Visualização normal

Antes de ontemStream principal
  • ✇Security Affairs
  • Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack Pierluigi Paganini
    Two members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London. A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transport for London (TfL). Transport for London (TfL) is a local government body responsible for most of the transport network in London, United Kingdom. The attack disrupted transport services, including Dial-a-
     

Two Scattered Spider Members Sentenced to Prison Over £29 Million TfL Cyberattack

16 de Julho de 2026, 14:34

Two members of the Scattered Spider cybercrime group received jail sentences in the UK for the 2024 cyberattack on Transport for London.

A UK court sentenced two Scattered Spider members, Thalha Jubair (20) and Owen Flowers (18), for their role in the 2024 cyberattack on Transport for London (TfL). Transport for London (TfL) is a local government body responsible for most of the transport network in London, United Kingdom.

The attack disrupted transport services, including Dial-a-Ride for vulnerable passengers, concessionary travel cards, digital payments, and the rollout of contactless ticketing. The attack also exposed customer data from the Oyster refunds system and delayed customer refunds and travel card applications.

All 27,000 employees had to reset their passwords, while 148 systems went offline, forcing staff to rely on manual processes.

The incident cost TfL an estimated £29 million ($39 million); however, the NCA reported that a complete shutdown could have caused up to £56 billion in economic damage.

The case marks another law enforcement success against one of the most active cybercrime groups targeting major organizations.

TfL estimates the attack cost £29 million, while a complete shutdown could have caused up to £56 billion in economic damage.

In September 2025, the National Crime Agency (NCA) arrested the two teenagers at their home addresses.

The law enforcement first arrested Flowers for the TfL attack, and investigators found evidence linking him to intrusions against U.S. healthcare providers SSM Health Care Corporation and Sutter Health. Authorities seized laptops, hard drives and USB devices, including one containing a screenshot of TfL network access.

Investigators also found videos showing Jubair accessing TfL systems during the attack while the two exchanged messages on Telegram and collaborated through an online workspace. Flowers was later arrested for breaching bail conditions, while Jubair faced additional charges for refusing to provide device passwords.

Both were charged with conspiring together to commit unauthorised acts against TfL, under the Computer Misuse Act.

“They both pleaded guilty to the attack last month in what was only the second criminal prosecution of its kind in the UK under the Computer Misuse Act (CMA).” reads the press release published by the NCA. “Section 3ZA of the CMA is the most serious section as it applies where the unauthorised act causes or creates a significant risk of serious damage, and the person intends or is reckless as to that damage.”

They were each sentenced to five years and six months in prison in what UK authorities described as the country’s largest cybercrime prosecution to date.

Although hackers continued using the Scattered Spider name into early 2026, UK authorities say the arrests of Jubair and Flowers effectively dismantled the group’s core operations. Microsoft also assessed that the arrests significantly reduced the group’s ability to carry out cyberattacks.

“Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity.” states NCA. “Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group’s ability to continue conducting cybercriminal operations.”

In July, Peter Stokes, 19, an alleged Scattered Spider member known online as “Bouquet,” was extradited from Finland to the U.S. to face hacking, fraud, and extortion charges. Prosecutors say he took part in multiple cyberattacks, including a 2025 breach of a luxury jewelry retailer where attackers allegedly stole data and demanded about $8 million in cryptocurrency.

“Among other offenses, the complaint alleges that Stokes and other co-conspirators breached a luxury jewelry retailer’s computer system, exfiltrated data from the company, and made a ransom demand of approximately $8 million in cryptocurrency in May 2025.” reads the press release published by DoJ. “The retailer’s security personnel successfully evicted the threat actors from the company’s computer network and no ransom was paid. The retailer nonetheless suffered a loss of at least $2 million due to business disruption, investigation, and mitigation of the threat.”

He was arrested in Finland in April on an Interpol Red Notice.

