Skip to content
You can now search across every topic, entity and event.What's new
Cybersecurity: Threats and Defences
24JUL

TfL hackers jailed five and a half years

2 min read
18:20UTC

Owen Flowers, 18, and Thalha Jubair, 20, drew five years six months each for the 2024 Transport for London hack that disabled 148 systems and cost £29 million.

TechnologyAssessed
Key takeaway

The UK's biggest cybercrime case jailed two Scattered Spider hackers over the 2024 TfL attack.

Owen Flowers, 18, and Thalha Jubair, 20, were jailed for five years and six months each at Woolwich Crown Court on Thursday 16 July for the September 2024 attack on Transport for London (TfL). The National Crime Agency (NCA) called it Britain's largest-ever cybercrime prosecution 1.

The attack disabled 148 systems, exposed data on roughly 10 million passengers and cost TfL an estimated £29 million. Had it shut the network entirely, the NCA put the potential hit to the UK economy at £56 billion.

The pair bought partial employee credentials on criminal forums, then phoned the TfL IT helpdesk posing as staff to secure a password reset and a two-factor authentication (2FA) bypass. That route repeats the Scattered Spider helpdesk-social-engineering playbook, the same group whose alleged member Peter Stokes, known online as Bouquet, was arrested in Helsinki in April and now faces US extradition . The NCA called Scattered Spider "the most significant cybercrime threat to the UK in recent years" and said Flowers was still hacking US healthcare providers SSM Health and Sutter Health when arrested 2.

Deep Analysis

In plain English

Scattered Spider is a cybercrime gang known for tricking IT helpdesks into resetting passwords, rather than hacking computer code directly. In September 2024 members of the group attacked Transport for London (TfL), the body that runs London's buses, Tube and trains, knocking out 148 of its computer systems and exposing personal data belonging to 10 million passengers. On 16 July a British court, Woolwich Crown Court, sentenced two of the people responsible, Owen Flowers and Thalha Jubair, to five years and six months in prison each. The National Crime Agency, the UK's equivalent of the FBI, called it the country's biggest-ever cybercrime prosecution.

Deep Analysis
Root Causes

TfL's exposure traces to a structural identity-verification gap: Scattered Spider's playbook targets IT helpdesk password-reset procedures, impersonating employees by phone to bypass multi-factor authentication rather than breaking any cryptographic control.

The scale of disruption, 148 systems and 10 million passenger records, reflects how deeply helpdesk-issued credentials cascade through a large public-sector network once initial access is gained, a dependency structure common to sprawling legacy transport IT estates.

Escalation

Flowers was arrested while separately attacking two more US healthcare providers, SSM Health and Sutter Health, showing the wider Scattered Spider collective kept operating despite the conviction of two known members.

What could happen next?
  • Precedent

    The case establishes UK prosecutorial capacity to convict Scattered Spider members domestically rather than relying solely on US extradition requests.

  • Risk

    Flowers' arrest while breaching two more US healthcare providers indicates the wider Scattered Spider collective kept operating despite the conviction of two known members.

First Reported In

Update #11 · Zimbra zero-click, and a 15-nation reply

National Crime Agency· 24 Jul 2026
Read original
Causes and effects
This Event
TfL hackers jailed five and a half years
Britain's largest cybercrime prosecution puts custodial numbers on the helpdesk-social-engineering method Scattered Spider has exported across sectors.
Different Perspectives
AIVD
AIVD
AIVD co-signed AA26-204A alongside CISA, the NSA and the FBI, adding its signature to the fifteen-agency coalition naming LAUNDRY BEAR. Dutch involvement continues a pattern of joint Five Eyes-adjacent advisories the agency has co-issued with CISA and NCSC through 2026.
CNCERT
CNCERT
China's national CERT was not party to AA26-204A and has previously argued that Western KEV-based advisories conflate demonstrated exploit capability with confirmed breach impact. It is expected to treat this fortnight's coalition-based Russia attribution as a Five Eyes-led exercise rather than an independently verified finding.
Russia
Russia
Moscow has not publicly responded to the AA26-204A attribution naming LAUNDRY BEAR as a Russian state-supported actor behind the Zimbra zero-click chain. Russian officials have consistently denied state involvement in prior Western cyber-attribution advisories, a pattern this fifteen-agency coalition is likely to meet with the same denial.
National Crime Agency
National Crime Agency
The NCA called the Woolwich Crown Court sentencing of Owen Flowers and Thalha Jubair Britain's largest-ever cybercrime prosecution. It expects continued pressure on Scattered Spider's UK-linked membership, alongside City of London Police's push for statutory Cyber Crime Risk Orders.
CISA
CISA
CISA co-led AA26-204A naming LAUNDRY BEAR and added five more flaws to KEV this fortnight, including a three-day Oracle EBS deadline, while absorbing a one-month detection-to-listing gap on FortiSandbox. It expects the risk-tiered BOD 26-04 model to hold even as a proposed $707m FY27 cut threatens the staffing behind it.
UK managed service providers and data centre operators
UK managed service providers and data centre operators
Newly brought into critical-infrastructure scope by the Cyber Security and Resilience Bill's Lords second reading, facing fines up to £17m or 4% of global turnover and a new near-miss reporting duty they did not previously carry. The sector moves from best-practice guidance to statutory exposure within this Parliamentary session.