

On 16 July 2026, Woolwich Crown Court sentenced Owen Flowers, 18, and Thalha Jubair, 20, to five and a half years in prison each for their roles in the August-September 2024 attack on Transport for London, and for a series of intrusion and extortion attacks against organisations in the United States. Both had pleaded guilty on 22 June 2026. The prosecution is the first successful use of Section 3ZA of the Computer Misuse Act 1990, the provision that covers computer attacks with serious consequences, against members of the cybercriminal group known as Scattered Spider. The National Crime Agency assessed that the arrests had effectively halted the group's operations.
Scattered Spider, also tracked under the threat intelligence designations Octo Tempest, UNC3944, and 0ktapus, had by the time of the TfL attack in September 2024 conducted what prosecutors described as hundreds of intrusions between 2022 and 2025, earning it a reputation as one of the most aggressive and disruptive English-speaking cybercriminal groups of the era. Flowers and Jubair were described by prosecutors as leading members. The sentencing of two of its principals at ages 18 and 20 puts faces and consequences to a group whose operations had previously seemed difficult to attribute or prosecute.
Transport for London is the integrated transport authority responsible for most of London's public transport network, including the London Underground, buses, Overground, Elizabeth line, Dial-a-Ride, and the congestion charge system. The attack began on 31 August 2024 and ran through 3 September, a four-day window that left 148 systems inoperable. All 27,000 TfL employees were required to attend in-person password resets, a response measure that reflects the scale of the credential compromise and the confidence the IT team had in remote password reset procedures after the attack.
The operational consequences were substantial. The Dial-a-Ride booking service, which provides accessible transport for disabled Londoners who cannot use mainstream public transport, was disrupted. Digital payment systems were affected. Concessionary card issuance, which allows eligible passengers to apply for reduced-fare passes including Oyster cards, was halted. The personal data of TfL customers was also affected: the attack resulted in the compromise of names, email addresses, home addresses, and potentially the bank account details of approximately 5,000 people who had claimed Oyster refunds online, placing the financial data of thousands of members of the public at risk alongside the operational disruption to the transport network itself.
The financial damage to TfL was £29 million in losses and recovery costs. That figure covers the immediate operational costs of the disruption, the expense of the in-person password reset exercise for 27,000 employees, the remediation work to bring 148 systems back into operation, and the ongoing recovery and security improvement programme that followed. For a public authority funded by transport fares and government grants, £29 million represents a significant diversion of resources from the transport improvements and maintenance that the funding was intended for.
Scattered Spider's signature technique is social engineering of technical support and helpdesk staff, combined with credential harvesting pages that impersonate legitimate corporate single sign-on portals. The group's operators are native English speakers with detailed knowledge of US and UK corporate IT processes, which allows them to make convincing vishing calls to helpdesk staff in which they impersonate employees or contractors who need urgent assistance with account access. During these calls, they guide helpdesk staff through actions that hand over authentication credentials, MFA codes, or account resets that create or restore attacker-controlled access to corporate systems.
The credential harvesting component uses pages that precisely replicate the target organisation's single sign-on portal, including the correct logo, layout, and authentication flow. When a user is directed to one of these pages through a vishing call or a text message, they see what appears to be their familiar corporate login page. The credentials they enter are captured by the attacker's infrastructure and used immediately to authenticate to the real system, while the victim is shown an error or redirected to a legitimate page. This technique bypasses the technological security controls that most organisations focus their defences on because it operates through human action rather than software exploitation: the victim authenticates on a real device, from a real network, with their real credentials, and the multi-factor authentication that was supposed to protect them is the mechanism the attacker exploited by capturing the code in real time during the vishing call.
The sophistication of this social engineering approach, combined with the group's apparent awareness of corporate IT procedures in large US and UK organisations, distinguished Scattered Spider from less capable groups. The TfL attack's success in rendering 148 systems inoperable and requiring all-staff in-person password resets reflects both the initial access method's effectiveness and the group's ability to move quickly once inside the network to maximise impact before detection and containment.
The sentencing covered conduct beyond the TfL attack. Owen Flowers faced additional charges in the US related to conspiracy against SSM Health Care Corporation and an attempted attack on Sutter Health, both large US healthcare systems. Flowers was arrested on 6 September 2024, five days after the TfL attack ended, in what prosecutors described as a mid-attack arrest: he was in the process of attacking both healthcare systems when he was taken into custody.
