Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

TfL hackers jailed five and a half years

2 min read
18:20UTC

Owen Flowers, 18, and Thalha Jubair, 20, drew five years six months each for the 2024 Transport for London hack that disabled 148 systems and cost £29 million.

TechnologyAssessed
Key takeaway

The UK's biggest cybercrime case jailed two Scattered Spider hackers over the 2024 TfL attack.

Owen Flowers, 18, and Thalha Jubair, 20, were jailed for five years and six months each at Woolwich Crown Court on Thursday 16 July for the September 2024 attack on Transport for London (TfL). The National Crime Agency (NCA) called it Britain's largest-ever cybercrime prosecution 1.

The attack disabled 148 systems, exposed data on roughly 10 million passengers and cost TfL an estimated £29 million. Had it shut the network entirely, the NCA put the potential hit to the UK economy at £56 billion.

The pair bought partial employee credentials on criminal forums, then phoned the TfL IT helpdesk posing as staff to secure a password reset and a two-factor authentication (2FA) bypass. That route repeats the Scattered Spider helpdesk-social-engineering playbook, the same group whose alleged member Peter Stokes, known online as Bouquet, was arrested in Helsinki in April and now faces US extradition . The NCA called Scattered Spider "the most significant cybercrime threat to the UK in recent years" and said Flowers was still hacking US healthcare providers SSM Health and Sutter Health when arrested 2.

Deep Analysis

In plain English

Scattered Spider is a cybercrime gang known for tricking IT helpdesks into resetting passwords, rather than hacking computer code directly. In September 2024 members of the group attacked Transport for London (TfL), the body that runs London's buses, Tube and trains, knocking out 148 of its computer systems and exposing personal data belonging to 10 million passengers. On 16 July a British court, Woolwich Crown Court, sentenced two of the people responsible, Owen Flowers and Thalha Jubair, to five years and six months in prison each. The National Crime Agency, the UK's equivalent of the FBI, called it the country's biggest-ever cybercrime prosecution.

Deep Analysis
Root Causes

TfL's exposure traces to a structural identity-verification gap: Scattered Spider's playbook targets IT helpdesk password-reset procedures, impersonating employees by phone to bypass multi-factor authentication rather than breaking any cryptographic control.

The scale of disruption, 148 systems and 10 million passenger records, reflects how deeply helpdesk-issued credentials cascade through a large public-sector network once initial access is gained, a dependency structure common to sprawling legacy transport IT estates.

Escalation

Flowers was arrested while separately attacking two more US healthcare providers, SSM Health and Sutter Health, showing the wider Scattered Spider collective kept operating despite the conviction of two known members.

What could happen next?
  • Precedent

    The case establishes UK prosecutorial capacity to convict Scattered Spider members domestically rather than relying solely on US extradition requests.

  • Risk

    Flowers' arrest while breaching two more US healthcare providers indicates the wider Scattered Spider collective kept operating despite the conviction of two known members.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

National Crime Agency· 24 Jul 2026
Read original
Causes and effects
This Event
TfL hackers jailed five and a half years
Britain's largest cybercrime prosecution puts custodial numbers on the helpdesk-social-engineering method Scattered Spider has exported across sectors.
Different Perspectives
ENISA
ENISA
ENISA published an SME cyber-resilience maturity model on 6 August and updated the Cyber Resilience Act reporting-platform FAQ on 31 August. The agency supplies common implementation tools for smaller operators, but it cannot fine organisations that do not use them.
UAE Cyber Security Council
UAE Cyber Security Council
On 10 August, the UAE Cyber Security Council said national teams contained attacks on aviation, energy and education before objectives were reached. Its second monthly statement, after a 3 July financial-sector disclosure, makes public reporting of stopped attacks part of its operating posture.
South African authorities
South African authorities
INTERPOL said on 25 August that South African authorities made 39 arrests, seized US$2.67 million and blocked 257 accounts during Operation Jackal IV. Their share of the 23-country operation shows the material enforcement burden in a cross-border fraud case.
Europol
Europol
On 2 September, Europol announced the sinkholing of Sality after a 31 August operation involving US, Bulgarian, Hungarian and Romanian authorities. Its more than 11 million linked IP addresses measure infrastructure contact, not confirmed victims, and show why technical partners joined the action.
CISA
CISA
From 3 August to 2 September, CISA recorded three-day deadlines for 24 of 37 KEV additions, compared with 34 of 39 from 10 June to 29 July. The falling share changes the urgency signal that US federal agencies and private-sector tooling draw from the catalogue.
Beacon
Beacon
On 3 September, Beacon said its final report found that an intruder likely exported its customer database during roughly one hour and 27 minutes on 27 July. Charities using the CRM now have a named exposure route, a compromised AWS access key in public build artefacts.