HackMyIP
← Back to News
2026-06-23 KrebsOnSecurity

Scattered Spider Members Plead Guilty in Transport for London Cyberattack

RansomwarePhishingAuthentication

Two key members of the prolific cybercrime group Scattered Spider pleaded guilty on the opening day of their six-week trial at a UK court. Thalha Jubair, 20, of East London, and 18-year-old Owen Flowers of Walsall admitted to conspiring to commit unauthorized acts against Transport for London (TfL) computer systems and causing risk of serious damage to human welfare following the August 2024 cyberattack that crippled the capital's public transport network. Flowers additionally admitted to participating in a conspiracy to hack US-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.

The guilty pleas come amid heightened scrutiny from US law enforcement. In September 2025, prosecutors in New Jersey unsealed an indictment alleging Jubair and other Scattered Spider members committed computer fraud, wire fraud, and money laundering across 120 computer network intrusions involving 47 US entities between May 2022 and September 2025, with victims paying at least $115 million in ransom payments. The duo were also arrested in connection with Scattered Spider ransomware attacks against UK retailers Marks & Spencer, Harrods, and Co-op Group, and Flowers is believed to be the member who gave anonymous media interviews following the September 2023 ransomware disruptions at MGM Resorts and Caesars Entertainment in Las Vegas.

According to prosecutors, Jubair co-ran a Telegram channel called Star Chat that served as the hub for a SIM-swapping group using voice- and SMS-based phishing attacks to steal credentials from employees at major US and UK wireless providers. The group exploited this access to sell phone number redirection services, enabling attackers to intercept calls, text messages, and one-time passcodes used for multi-factor authentication. Security teams can audit their exposure to credential-based attacks using a password checker to identify compromised credentials before attackers can weaponize them.

Jubair was also linked to a summer 2022 mass SMS phishing campaign that harvested single sign-on credentials from employees at hundreds of companies. The operation led to intrusions and data thefts at more than 130 organizations, including LastPass, DoorDash, Mailchimp, Plex, and Signal. Given the scale of these breaches, individuals can verify whether their personal data has been exposed using an email breach checker and strengthen their defenses with a privacy checkup to limit the attack surface available to threat actors.

Source: KrebsOnSecurity →

Related Tools

Check whether this kind of story affects you — free, no signup:

Email Breach Check →Privacy Checkup →

Related Guides

Learn the background behind this story:

What is a data breach? →Credential stuffing attacks →How to check for an email breach →