Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack

Two Scattered Spider Leaders Jailed for £29M Transport for (TL-2026-1429), also tracked as TfL Cyberattack Sentencing, is a high-severity tracked intrusion set, first published 2026-07-17. It is attributed to Scattered Spider with high confidence, affects Transport for London TfL internal corporate and customer-facing IT, maps to 32 MITRE ATT&CK techniques (T1003, T1003.006, T1018), and is covered by 9 detection rules and 22 indicators of compromise.

Key facts for TL-2026-1429

Threat ID
TL-2026-1429
Also known as
TfL Cyberattack Sentencing, Operation against Thalha Jubair and Owen Flowers
Severity
HIGH
Status
RESOLVED
Category
THREAT_INTEL
First published
2026-07-17
Last reviewed
2026-07-17
Attribution
Scattered Spider
Attribution confidence
HIGH
Motivation
FINANCIAL
Target sectors
transport, government administration, health, telecoms, hospitality, technology
Target regions
united kingdom, North America
Detection rules
9
Indicators of compromise
22

Malware and tooling in Two Scattered Spider Leaders Jailed for £29M Transport for

Malware and tooling: BlackCat/ALPHV ransomware, ConnectWise - S0591, Mimikatz, Rclone - S1040, ngrok - S0508

Thalha Jubair, 20, and Owen Flowers, 18, both leading members of the Scattered Spider cybercrime group, were sentenced to five years and six months each at Woolwich Crown Court on 16 July 2026 under Section 3ZA of the UK Computer Misuse Act 1990 for the 31 August–3 September 2024 attack on Transport for London that compromised 148 systems, exposed up to 7 million customer records, and cost TfL an estimated £29 million.

How Two Scattered Spider Leaders Jailed for £29M Transport for works

On 16 July 2026, Woolwich Crown Court sentenced Thalha Jubair (20, of Bow, East London) and Owen Flowers (18, of Walsall) to five years and six months' imprisonment each for their roles in the August-September 2024 cyberattack on Transport for London (TfL), one of the largest transit authorities in the world. Both pleaded guilty on the first day of their trial, 22-23 June 2026, receiving a 15% sentence reduction. The charge — conspiracy to commit unauthorized acts against TfL computer systems with recklessness as to whether the acts would cause serious damage to human welfare — was brought under Section 3ZA of the Computer Misuse Act 1990, a provision reserved for the most severe offenses and only the second (per the NCA) or first (per the CPS) conviction secured under it in UK legal history. The National Crime Agency (NCA) described the case as the largest cybercrime prosecution ever brought before UK courts.

Jubair and Flowers were both identified as leading members of Scattered Spider (aka UNC3944, Octo Tempest, Scatter Swine, 0ktapus, Storm-0875, Muddled Libra), a loosely affiliated, predominantly English-speaking cybercriminal collective of individuals aged roughly 16-25 known for social-engineering-driven intrusions, SIM swapping, and data extortion. The TfL intrusion began on 31 August 2024 when the pair used TfL employee credentials purchased on criminal forums, combined with a helpdesk vishing (voice phishing) call impersonating a TfL employee, to trigger a fraudulent 2FA/password reset and gain initial account access after several failed attempts. From there they escalated privileges and moved laterally into internal databases and infrastructure, ultimately touching 148 systems and accessing records that TfL initially told the public numbered around 5,000 people but which TfL and the NCA later confirmed reached approximately 7 million customer records (names, emails, home addresses, and for a subset of customers potentially bank account/sort-code details). The intrusion, including a roughly 16-hour livestreamed session in which the attackers navigated TfL's internal systems, forced all 27,000-28,000 TfL staff into in-person password resets, disabled online account logins and customer portals, halted new Oyster/photocard applications until 4 December 2024, delayed the contactless-payment rollout, disrupted Dial-a-Ride booking and concessionary travel-card services, and impaired Oyster refund processing — while core train and bus operations continued running. NCA investigators separately assessed that a full network shutdown scenario could have cost the UK economy up to £56 billion; the realized direct cost to TfL was approximately £29 million in remediation plus an estimated £10 million in lost revenue.

