Scattered Spider Hackers Behind London Transport Network Breach Identified

Two members of the notorious Scattered Spider cybercriminal collective have pleaded guilty to orchestrating a devastating cyberattack against Transport for London (TfL), one of the UK’s most critical pieces of national infrastructure.

Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, West Midlands, admitted their roles on June 22, 2026, at Woolwich Crown Court on the first day of what was expected to be a full trial. Sentencing is scheduled for July 16, 2026.

The breach unfolded between August 31 and September 3, 2024, when the pair infiltrated TfL’s internal network systems.

The intrusion triggered an unprecedented organizational response; all 28,000 TfL employees were required to attend a physical office location to complete mandatory password resets, a logistical disruption of significant scale.

TfL reported approximately £29 million in losses and recovery costs, making it one of the most financially damaging cyberattacks on UK public infrastructure in recent memory.

Attackers accessed data from TfL’s Oyster refund system, disrupted the customer refund processing pipeline, and shut down the Oyster photocard application system used by children and young people across the city.

Flowers was first arrested on September 6, 2024, just days after the attack concluded. NCA officers executing a search of his residence recovered multiple devices, including laptops, tower computers, hard drives, and USB sticks.

A key piece of forensic evidence was an Acer laptop containing a screenshot of active network connectivity to TfL infrastructure.

The same laptop held screen-recorded videos of Jubair actively accessing TfL systems during the breach. Simultaneous Telegram communications between the pair during the attack further corroborated their coordination.

Investigators also discovered that Flowers had accessed a dark web credential marketplace that sold breached login data. Both suspects were arrested at their home addresses on September 16, 2024, by the NCA and City of London Police (COLP).

Beyond the TfL breach, investigators uncovered evidence that Flowers had also compromised the networks of SSM Health Care Corporation and Sutter Health, two major US healthcare organizations, highlighting the transnational nature of the Scattered Spider threat group.

Scattered Spider is a loosely organized, English-speaking cybercriminal collective known for social engineering, SIM swapping, and ransomware deployment.

The group has previously been linked to high-profile breaches at MGM Resorts, Caesars Entertainment, and multiple cloud-based enterprises. The investigation was supported by the West Midlands Regional Organized Crime Unit and British Transport Police.

NCA Deputy Director Paul Foster emphasized the real-world consequences of cybercrime: “The attack caused millions of pounds in losses to a key part of the UK’s critical national infrastructure, and was a significant inconvenience for customers.”

City of London Police Deputy Commissioner Nik Adams reinforced that joint law enforcement coordination was central to securing the conviction, noting the UK’s commitment to remaining a “hostile environment for cyber criminals.”

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories