process for children’s and young people’s Oyster photocards. Transport for London reported £29m in direct losses and recovery costs, with investigators noting that had the attack succeeded in fully shutting down the capital’s transport network, the economic damage could have reached £56bn.

The pair were charged under Section 3ZA of the Computer Misuse Act, the statute’s most severe provision, covering unauthorised acts causing or risking serious damage where the offender intended or was reckless to that outcome. This marked only the second prosecution of its kind in the UK.

The National Crime Agency stated that Flowers was first arrested on 6 September 2024, whilst actively hacking US healthcare providers SSM Health Care Corporation and Sutter Health. A search of his home turned up laptops, hard drives and USB devices, including a screenshot showing network connectivity to Transport for London infrastructure and recorded videos of Jubair accessing the systems in real time.

Both men were arrested again on separate occasions, with Flowers detained for breaching bail conditions on device usage, and Jubair for refusing to disclose device PINs and passwords to investigators.

National Crime Agency Deputy Director Paul Foster called Scattered Spider “the most significant cybercrime threat to the UK in recent years,” crediting the transport provider’s early engagement with law enforcement as pivotal to securing convictions.

Microsoft independently assessed that the arrests materially degraded the group’s operational capacity, even as other actors may continue exploiting the damaged Scattered Spider brand. FBI Cyber Division Assistant Director Brett Leatherman noted the group’s signature tactics, data extortion, SIM-swapping and social engineering, and pledged continued cross-border collaboration.

City of London Police also used the case to advocate for proposed Cyber Crime Risk Orders, which would impose court-supervised, risk-based restrictions on convicted offenders’ technology use, described as a digital prison model aimed at both prevention and rehabilitation.

Image source: NCA and TfL

STORY OF THE WEEK

Technology PR, search and social agency

Trending Now

Leave a Reply

Your email address will not be published. Required fields are marked *