Both defendants were arrested on 16 September 2024 (Flowers was first arrested 6 September 2024 and later breached bail conditions twice, in October 2024 and May 2025, related to prohibited device use; Jubair separately faced a charge for refusing to provide device PINs/passwords to investigators). Digital forensics were central to the case: an Acer laptop seized from Flowers contained remote-infrastructure access logs, virtual-machine connection records, screenshots and videos documenting the TfL intrusion in progress, a cryptocurrency wallet used both to pay for attack infrastructure and for food deliveries, spreadsheets of partial TfL employee credentials, and artifacts linking Flowers to separate intrusions against US healthcare providers SSM Health Care Corporation (conspiracy) and Sutter Health (attempted attack) in September 2024 — in chat logs Flowers reportedly acknowledged the healthcare attacks could risk killing an at-risk patient. Jubair and Flowers communicated over Telegram via a shared online workspace during the operation.

Both defendants have extensive prior involvement in the Scattered Spider/Lapsus$ ecosystem. Jubair, online as "Rocket Ace" and (at age 15) "Everlynn," was previously convicted in 2023 as a member of the Lapsus$ crew for the BT/EE and Nvidia breaches, sold fraudulent Emergency Data Requests using compromised government email addresses, and co-administered "Star Chat," a Telegram-based SIM-swapping service that used voice- and SMS-based phishing to steal employee credentials at major US and UK wireless carriers and redirect victim phone numbers to attacker-controlled devices. He also participated in a summer 2022 SMS phishing campaign against more than 130 organizations including LastPass, DoorDash, Mailchimp, Plex, and Signal, netting at least $8 million in stolen cryptocurrency, and has 22 prior UK convictions (13 fraud-related, 1 blackmail). In September 2025 US federal prosecutors in New Jersey unsealed a criminal complaint against Jubair alleging participation in roughly 120 network intrusions against 47+ US entities between May 2022 and September 2025 — including critical national infrastructure and a federal court system — with victims paying at least $115 million in ransoms; roughly $8.4 million in cryptocurrency was seized from a related server wallet. Jubair faces up to 95 years if convicted in the US and a pending US trial follows his UK sentence. Flowers, online as "Bo764," previously gave anonymous media interviews after the September 2023 MGM Resorts and Caesars Entertainment ransomware/social-engineering attacks (also attributed to Scattered Spider, with ALPHV/BlackCat ransomware deployment in the MGM incident) and had received a police cease-and-desist warning in October 2023 for prior lower-level computer offenses before the TfL attack. Both defendants are documented as neurodivergent (autism; Jubair also with depression and a severe mood disorder).

NCA Deputy Director Paul Foster called Scattered Spider "the most significant cybercrime threat to the UK in recent years" and stated the investigation was more complex than Operation Chronos, the LockBit ransomware takedown; the agency and Microsoft both assessed that the arrests and prosecution have measurably degraded the group's operational capability, though Scattered Spider/Octo Tempest/UNC3944 activity by other affiliated actors continues to be tracked via the CISA/FBI joint advisory AA23-320A (most recently updated July 2025) and MITRE ATT&CK Group G1015. This threat record documents the sentencing outcome and consolidates the confirmed TTPs and technical/legal facts of the TfL intrusion together with the actor's documented broader tradecraft as tracked by CISA and MITRE ATT&CK.

MITRE ATT&CK techniques used in TL-2026-1429

Credential Access

T1003 OS Credential Dumping; T1003.006 DCSync; T1552.001 Credentials In Files; T1621 Multi-Factor Authentication Request Generation

Discovery

T1018 Remote System Discovery; T1083 File and Directory Discovery; T1087.002 Domain Account

Exfiltration

T1020 Automated Exfiltration; T1567.002 Exfiltration to Cloud Storage

Lateral Movement

T1021.001 Remote Desktop Protocol; T1570 Lateral Tool Transfer

Defense Evasion

T1036 Masquerading; T1070.008 Clear Mailbox Data

Privilege Escalation

T1068 Exploitation for Privilege Escalation

Command and Control

T1071.001 Web Protocols; T1090 Proxy; T1219.002 Remote Desktop Software

Collection

T1074 Data Staged; T1113 Screen Capture; T1213.002 Sharepoint

Persistence

T1078.004 Cloud Accounts; T1098 Account Manipulation; T1556.006 Multi-Factor Authentication