U.S. officials said Scattered Spider (aka Octo TempestUNC3944, and 0ktapus) has caused major disruption by targeting American companies, stealing data, encrypting systems, and demanding cryptocurrency payments. The FBI warned that the group has cost businesses millions of dollars and disrupted critical operations. Authorities pledged to continue working with international partners to identify, disrupt, and prosecute members of the group, regardless of where they operate.

The cybercrime group is suspected of hacking into hundreds of organizations over the past two years, including TwilioLastPassDoorDash, and Mailchimp.

Scattered Spider members are part of a broader cybercriminal community called “The Com,” where hackers brag about high-profile cyber thefts, typically initiated through social engineering tactics like phone, email, or SMS scams to gain access to corporate networks.

In April 2026, Tyler Buchanan, a 24-year-old from Scotland, also linked to the Scattered Spider group, admitted in a US court that he hacked dozens of companies, committed fraud, and stole millions in cryptocurrency. Spanish police arrested the British national in Palma de Mallorca while attempting to fly to Italy. During the arrest, police confiscated a laptop and a mobile phone. The arrest resulted from a joint operation conducted by the U.S. Federal Bureau of Investigation (FBI) and the Spanish Police.

In April 2025, Noah Urban, 20, linked to Scattered Spider (UNC3944), pleaded guilty in Florida and California to conspiracy, wire fraud, and identity theft. He admitted involvement in phishing and fraud operations, including stealing at least $800,000 in crypto from victims between Aug 2022 and Mar 2023. He also helped export stolen data and run multi-state cybercrime activities tied to the group.

In November 2025, two British teenagers, Thalha Jubair (19) and Owen Flowers (18), accused of links to Scattered Spider, pleaded not guilty in Southwark Crown Court to charges under the Computer Misuse Act. They are alleged to have conspired in a cyberattack against Transport for London (TfL) in 2024. Both were arrested in September by the NCA and formally denied the accusations in court.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, cybercrime)

‘Keys to the kingdom’: hackers who gained access to heart of London transport network jailed

Thalha Jubair, 20, and Owen Flowers, 19, sentenced to five and a half years each for cyber-attack that cost Transport for London £39m

The data of millions of commuters was stolen, Londoners were left out of pocket and 27,000 Transport for London staff were forced to reset their passwords.

Over four days in 2024 a pair of teenage hackers had London’s transport network at their mercy. Thalha Jubair and Owen Flowers had burrowed into the heart of Transport for London’s IT systems and held the “keys to the kingdom”.

Continue reading...

© Photograph: William Barton/Alamy

© Photograph: William Barton/Alamy

© Photograph: William Barton/Alamy

  • ✇Krebs on Security
  • Scattered Spider Hackers Plead Guilty on Day 1 of Trial BrianKrebs
    Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial. Owen Flowers (left) 18, and Thalha Jubair, 20. Image: UK National Crime Agency (NCA). Thalh
     

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

23 de Junho de 2026, 13:12

Two men pleaded guilty in the United Kingdom this week to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London, the entity responsible for the public transport network in the Greater London area. The duo were key members of a prolific cybercrime group known as Scattered Spider, and their guilty pleas came on the first day of what was expected to be a six-week trial.

Owen Flowers (left) 18, and Thalha Jubair, 20. Image: UK National Crime Agency (NCA).

Thalha Jubair, 20, of East London and 18-year-old Owen Flowers of Walsall admitted conspiring to commit unauthorized acts against Transport for London computer systems and causing risk of serious damage to human welfare. According to a report from the BBC, Flowers alone admitted to being part of a conspiracy to hack into U.S. based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.

Jubair is also wanted by U.S. law enforcement agencies. In September 2025, prosecutors in New Jersey unsealed an indictment alleging Jubair and other Scattered Spider members committed computer fraud, wire fraud, and money laundering in relation to 120 computer network intrusions involving 47 U.S. entities between May 2022 and September 2025, and that the group’s victims paid at least $115 million in ransom payments.

