Scattered Spider Hackers Jailed 5.5 Years Each for £29M TfL Cyberattack
Owen Flowers, 18, and Thalha Jubair, 20, members of the Scattered Spider cybercrime group, were each sentenced to five and a half years at Woolwich Crown Court on 16 July 2026 for the August 2024 hack of Transport for London. Prosecutors valued the damage and recovery costs at £29 million, while the NCA estimated that a full shutdown of the TfL network could have cost the UK economy up to £56 billion. Both defendants pleaded guilty to Section 3ZA of the Computer Misuse Act 1990 on 22 June 2026, the day their trial was due to begin, making them the first hackers successfully prosecuted under the statute's most serious provision.
The four-day intrusion, which ran from 31 August to 3 September 2024, knocked 148 TfL systems offline and forced the authority's entire 27,000-person workforce to appear in person for password resets. Critical services including Dial-a-Ride, digital payments, concessionary travel card issuance, and Oyster photocard applications all went down, while contactless ticketing rollouts and refunds were delayed during a period when TfL handles an average of 9 million journeys daily. The attackers also exfiltrated customer data, including names, email addresses, home addresses, and Oyster refund records containing bank account numbers and sort codes for approximately 5,000 people — a breach that anyone affected can evaluate with an email breach checker.
Flowers was arrested at home on 6 September 2024 while NCA officers discovered him actively attacking two US healthcare organizations, SSM Health Care Corporation and Sutter Health. Investigators seized laptops, tower computers, hard drives, and USB sticks, one of which contained a screenshot showing network connectivity to TfL infrastructure alongside video evidence of Jubair navigating TfL systems during the attack. The pair coordinated through Telegram and shared an online workspace throughout the operation, though prosecutors noted that only the two defendants knew their full intent, with chat logs suggesting they planned to wipe their access on exit.
TfL's swift decision to pull its own network offline contained the incident before the attackers could escalate further, a containment move the CPS credited with keeping the worst-case scenario hypothetical. The case underlines both the regulatory weight now applied to large-scale intrusions against critical national infrastructure and the persistent risk that compromised credentials pose to enterprise systems — a reminder that employees should routinely verify credential strength using a password checker and that exposed network endpoints should be audited through a port scanner to reduce the attack surface available to groups like Scattered Spider.