Initial Access

T1133 External Remote Services; T1566.004 Spearphishing Voice

execution

T1204 User Execution

initial-access

T1451 SIM Card Swap

Impact

T1485 Data Destruction; T1657 Financial Theft

Resource Development

T1588.002 Tool

Reconnaissance

T1589.001 Credentials; T1598.004 Spearphishing Voice

Affected products and versions in Two Scattered Spider Leaders Jailed for £29M Transport for

  • Transport for London — TfL internal corporate and customer-facing IT systems (148 systems, incl. Oyster/photocard, Dial-a-Ride, contactless ticketing, account portal)
    Vulnerable versions: as deployed Aug-Sept 2024
    Fixed in: remediated post-incident, full restoration by Dec 2024
  • SSM Health Care Corporation — US healthcare IT systems
    Vulnerable versions: as targeted Sept 2024 (conspiracy)
    Fixed in: not specified
  • Sutter Health — US healthcare IT systems
    Vulnerable versions: as targeted Sept 2024 (attempted attack)
    Fixed in: not specified

Remediation for Two Scattered Spider Leaders Jailed for £29M Transport for

Immediate actions

  • Enforce strict helpdesk identity-verification procedures (call-back to a pre-registered number, manager approval) before any password or MFA reset
  • Require phishing-resistant MFA (FIDO2/WebAuthn hardware keys) for privileged and helpdesk-facing accounts to eliminate SMS/voice/push-based MFA bypass
  • Restrict and monitor use of commercial remote-monitoring-and-management (RMM) tools (e.g., ConnectWise, AnyDesk) via application allow-listing
  • Audit and rotate credentials exposed via employee-data broker/criminal-forum listings; monitor for credential-stuffing activity against employee portals

Workarounds

  • Where phishing-resistant MFA cannot be deployed immediately, disable self-service MFA/password reset via helpdesk phone channel and require in-person or video-verified identity checks

Longer-term hardening

  • Deploy conditional-access policies that block device-registration and additional-cloud-credential enrollment from unrecognized devices/locations
  • Implement network segmentation between customer-facing and back-office/database systems to limit lateral movement blast radius
  • Run regular vishing/social-engineering red-team exercises against IT helpdesk and customer-support staff
  • Establish 24/7 SOC monitoring for anomalous privilege escalation, mass account-manipulation events, and large data-staging/exfiltration activity

Timeline of Two Scattered Spider Leaders Jailed for £29M Transport for

  • Start of the ~120-intrusion campaign later charged against Thalha Jubair in the September 2025 US federal complaint (activity window May 2022–September 2025).
  • MGM Resorts and Caesars Entertainment hit by Scattered Spider social-engineering/ransomware attacks (ALPHV/BlackCat); Owen Flowers later gave anonymous media interviews about the incidents.
  • UK police issue a cease-and-desist warning to Owen Flowers over prior lower-level computer offenses.
  • Jubair and Flowers gain unauthorized access to Transport for London systems using purchased employee credentials and a helpdesk vishing call to trigger a fraudulent 2FA/password reset.
  • Attacker access to TfL systems ends after roughly three days; 148 systems ultimately found to have been touched and up to 7 million customer records accessed.
  • Owen Flowers first arrested in connection with the TfL and US healthcare intrusions.
  • Thalha Jubair and Owen Flowers both arrested at their homes by the NCA and City of London Police; devices including an Acer laptop, hard drives and USB media seized.
  • Owen Flowers breaches bail conditions relating to prohibited device use (first of two breaches).
  • TfL restores Oyster photocard issuance, among the last disrupted services to return to normal operation.
  • Owen Flowers breaches bail conditions a second time.
  • US federal prosecutors in New Jersey unseal a criminal complaint against Thalha Jubair alleging ~120 network intrusions against 47+ US entities and $115M+ in ransom payments; he faces up to 95 years if convicted.
  • Jubair and Flowers plead guilty on the first day of their UK trial at Woolwich Crown Court, receiving a 15% sentence reduction.
  • Woolwich Crown Court sentences both defendants to five years and six months' imprisonment each under Section 3ZA of the Computer Misuse Act 1990 for the TfL attack.

Sources cited for Two Scattered Spider Leaders Jailed for £29M Transport for

Threats related to Two Scattered Spider Leaders Jailed for £29M Transport for

Detection coverage for TL-2026-1429

As of 2026-07-17, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-1429 across Splunk SPL, Microsoft KQL and Sigma, covering 22 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Latest Threats