In July 2025, KrebsOnSecurity reported that Flowers and Jubair were arrested in the United Kingdom in connection with Scattered Spider ransom attacks against the retailers Marks & Spencer and Harrods, and the British food retailer Co-op Group. Multiple sources familiar with those investigations said Flowers was the Scattered Spider member who anonymously gave interviews to the media in the days after the group’s September 2023 ransomware attacks disrupted operations at Las Vegas casinos operated by MGM Resorts and Caesars Entertainment.

According to prosecutors, Jubair co-ran a bustling Telegram channel called Star Chat, the home of a SIM-swapping group that used voice- and SMS-based phishing attacks to steal credentials from employees at the major wireless providers in the U.S. and U.K. The group would then use that access to sell a service that could redirect a target’s phone number to a device the attackers controlled and intercept the victim’s calls and text messages (including one-time codes for multi-factor authentication).

A receipt from Star Fraud Chat’s SIM-swapping service targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools. “Rocket Ace” was one of Jubair’s hacker handles, according to U.S. prosecutors.

New Jersey prosecutors also allege Jubair also was involved in a mass SMS phishing campaign during the summer of 2022 that stole single sign-on credentials from employees at hundreds of companies. That weeks-long SMS phishing campaign led to intrusions and data thefts at more than 130 organizations, including LastPassDoorDashMailchimpPlex and Signal.

KrebsOnSecurity reported last year that one of Jubair’s alter egos at age 15 was “Everlynn,” a hacker who sold fraudulent “emergency data requests” that used compromised police and government email addresses to demand subscriber data (e.g. username, IP/email address) from major tech companies, claiming the requests concerned urgent matters of life and death and could not wait for a court order.

In April 2026, 24-year-old British national and Scattered Spider member Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for participating in the group’s SMS phishing spree in the summer of 2022. The government said Buchanan, Jubair and others used the credentials harvested in that phishing campaign to steal at least $8 million in cryptocurrency from victims throughout the United States. Buchanan is currently scheduled to be sentenced on October 2.

In August 2025, 20-year-old Scattered Spider member from Florida named Noah Michael Urban was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution, after pleading guilty to charges of wire fraud and conspiracy.

The U.S. Department of Justice says three alleged Scattered Spider defendants indicted along with Buchanan still face charges, including Ahmed Hossam Eldin Elbadawy, 24, a.k.a. “AD,” of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, a.k.a. “joeleoli,” of Jacksonville, North Carolina.

Flowers and Jubair are slated to be sentenced in a London court on July 15, 2026.

2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack

Two teenagers face sentencing after admitting to a massive Scattered Spider cyberattack that hit Transport for London (TfL) and US healthcare networks.

London councils enact emergency plans after three hit by cyber-attack

Kensington and Westminster councils investigating whether data has been compromised as Hammersmith and Fulham also reports hack

Three London councils have reported a cyber-attack, prompting the rollout of emergency plans and the involvement of the National Crime Agency (NCA) as they investigate whether any data has been compromised.

The Royal Borough of Kensington and Chelsea (RBKC), and Westminster city council, which share some IT infrastructure, said a number of systems had been affected across both authorities, including phone lines. The councils shut down several computerised systems as a precaution to limit further possible damage.

Continue reading...

© Photograph: Artur Marciniec/Alamy

© Photograph: Artur Marciniec/Alamy

© Photograph: Artur Marciniec/Alamy

Hackers reportedly steal pictures of 8,000 children from Kido nursery chain

Firm, which has 18 sites around London and more in US, India and China, has received ransom demand, say reports

The names, pictures and addresses of about 8,000 children have reportedly been stolen from the Kido nursery chain by a gang of cybercriminals.

The criminals have demanded a ransom from the company – which has 18 sites around London, with more in the US, India and China – according to the BBC.

Continue reading...

© Photograph: solarseven/Getty Images/iStockphoto

© Photograph: solarseven/Getty Images/iStockphoto

© Photograph: solarseven/Getty Images/iStockphoto

❌
❌