Two young members of the notorious Scattered Spider hacking collective have been sentenced to five years and six months in prison each for orchestrating a cyber attack on Transport for London (TfL) that cost tens of millions of pounds and disrupted services for thousands of Londoners.
Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, were sentenced at Woolwich Crown Court on July 16, 2026, following the largest cybercrime prosecution ever brought before UK courts.
Both men pleaded guilty last month, changing their pleas on the day their trial was set to begin. The National Crime Agency (NCA) and City of London Police (CoLP) traced the intrusion to a three-day window between August 31 and September 3, 2024.
Scattered Spider Hackers Sentenced
The attackers infiltrated TfL’s network, forcing all 27,000 employees to attend in-person password resets and knocking 148 systems offline, some critical enough to require manual workarounds for weeks.
Disrupted services included the Dial-a-Ride booking system for vulnerable residents, concessionary travel card issuance, digital payments, and the rollout of contactless ticketing.
Attackers also accessed TfL’s Oyster refunds system and disabled the application process for children’s and young people’s Oyster photocards.
TfL reported £29 million in direct losses and recovery costs. Investigators noted that had the attack succeeded in fully shutting down London’s transport network, the economic damage could have reached £56 billion.
The pair were charged under Section 3ZA of the Computer Misuse Act, the statute’s most severe provision, covering unauthorized acts causing or risking serious damage where the offender intended or was reckless to that outcome. This marked only the second prosecution of its kind in the UK.
NCA stated that Flowers was first arrested on September 6, 2024, while actively hacking US healthcare providers SSM Health Care Corporation and Sutter Health.
A search of his home turned up laptops, hard drives, and USB devices, including a screenshot showing network connectivity to TfL infrastructure and recorded videos of Jubair accessing TfL systems in real time.
Both men were arrested again on separate occasions: Flowers for breaching bail conditions on device usage, and Jubair for refusing to disclose device PINs and passwords to investigators.
NCA Deputy Director Paul Foster called Scattered Spider “the most significant cybercrime threat to the UK in recent years,” crediting TfL’s early engagement with law enforcement as pivotal to securing convictions.
Microsoft independently assessed that the arrests materially degraded the group’s operational capacity, even as other actors may continue exploiting the damaged Scattered Spider brand.
FBI Cyber Division Assistant Director Brett Leatherman noted the group’s signature tactics, data extortion, SIM-swapping, and social engineering, and pledged continued cross-border collaboration.
City of London Police also used the case to advocate for proposed Cyber Crime Risk Orders (CCROs), which would impose court-supervised, risk-based restrictions on convicted offenders’ technology use, described as a “digital prison” model aimed at both prevention and rehabilitation.
Prevent critical incidents and financial loss with stronger proactive defense. Integrate a live threat feed from 15K SOCs