Two members of the Scattered Spider cybercrime collective have been sentenced for the 2024 cyberattack on Transport for London, in what the National Crime Agency describes as the largest cybercrime prosecution ever brought before a UK court. On 16 July 2026 at Woolwich Crown Court, Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from East London, were each sentenced to five years and six months in prison. The detail worth holding onto is not the sentence but the method: this attack, which cost £29 million to remediate, began with a bought password and a phone call.

What they were convicted of

Flowers and Jubair pleaded guilty on 22 June 2026 — the day their trial was due to begin, which earned them a 15 per cent reduction in sentence — to an offence under Section 3ZA of the Computer Misuse Act 1990. That is the Act's most serious provision, covering unauthorised acts that cause or create a significant risk of serious damage; the pair admitted the charge on the basis that they were reckless as to whether they created a significant risk of serious damage to human welfare. According to the NCA, it was only the second prosecution of its kind under the Act.

The impact figures come from the NCA and the Crown Prosecution Service. The intrusion ran from 31 August to 3 September 2024 and cost TfL £29 million to remedy — one outlet reported a higher recovery figure of nearly £40 million, but the £29 million total is the one the prosecuting authorities used. More than 140 internal systems were rendered inoperable, and all of TfL's roughly 27,000 employees had to reset their passwords in person. The attack did not stop London's tube or bus services, but it disrupted technical systems including Oyster payment accounts and third-party interfaces. The scale of data exposure was revised sharply over time, through public estimates that grew from an initial figure of around 5,000 affected individuals to several million passengers as forensic investigations progressed.

The method is the story

The court heard how the two gained access, and it is striking for how ordinary it was. There was no zero-day exploit and no bespoke nation-state malware. The pair obtained partial TfL employee credentials from criminal forums, then telephoned the organisation's IT helpdesk, impersonated an employee, and persuaded a helpdesk worker to reset account credentials through the organisation's identity-recovery process, allowing them to obtain authenticated access without exploiting a technical vulnerability. From that foothold they moved through the network over the following days, elevating their access to reach internal systems and databases.

That is deliberately described here at the level of the mechanism rather than as a procedure. The point for defenders is not how to do it but what it targets: the helpdesk, and the human judgement of the person answering the reset request. Scattered Spider has become particularly well known for using helpdesk-focused social-engineering techniques to defeat organisational identity controls, and the TfL case is the clearest possible demonstration that it works against a large, well-resourced organisation. The defensive response lives at the same layer: rigorous, un-bypassable identity verification for password and multi-factor resets, callback procedures, and helpdesk staff who are trained and empowered to refuse a plausible-sounding request.

The people behind it

The picture that emerged in court cut against the image of the sophisticated, untouchable hacker. Investigators recovered videos and screenshots that Flowers had recorded of the attack in progress, showing Jubair accessing TfL systems, and found the pair had coordinated over Telegram and a shared online workspace. When officers first came to Flowers' home days after the TfL attack, he was, by the CPS's account, in the middle of attacking two US healthcare organisations — SSM Health and Sutter Health — offences he later admitted. The sentencing judge, Mr Justice Turner, weighed the defendants' evident immaturity against the sophistication of the offending, the scale of the harm, and the significant planning involved, and noted the age gap between the two as a potentially meaningful difference in maturity.

Key Takeaways

  • Owen Flowers (18) and Thalha Jubair (20), Scattered Spider members, were each sentenced to 5 years 6 months on 16 July 2026 for the 2024 TfL attack — the UK's largest cybercrime prosecution, per the NCA.

  • They pleaded guilty under Section 3ZA of the Computer Misuse Act; the attack cost TfL £29 million (NCA/CPS figure), took down 140-plus systems and forced 27,000 staff to reset passwords in person.

  • The method was social engineering, not a technical exploit: bought credentials plus a call to the IT helpdesk to reset account credentials through the identity-recovery process.

  • The defensive lesson sits at the helpdesk — un-bypassable identity verification, callback procedures, and staff empowered to refuse plausible reset requests.

  • Data-exposure estimates grew over time from an initial ~5,000 to several million passengers as investigations progressed; the NCA says the action halted the group but concedes the brand may persist.