Skip to main content
Meet us at Black Hat USA 2026— Las Vegas, August 1–6Book a Meeting
Mallory
Back to intelligence
operational-disruptioncybercrime-service-ecosystemcritical-infrastructure-threatmass-credential-exposure

Scattered Spider-Linked Pair Plead Guilty in Transport for London Cyberattack

Updated 19h agoFirst seen Jun 23, 202616 sources

Two men, Thalha Jubair and Owen Flowers, pleaded guilty under the UK Computer Misuse Act for their roles in the 2024 cyberattack on Transport for London (TfL), an intrusion investigators linked to the Scattered Spider cybercrime ecosystem. Authorities said the attackers accessed TfL’s network between 31 August and 3 September 2024, disrupting Oyster refund processing, temporarily affecting children’s and young people’s photocard applications, and forcing all 28,000 employees to reset passwords in person after trust in internal identity systems was lost. The breach is reported to have affected about 10 million customers and caused losses and recovery costs estimated between £29 million and £39 million.

The National Crime Agency, City of London Police, British Transport Police, and regional officers said a lengthy investigation produced digital evidence including screenshots showing connectivity to TfL infrastructure, videos of system access during the intrusion, Telegram communications, and activity on an online collaboration platform. Investigators also alleged that Flowers was linked to intrusions involving U.S. healthcare organizations including SSM Health and Sutter Health. Both defendants remain in custody and are due to be sentenced in July 2026, as officials cite the case as a warning about the operational impact of cyberattacks on critical infrastructure and the growing role of young, English-speaking offenders in serious cybercrime.

Share:
Scattered Spider-Linked Pair Plead Guilty in Transport for London Cyberattack
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

7 events from the most recent confirmed update back to the earliest known activity.

7 EVENTS
Jul 15, 2026just now

Sentencing dates set for the two defendants

The defendants were scheduled for sentencing in July 2026, with reporting citing hearings on 15 and 16 July 2026. One source summarized the sentencing as set for July 16.

2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack
Jun 23, 20264d ago

Investigators arrested suspects and seized digital evidence

In 2025, National Crime Agency and City of London Police investigators arrested the suspects in connection with the TfL intrusion. Authorities said they seized devices and recovered evidence including screenshots of TfL access, videos of system access, and Telegram and collaboration-platform communications.

2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack

Jubair and Flowers pleaded guilty over TfL cyberattack

Two young men, Thalha Jubair and Owen Flowers, pleaded guilty in London under the UK Computer Misuse Act for their roles in the 2024 cyberattack on Transport for London. Authorities linked them to the Scattered Spider ecosystem and said the attack affected millions of customers and caused major financial losses.

Duo accused of role in TfL cyber attack plead guilty after ‘lengthy, highly complex, and painstaking investigation’ | IT Pro
Jun 22, 20265d ago

Two men changed pleas to guilty before trial

Shortly before their trials were due to begin, Thalha Jubair and Owen Flowers reportedly changed their pleas to guilty over offenses tied to the TfL cyberattack. Reporting said the case concerned a major incident that caused months of disruption and tens of millions of pounds in losses.

Two men, believed to part of Scattered Spiders, plead guilty over £39m TfL cyber attack - Malware News - Malware Analysis, News and Indicators
Sep 16, 20242y ago

NCA and City of London Police arrested two TfL cyberattack suspects

The National Crime Agency said two men were arrested at their home addresses on 16 September 2024 in a joint investigation with the City of London Police into the TfL cyberattack. Investigators seized multiple digital devices, including a laptop with a screenshot showing connectivity to TfL infrastructure, videos appearing to show access to TfL systems, and evidence of Telegram and collaborative-workspace communications.

Two men plead guilty over £39m Transport for London cyber attack
Sep 3, 20242y ago

Investigators linked seized evidence to intrusions at two US healthcare firms

The National Crime Agency said evidence recovered during Owen Flowers’ arrest indicated intrusions affecting SSM Health Care Corporation and Sutter Health in the United States. This introduced two additional victim organizations beyond Transport for London.

Cyber criminals who hacked into Transport for London's computer network are convicted - National Crime Agency
Aug 31, 20242y ago

Attackers breached TfL systems over four days

Transport for London's network was intruded between 31 August and 3 September 2024. The breach disrupted Oyster refund processing and related customer services and ultimately forced all 28,000 employees to reset passwords in person.

2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack
LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

42 LINKEDOpen in app
Threat actors
1 linked
Affected products
3 linked
TelegramSignalDoordash
Organizations
31 linked
Sutter HealthTransport for LondonSSM Health Care CorporationSSM HealthMGM Resorts InternationalMarks & SpencerCaesars EntertainmentCo-opDoordashHarrodsTelegramMailchimpAcerT-Mobile USLastPassPlexSignal MessengerAmerican AirlinesPalo Alto NetworksSnowflakeWestJetJaguar Land RoverPicus SecurityHawaiian AirlinesTwilioMicrosoft CorporationAflacSlack TechnologiesKrebsOnSecurityEnterprise TimesSSM Health Care
Breaches
7 linked
TRANSPORTFORLONDON-2024-08TRANSPORTFORLONDON-2024-09TRANSPORTFORLONDON-2026-06TRANSPORTFORLONDON-2024-06SSMHEALTHCARECORPORATION-2026-06SUTTERHEALTH-2024-09SSMHEALTHCARECORPORATION-2024-09
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.

Scattered Spider-Linked Pair Plead Guilty in Transport for London Cyberattack | Mallory