Two UK men linked to Scattered Spider, Thalha Jubair and Owen Flowers, were jailed after admitting their roles in the 2024 cyberattack on Transport for London (TfL), a breach prosecutors said gave them the highest privileged access in TfL’s environment. Investigators said the intrusion began when a co-conspirator socially engineered the TfL help desk into resetting authentication to a device controlled by the attackers, allowing them to create a domain administrator account and move through 148 systems. Authorities said the attackers stole data relating to about 7 million people and accessed information from TfL’s Oyster refunds system.
The breach disrupted customer-facing services including Dial-a-Ride, concessionary travel cards, digital payments and Oyster-related systems, and forced 27,000 employees to reset passwords in person while TfL shut systems down to contain the attack. Prosecutors said the hackers could have caused catastrophic disruption across London’s transport network; the incident ultimately cost TfL tens of millions of pounds, with reported losses and recovery costs ranging from £29 million to £39 million. Jubair received five and a half years in prison, while Flowers received five and a half years for the TfL attack alongside additional hacking offences involving two US healthcare providers; the National Crime Agency said the convictions significantly degraded Scattered Spider’s operations.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Thalha Jubair and Owen Flowers were sentenced to five years and six months in prison for the 2024 cyberattack on Transport for London. UK authorities described them as leading members of Scattered Spider and said the case was the UK's largest cybercrime prosecution, with the arrests and convictions materially degrading the group's operations.
In June, Thalha Jubair and Owen Flowers pleaded guilty over the TfL cyberattack. The Guardian reports the plea preceded sentencing for the intrusion and related offenses.
On 2024-09-16, the City of London Police and the UK National Crime Agency arrested Thalha Jubair and Owen Flowers in connection with the 2024 Transport for London cyberattack. The arrest marked a distinct law-enforcement action preceding their later guilty pleas and sentencing.
During the 2024 intrusion, TfL shut systems down to contain the breach, public-facing services were disrupted, and all 27,000 staff had to reset passwords in person. Authorities said 148 systems were affected and data from about 7 million people, including Oyster refunds data, was exposed.
Between 2024-08-31 and 2024-09-03, attackers linked to Scattered Spider gained highly privileged access to Transport for London after a co-conspirator allegedly tricked the TfL help desk into resetting authentication to an attacker-controlled device. Prosecutors said they created a domain administrator account and reached the core of TfL's environment.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
18 references tracked. Mallory keeps watching after this page renders.
cyberveille.ch
Open sourcecyberscoop.com
Open sourcecybersecuritynews.com
Open sourcecysecurity.news
Open sourcetechcrunch.com
Open sourcelinkedin.com
Open sourcenationalcrimeagency.gov.uk
Open sourcejustice.gov
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.