Two Scattered Spider Hackers Sentenced to 5.5 Years for £29 Million Transport for London Cyberattack
- Jul 17
- 3 min read
Key Findings
Two Scattered Spider members, Owen Flowers (18) and Thalha Jubair (20), sentenced to 5.5 years in prison for 2024 cyberattack on Transport for London
TfL attack cost £29 million; potential complete shutdown could have caused £56 billion in economic damage to UK economy
Attack knocked 148 systems offline, disrupted services for 9 million daily journeys, exposed customer data including bank details
First hackers successfully prosecuted under Section 3ZA of Computer Misuse Act, the legislation's most serious provision
Arrests effectively dismantled Scattered Spider's core operations; Microsoft confirmed the group's degraded capability to conduct cyberattacks
Flowers also linked to intrusions against US healthcare providers SSM Health Care Corporation and Sutter Health
Background
Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, has been one of the most active cybercrime groups targeting major organizations globally since 2022. The group specializes in data extortion, SIM swapping, and social engineering attacks. Between 2022 and 2025, they're believed responsible for hundreds of attacks across both UK and US critical infrastructure, healthcare, and financial sectors.
The TfL Attack
The intrusion occurred between August 31 and September 3, 2024, targeting Transport for London, which oversees approximately 9 million journeys daily across the UK capital. The attack forced all 27,000 TfL employees to physically reset their passwords and brought Dial-a-Ride services for vulnerable passengers offline. Digital payment systems, concessionary travel card issuance, and contactless ticketing rollout all suffered disruption. Customer refunds were delayed, and applications for Oyster photocards closed entirely.
The breach exposed customer names, email addresses, and home addresses. Data from the Oyster refunds system—including bank account numbers and sort codes for approximately 5,000 people—was also compromised. The incident forced TfL to manually shut down its network to contain the attackers, preventing what authorities estimated could have been a catastrophic £56 billion economic impact.
The Investigation and Arrests
The National Crime Agency arrested Flowers on September 6, 2024, just three days after the TfL attack ended. Officers found him actively conducting cyberattacks on two US healthcare organizations at the time of arrest. Investigators seized laptops, hard drives, and USB devices, including one containing a screenshot of TfL network access and videos showing Jubair moving through TfL systems during the attack.
Communication evidence revealed the pair coordinating via Telegram and sharing an online workspace throughout the intrusion. Jubair was arrested separately, with investigators finding evidence linking him to the TfL attack through overseas assistance. Flowers was later arrested again for breaching bail conditions, while Jubair faced additional charges for refusing to provide device passwords.
The Charges and Guilty Pleas
Both defendants were charged under Section 3ZA of the Computer Misuse Act 1990, the legislation's most serious provision, which applies when unauthorized acts cause or create significant risk of serious damage. They pleaded guilty on June 22, 2026, just as their trial was set to begin, admitting they were reckless as to whether they caused or created serious damage.
Flowers faced additional charges related to the US healthcare intrusions. Prosecutors revealed he threatened to lock down SSM Health systems while acknowledging in chats that doing so "might kill some 90-year-old on life support." He admitted conspiracy charges against SSM Health and attempted intrusion charges against Sutter Health.
Sentencing and Legal Significance
Woolwich Crown Court sentenced both men to five years and six months in prison in July 2026. Authorities described this as the UK's largest cybercrime prosecution to date and noted it marked only the second criminal prosecution under Section 3ZA of the Computer Misuse Act. Flowers and Jubair are believed to be the first hackers successfully convicted under this most serious provision.
The case established significant legal precedent in UK cybercrime prosecution, particularly regarding recklessness as it applies to critical infrastructure attacks with potential for widespread harm.
Impact on Scattered Spider Operations
The NCA stated that the arrests effectively dismantled Scattered Spider's core operations. Microsoft independently assessed that the arrests materially degraded the group's ability to conduct cyberattacks going forward. However, authorities acknowledged that other cybercriminals may continue using the Scattered Spider brand, though the organization's centralized criminal activity has been substantially disrupted.
Ongoing Cases
Jubair faces additional charges in the United States relating to approximately 120 network intrusions affecting at least 47 US victims between May 2022 and September 2025. US prosecutors allege the schemes generated over $115 million in ransoms and targeted US critical infrastructure and courts. He faces a maximum of 95 years on those charges, though extradition proceedings remain unclear.
In July 2026, another alleged Scattered Spider member, Peter Stokes (19), known online as "Bouquet," was extradited from Finland to face US charges including participation in a luxury jewelry retailer breach where attackers demanded approximately $8 million in cryptocurrency.
Sources
https://securityaffairs.com/195501/cyber-crime/two-scattered-spider-members-sentenced-to-prison-over-29-million-tfl-cyberattack.html
https://thehackernews.com/2026/07/two-scattered-spider-hackers-get-55.html
https://hackread.com/two-scattered-spider-members-sentenced-tfl-cyberattack/
https://www.securityweek.com/two-scattered-spider-hackers-sentenced-to-jail-in-uk
https://therecord.media/scattered-spider-hackers-tfl-sentenced
https://www.helpnetsecurity.com/2026/07/16/ransport-for-london-cyberattack-prison-time

Comments