World

Two Young Hackers Jailed for Crippling London's Transport Network

Elena MarquezPublished 3w ago4 min readBased on 7 sources
Reading level
Two Young Hackers Jailed for Crippling London's Transport Network

Two hackers were each sentenced to five and a half years in prison on July 16, 2026, for a cyber-attack on Transport for London (TfL) that stole the personal data of millions of commuters and cost the organisation an estimated £39 million.

Thalha Jubair, 20, and Owen Flowers, 19, were sentenced at the Old Bailey, London's central criminal court. Mr Justice Turner told the court the attack was "primarily motivated by selfish bravado, heedless of the severe consequences to others" (The Guardian). The pair had pleaded guilty in June 2026.

The attack took place between 31 August and 3 September 2024. The hackers managed to get the highest possible level of access to TfL's computer systems. Think of it like getting a master key that opens every door in a building. The court heard it described as the "keys to the kingdom." With that access, they copied and stole data belonging to millions of commuters, searched TfL's customer database for celebrities, and forced 27,000 staff members to reset their passwords. The disruption lasted months (BBC News). TfL commissioner Andy Lord called it the worst incident he had faced in his career, and the organisation said the attack could have caused "catastrophic damage" leading to "significant and extended transport service degradation and disruption."

The main tube and bus networks were not directly affected. But the Dial-a-Ride service, which provides transport for disabled passengers, could not process bookings during the incident. This shows how attacking an organisation's behind-the-scenes computer systems can shut down specific services even when the main operations keep running.

Jubair and Flowers were key figures in Scattered Spider, a loose group of English-speaking hackers suspected of carrying out many break-ins. Both were known to police years before the TfL attack (Yahoo News). They were arrested at their home addresses in September 2024 (BBC News). Jubair lived with his parents in a council flat in Bow, east London. Flowers lived with his grandmother and uncle in Walsall, West Midlands.

The investigation was carried out jointly by the National Crime Agency (NCA) and the City of London Police (NCA). The NCA stated that the convictions had effectively halted Scattered Spider's criminal activity. Flowers was also sentenced for hacking two US healthcare providers, in addition to the TfL offences.

The pair communicated via the messaging app Telegram throughout the attack. Flowers recorded a livestream of the break-in that Jubair broadcast, a detail that points to the show-off culture within the group. They had earned millions of dollars in cryptocurrency through their hacking activities.

The £39 million cost figure, reported when the guilty pleas were entered in June 2026 (Sky News), covers fixing the damage, resetting staff passwords, strengthening systems against future attacks, and the long-running disruption that followed the initial break-in.

The broader context here raises questions that cybersecurity experts and policymakers have been watching closely. Two teenagers, living with family and chatting on an everyday messaging app, managed to get the "keys to the kingdom" inside one of the world's largest transport authorities. That suggests large public-sector organisations are still not defending their systems well enough, especially given how valuable the data they hold is. The fact that both hackers were already known to police before the 2024 attack adds another concern: the difficulty of stopping cyber-criminals before they go after major targets.

The NCA's claim that these convictions have "effectively halted" Scattered Spider's activity is worth questioning. Loose groups like this do not depend on any two people to keep going. The methods they used, with their Telegram channels, livestreamed break-ins, and cryptocurrency profits, are a playbook that is widely shared. The five-and-a-half-year sentences may discourage others, but the techniques are out there. For organisations running critical services, the lesson is clear: assume attackers may already be inside your systems, and focus on catching them as they move around, not just on keeping them out in the first place.