Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack — Threadlinqs Intelligence
As of 2026-07-17, Two Scattered Spider Leaders Jailed for £29M Transport for London (TfL) Cyberattack is a high-severity threat intel threat attributed to Scattered Spider, tracked by Threadlinqs Intelligence with 9 detection rules (Splunk SPL, Microsoft KQL, Sigma) and 22 indicators of compromise.
Threat ID: TL-2026-1429 · Severity: HIGH · Status: RESOLVED · Category: THREAT_INTEL
Attribution: Scattered Spider · FINANCIAL
Thalha Jubair, 20, and Owen Flowers, 18, both leading members of the Scattered Spider cybercrime group, were sentenced to five years and six months each at Woolwich Crown Court on 16 July 2026 under
On 16 July 2026, Woolwich Crown Court sentenced Thalha Jubair (20, of Bow, East London) and Owen Flowers (18, of Walsall) to five years and six months' imprisonment each for their roles in the August-September 2024 cyberattack on Transport for London (TfL), one of the largest transit authorities in the world. Both pleaded guilty on the first day of their trial, 22-23 June 2026, receiving a 15% sentence reduction. The charge — conspiracy to commit unauthorized acts against TfL computer systems with recklessness as to whether the acts would cause serious damage to human welfare — was brought under Section 3ZA of the Computer Misuse Act 1990, a provision reserved for the most severe offenses and only the second (per the NCA) or first (per the CPS) conviction secured under it in UK legal history. The National Crime Agency (NCA) described the case as the largest cybercrime prosecution ever brought before UK courts.
Jubair and Flowers were both identified as leading members of Scattered Spider (aka UNC3944, Octo Tempest, Scatter Swine, 0ktapus, Storm-0875, Muddled Libra), a loosely affiliated, predominantly English-speaking cybercriminal collective of individuals aged roughly 16-25 known for social-engineering-driven intrusions, SIM swapping, and data extortion. The TfL intrusion began on 31 August 2024 when the pair used TfL employee credentials purchased on criminal forums, combined with a helpdesk vishing (voice phishing) call impersonating a TfL employee, to trigger a fraudulent 2FA/password reset and gain initial account access after several failed attempts. From there they escalated privileges and moved laterally into internal databases and infrastructure, ultimately touching 148 systems and accessing records that TfL initially told the public numbered around 5,000 people but which TfL and the NCA later confirmed reached approximately 7 million customer records (names, emails, home addresses, and for a subset of customers potentially bank account/sort-code details). The intrusion, including a roughly 16-hour livestreamed session in which the attackers navigated TfL's internal systems, forced all 27,000-28,000 TfL staff into in-person password resets, disabled online account logins and customer portals, halted new Oyster/photocard applications until 4 December 2024, delayed the contactless-payment rollout, disrupted Dial-a-Ride booking and concessionary travel-card services, and impaired Oyster refund processing — while core train and bus operations continued running. NCA investigators separately assessed that a full network shutdown scenario could have cost the UK economy up to £56 billion; the realized direct cost to TfL was approximately £29 million in remediation plus an estimated £10 million in lost revenue.
Both defendants were arrested on 16 September 2024 (Flowers was first arrested 6 September 2024 and later breached bail conditions twice, in October 2024 and May 2025, related to prohibited device use; Jubair separately faced a charge for refusing to provide device PINs/passwords to investigators). Digital forensics were central to the case: an Acer laptop seized from Flowers contained remote-infrastructure access logs, virtual-machine connection records, screenshots and videos documenting the TfL intrusion in progress, a cryptocurrency wallet used both to pay for attack infrastructure and for food deliveries, spreadsheets of partial TfL employee credentials, and artifacts linking Flowers to separate intrusions against US healthcare providers SSM Health Care Corporation (conspiracy) and Sutter Health (attempted attack) in September 2024 — in chat logs Flowers reportedly acknowledged the healthcare attacks could risk killing an at-risk patient. Jubair and Flowers communicated over Telegram via a shared online workspace during the operation.
Both defendants have extensive prior involvement in the Scattered Spider/Lapsus$ ecosystem. Jubair, online as "Rocket Ace" and (at age 15) "Everlynn," was previously convicted in
Target sectors: transport, government administration, health, telecoms, hospitality, technology
Target regions: united kingdom, North America
Detections & IOCs
As of 2026-07-28, this threat has 9 detection rule(s) across Splunk SPL, Microsoft KQL and Sigma, and 22 indicator(s) of compromise. Detection query text and full IOC values are available to authenticated users and programmatically via the Threadlinqs MCP server (Purple tier). View plans.
THREAT_INTEL, HIGH, threat intelligence, cybersecurity, T1589.001, T1598.004, T1588.002, T1566.004, T1133, T1204, T1098, T1556.006, T1078.004, T1068