Vulnerabilities

Scattered Spider Hackers Plead Guilty to TfL Breach

June 24, 2026 00:16 · 10 min read
Scattered Spider Hackers Plead Guilty to TfL Breach

Scattered Spider Members Plead Guilty to Hacking TfL

Two members of the 'Scattered Spider' cybercrime group, Thalha Jubair (20) and Owen Flowers (18), have pleaded guilty to hacking the Transport for London (TfL) systems in 2024. The breach occurred between August 31 and September 3, 2024, and caused millions of pounds in losses.

Jubair and Flowers initially declined involvement in the incident but changed their pleas to guilty on the first day of the proceedings at Woolwich Crown Court. TfL is a public body responsible for managing the majority of London’s transportation networks, serving a metropolitan area of millions, and handling thousands of journeys daily.

The Cyberattack on TfL

On September 2, 2024, TfL's infrastructure suffered a cybersecurity incident, causing operational disruptions that continued for days. The attackers accessed data from TfL's Oyster refunds system and disrupted customer refund services, delaying refunds for some users. On September 12, 2024, TfL admitted that customer data had been stolen in the attack, while the U.K.’s National Crime Agency (NCA) announced the arrest of Flowers, a suspect at the time.

Jubair and Flowers were arrested on September 18, 2025, after investigators retrieved incriminating evidence for both, extending even beyond the TfL cyberattack. Flowers breached his bail conditions twice, in March and in May 2025.

Financial Damage and Investigation

According to the NCA, the cyberattack at TfL forced all 28,000 employees to visit their local offices to reset their passwords and caused £29 million ($38.3M) in financial damage to the public transportation organization. “The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers,” stated NCA’s Deputy Director Paul Foster.

The investigators seized multiple devices from Flower’s home, including a laptop containing a screenshot showing connectivity to TfL infrastructure, evidence of access to a marketplace selling stolen credentials, and videos showing Jubair breaching TfL systems. The hackers communicated via Telegram and a shared online collaboration platform during the intrusion, the NCA stated.

Linked to Other Intrusions

In addition to TfL, authorities have also linked Flowers to intrusions at SSM Health Care Corporation and Sutter Health, both American healthcare organizations. The two Scattered Spider members were scheduled to stand trial on June 22, but the sentencing was rescheduled for July 16 due to their changed plea.

The case highlights the importance of early engagement with law enforcement in the event of a cyberattack. As stated by NCA’s Deputy Director Paul Foster, “Today’s result would not have been possible if TfL had not engaged with law enforcement early, so I would urge any other organization to please do the same in such circumstances.”

The incident also underscores the need for robust cybersecurity measures to prevent such attacks. As the Picus whitepaper shows, breach and attack simulation can help test SIEM and EDR rules, ensuring that threats do not slip by detection.

The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers. - NCA’s Deputy Director Paul Foster

Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free