Two leading members of the Scattered Spider cybercrime collective, Thalha Jubair and Owen Flowers, have been sentenced to 5.5 years in prison for carrying out a 2024 cyberattack against Transport for London (TfL), resulting in £29 million in recovery expenses.
The Attack and Its Consequences
The pair pleaded guilty to offenses under Section 3ZA of the Computer Misuse Act and admitted to infiltrating TfL's network, disrupting public services, and exposing customer data. The attack forced all 27,000 TfL employees to attend offices for in-person password resets, and 148 internal systems became unavailable, including critical operational platforms.
The breach also compromised data held within TfL's refund system for Oyster, leaving some passengers waiting significantly longer than normal for refunds. Applications for Oyster photocards used by children and young people were temporarily suspended.
Financial Consequences and Potential Impact
The National Crime Agency (NCA) stated that the financial consequences could have been significantly worse, with an estimated economic impact of £56 billion if the attackers had succeeded in disabling London's transport network.
The NCA identified Jubair and Flowers as leading members of Scattered Spider, a loosely organized English-speaking cybercriminal network responsible for numerous high-profile intrusions targeting organizations across the U.K. and United States.
Investigation and Arrests
British investigators carried out arrests in September 2024, which significantly disrupted the group's operations. Flowers was first arrested in September 2024, while simultaneously compromising systems belonging to U.S. healthcare providers SSM Health Care Corporation and Sutter Health.
Searches of his home uncovered laptops, desktop computers, external hard drives, and USB devices, including a screenshot showing connectivity to TfL's infrastructure and videos allegedly recorded by Flowers showing Jubair actively accessing TfL systems during the intrusion.
Coordination and Communication
The pair coordinated the attack through Telegram and an online collaborative workspace. Flowers was later rearrested after breaching bail conditions relating to restrictions on device usage, and Jubair faced an additional charge after refusing to disclose passwords and PINs for seized electronic devices.
Security officials said the case demonstrated both the growing sophistication of cybercriminal groups and the importance of early reporting by victims. The convictions would likely not have been possible without TfL's prompt engagement with law enforcement.
Proposed Cyber Crime Risk Orders
Commander Ollie Shaw of the City of London Police used the sentencing to argue for proposed Cyber Crime Risk Orders, which would allow courts to impose technology restrictions on convicted cyber offenders after release. The proposed measures could limit offenders' access to devices, online services, or technologies frequently used to commit cybercrime.
Security Minister Angela Eagle said the case illustrated the risks cybercriminals pose to Britain's economy and national infrastructure, stating that there will be consequences for those caught engaging in illegal cyber activity.
London's Transport Commissioner Andy Lord welcomed the sentencing, thanking investigators and TfL staff who helped respond to the incident and restore affected systems. The investigation was led jointly by the National Crime Agency and City of London Police, with support from the West Midlands Regional Organised Crime Unit, British Transport Police, and international partners, including the FBI.
Jubair and Flowers were also arrested last July on suspicion of involvement in a series of ransomware attacks targeting British retailers Marks & Spencer, the Co-op, and the London-based luxury store Harrods. No suspects have yet been charged with those crimes.
Source: The Record