Two Scattered Spider Hackers Jailed for £39 Million TfL Cyber-Attack

Two members of the Scattered Spider hacking group were each sentenced to five and a half years in prison on July 16, 2026, for the September 2024 cyber-attack on Transport for London (TfL). The breach compromised the data of millions of commuters and cost the organisation an estimated £39 million.
Thalha Jubair, 20, and Owen Flowers, 19, were sentenced at the Old Bailey by Mr Justice Turner, who told the court the attack was "primarily motivated by selfish bravado, heedless of the severe consequences to others" (The Guardian). The pair had pleaded guilty in June 2026.
The attack, conducted between 31 August and 3 September 2024, saw the hackers gain the highest level of privileged access within TfL's IT infrastructure. They created what is known as a domain administrator account — essentially a master key that lets the holder move freely through an entire network and access any system connected to it. The court heard it described as the "keys to the kingdom." With that access, they exfiltrated (meaning they secretly copied and removed) data belonging to millions of commuters, searched TfL's customer database for celebrities, and forced 27,000 staff to reset their passwords. The disruption lasted months for the operator (BBC News). TfL commissioner Andy Lord described it as the worst incident he had faced in his career, and the organisation said the attack could have caused "catastrophic damage" leading to "significant and extended transport service degradation and disruption."
While the main tube and bus networks were not directly affected, the Dial-a-Ride service for disabled passengers was unable to process bookings during the incident. This is a useful illustration of how compromising the behind-the-scenes systems of an organisation can paralyse specialised services even when the core operations keep running.
Jubair and Flowers were key figures in Scattered Spider, a loose collective of English-speaking hackers suspected of numerous intrusions. Both were known to police years before the TfL attack (Yahoo News). They were arrested at their home addresses in September 2024 (BBC News). Jubair lived with his parents in a council flat in Bow, east London. Flowers lived with his grandmother and uncle in Walsall, West Midlands.
The investigation was conducted jointly by the National Crime Agency (NCA) and the City of London Police (NCA). The NCA stated that the convictions had effectively halted Scattered Spider's criminal activity. Flowers was also sentenced for hacking two US healthcare providers, in addition to the TfL offences.
The pair communicated via Telegram throughout the attack. Flowers recorded a livestream of the intrusion that Jubair broadcast, a detail that points to the performative culture within the collective. They had accrued millions of dollars in cryptocurrency through their hacking activities.
The £39 million cost figure, reported when the guilty pleas were entered in June 2026 (Sky News), covers remediation, staff password resets, system hardening (meaning strengthening systems against future attacks), and the prolonged operational disruption that followed the initial breach.
The broader context here raises several issues that security practitioners and policy makers have been tracking closely. The speed with which the attackers escalated from initial access to domain-level privilege within a major public-sector network raises pointed questions about identity and access management — the policies and tools that control who can log in to what — in critical infrastructure. That two teenagers, living with family and communicating over consumer messaging apps, were able to achieve what the court called the "keys to the kingdom" inside one of the world's largest transport authorities suggests the attack surface (the sum of all points where an attacker could attempt entry) of large public-sector organisations is poorly defended relative to the value of the data they hold. The fact that both perpetrators were known to police before the 2024 attack adds a further dimension: the challenge of disrupting cyber-criminal pathways before they escalate to high-impact targets.
The NCA's claim that these convictions have "effectively halted" Scattered Spider's activity warrants scrutiny. Loose collectives, by design, do not depend on any two individuals to continue operating. The structure that enabled Jubair and Flowers, with its Telegram channels, livestreamed intrusions, and cryptocurrency monetisation, is a methodology, not a membership roster. The precedent set by the five-and-a-half-year sentences may well deter, but the underlying tradecraft is widely shared. For critical infrastructure operators, the operational lesson is straightforward: assume the adversary is already inside, and invest in detection of lateral movement (an attacker shifting from one system to another within a network) and privilege escalation, not just perimeter defence.


