skip to content
ai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILUREai · TSMC ADDS $100 BILLION TO ARIZONA CHIP BET, TOTAL HITS $265 BILLIONai · META WILL ALERT PARENTS IF TEENS DISCUSS SUICIDE WITH META AIai · ROBLOX'S "BUILD" LETS ANYONE MAKE A GAME FROM THEIR PHONE WITH AIbusiness-of-tech · APPLE RECLAIMS WORLD MOST VALUABLE COMPANY TITLE, NVIDIA BOTTLES ITconsumer-tech · GOOGLE ADDS YOUTUBE MUSIC, INSTACART & CANVA TO AI MODE SEARCHai · ZOOX REALLS ENTURE ROBOTAXI FLEET OVER SMOKE DETECTION FAILURE
BAD/GATEWAY*

TWO SCATTERED SPIDER HACKERS JAILED FOR 5.5 YEARS OVER TFL ATTACK

The attack cost London’s transport authority an estimated £29 million and forced 27,000 employees to reset passwords in person.

by editor5 min readcomments soon

TWO SCATTERED SPIDER HACKERS JAILED FOR 5.5 YEARS OVER TFL ATTACK

Two members of the cybercriminal group Scattered Spider were each sentenced to five years and six months in prison for the 2024 cyberattack on Transport for London. Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty last month on the day their trial was due to start, under Section 3ZA of the Computer Misuse Act, the UK's most serious computer crime statute. The National Crime Agency described the section as covering unauthorised acts that cause or create a significant risk of serious damage, where the offender intends or is reckless as to that damage. "Section 3ZA of the CMA is the most serious section as it applies where the unauthorised act causes or creates a significant risk of serious damage, and the person intends or is reckless as to that damage" Both men pleaded guilty on the basis that they were reckless, not intentional.

Security Minister Dame Angela Eagle said the case shows the very real threat cybercriminals pose to critical infrastructure. "This shocking case shows the very serious threat that cyber criminals pose to our security and prosperity – a key part of our capital’s infrastructure lost millions of pounds and ordinary paying customers suffered huge disruption"

HOW THEY BROKE IN

Between August 31 and September 3, 2024, Jubair and Flowers gained unauthorised access to TfL's network. They purchased partial TfL credentials from well-known criminal forums and used those to reset two-factor authentication on employee accounts. Then they impersonated an employee and socially engineered a TfL helpdesk worker into resetting the password for that account. Once inside, they worked to elevate privileges and reached databases containing what was originally thought to be information on around 5,000 people. It came to light earlier this year that the group actually accessed data on roughly 7 million users.

The pair communicated through Telegram and used a shared online workspace during the attack. A search of Flowers' home uncovered laptops, hard drives, USB devices, and a video showing Jubair inside TfL's systems. Police arrested Flowers on September 6, 2024. At the time of that arrest, investigators said Flowers was also involved in attacks targeting two US healthcare organisations, SSM Health Care Corporation and Sutter Health. Jubair was arrested later, on September 16.

THE REAL COST TO LONDON

The attack cost TfL an estimated £29 million. While the transport network itself saw minimal disruption in real terms, the breach affected 148 systems and forced all 27,000 employees to reset their passwords in person, not remotely. Investigators estimated that a complete outage of London's transport network could have cost the UK economy up to £56 billion.

The operational fallout was extensive. The incident disrupted the Dial-a-Ride booking system, concessionary travel cards, digital payments, the refund system, the planned rollout of contactless ticketing, and applications for children's discounted travel cards. TfL was not able to issue photo travel cards to Londoners until December 4, 2024, more than three months after the breach began.

THE JUDGE'S CALCULATION

Mr Justice Turner, delivering the sentence, noted the pair's immaturity, the sophistication of the offending, the scale of the impact on TfL, the significant planning behind the attack, and that both knew the criminality of their actions. He also acknowledged the age gap between them: Jubair is one year and four months older than Flowers, which the judge said marks a potentially significant distinction in maturity. The judge recognised both defendants' neurodiversity and said the sentence was the most lenient he could give while still reflecting the seriousness of the offences. They received a 15 per cent reduction for their guilty pleas.

Flowers faced additional trouble. He was arrested again for breaching bail conditions related to device use. Jubair faced a separate charge after refusing to provide investigators with the PINs and passwords for seized devices.

WO SCATTERED SPIDER ACTUALLY IS

Scattered Spider is not a formal group with hierarchy or command structure. Authorities describe it as a loosely connected network of English-speaking individual cybercriminals, mostly young men aged 16 to 25. They have claimed responsibility for some of the highest-profile attacks of recent years, including the 2023 breach of MGM Resorts and attacks on British retail giants in 2025. Paul Foster of the NCA called Scattered Spider the most significant cybercrime threat to the UK in recent years, stating that "Scattered Spider has been the most significant cybercrime threat to the UK in recent years. Through this investigation, we have severely disrupted that threat and brought key offenders to justice"

The NCA has continually refused to comment on whether Flowers or Jubair were linked to those other major attacks. The sentencing only covers the TfL breach, but the disruption to the group's operations is seen as a major blow.

A LANDMARK PROSECUTION

Today's sentencing closes the book on the biggest prosecution of cyber offenders in UK history, according to the NCA. Section 3ZA of the Computer Misuse Act is rarely used. The only previous conviction under the statute came last year, involving a former GCHQ intern jailed for six years following a national security investigation. The NCA said there were no parallels between that case and the TfL attack.

The fact that two teenagers, one still 18 at the time of the attack, could inflict £29 million in damage and access millions of people's personal data is a stark illustration of the low barrier to entry in cybercrime. They did not need sophisticated zero-day exploits. They bought credentials off criminal forums and talked their way past a helpdesk. That pattern is depressingly common, but the scale of the impact and the rarity of a successful prosecution under Section 3ZA make this case a benchmark for how the UK intends to respond to the next generation of financially motivated hackers.


what did you make of it?

share

more from cybersecurity