The Telegram communications entered into evidence at the sentencing included a message from Flowers acknowledging that his actions against healthcare systems "might kill some 90-year-old on life support." This message, produced by prosecutors, provides a rare and stark documentary record of the psychological attitude of a threat actor toward the consequences of attacking critical healthcare infrastructure. Ransomware and extortion attacks against hospitals have caused patient deaths in documented cases in Germany and the United States, where the disruption of clinical systems during attacks delayed care for patients in critical conditions. The willingness to proceed with a healthcare attack after acknowledging this risk, even in Telegram communications that the perpetrators apparently did not expect to become evidence, speaks to the deliberate recklessness that characterises this class of attack.
Thalha Jubair's exposure across his full charge sheet is considerably larger than the TfL conviction alone. A complaint unsealed in New Jersey in September 2025 alleged that Jubair participated in approximately 120 network intrusions targeting 47 or more US victims between May 2022 and September 2025. The alleged ransoms paid to threat actors associated with the activity he participated in totalled more than $115 million. The maximum exposure across all counts in the US complaint is 95 years. The 5.5-year UK sentence is the immediate consequence of the TfL guilty plea; the US charges remain outstanding and will determine the longer-term legal exposure depending on how the US proceedings progress following the UK sentencing.
The scale of alleged activity attributed to Jubair between 2022 and 2025 illustrates the volume of attacks that a small number of highly capable social engineers can conduct when they have perfected their technique and operate without meaningful legal consequence for an extended period. 120 intrusions over three years is approximately one every nine days. The $115 million in alleged ransoms across those intrusions represents an average of roughly $960,000 per victim organisation that paid. These are not random, opportunistic attacks but targeted intrusions against organisations selected for their capacity to pay and their vulnerability to the social engineering techniques the group had refined.
The Flowers and Jubair prosecutions are the first successful use of Section 3ZA of the Computer Misuse Act 1990 in the UK. Section 3ZA was added to the Computer Misuse Act in 2015 specifically to address computer attacks that cause or create a significant risk of serious damage to human welfare, the economy, the environment, or national security. The provision carries a maximum sentence of life imprisonment for the most serious cases, and up to 14 years for cases where a significant risk of serious damage was created. The TfL attack's scale, the disruption to a critical infrastructure provider serving millions of Londoners, and the compromise of personal and financial data for thousands of customers provided the factual basis for prosecution under a provision that had not previously been successfully applied.
The first application of Section 3ZA in a concluded prosecution establishes a precedent for how future UK prosecutions of large-scale cyberattacks against public infrastructure will be framed. The Crown Prosecution Service's successful use of the provision signals that attacks against transport, healthcare, and other systems providing essential services to the public will be treated as qualitatively different from computer fraud targeting private financial systems, even when the immediate technical mechanism is similar. The 5.5-year sentences in a case where life imprisonment was the theoretical maximum also establish a data point for how sentences under Section 3ZA are calibrated in practice against the specific harm caused and the ages and circumstances of the defendants.
The National Crime Agency's assessment that the arrests had "effectively halted" Scattered Spider's operations deserves some scrutiny as a claim about a decentralised criminal group. Scattered Spider has never been a formally organised criminal enterprise in the traditional sense: it is a loose network of individuals who communicate through online communities and collaborate on specific operations. The arrest and imprisonment of two identified leading members removes known capabilities from the group, but it does not necessarily mean that all individuals who participated in Scattered Spider operations, or who learned the social engineering and credential harvesting techniques the group developed, have ceased their activities.
The history of other cybercriminal communities suggests that the arrest of prominent members disrupts operations significantly in the short term but that the underlying techniques and knowledge dispersed through the community do not disappear. The social engineering tradecraft that Scattered Spider developed, specifically the use of vishing calls combined with victim-branded SSO phishing pages and real-time MFA interception, has been documented publicly through incident reports, security research, and the extensive media coverage of the group's activities. Organisations that adjusted their defences against phishing in response to Scattered Spider's known tactics should maintain those defences regardless of the NCA's assessment of the group's current operational status.
The primary defensive lesson from Scattered Spider's operational approach is that technical authentication controls, including MFA, can be bypassed when the attack is executed through social engineering of human processes rather than technical exploitation of software. The standard configuration of SMS-based or time-based one-time password MFA, which most organisations rely on, provides a code that is valid for 30 to 60 seconds. An attacker conducting a vishing call in real time can capture the code as the victim reads it aloud and use it within that window. FIDO2 hardware security keys resist this attack because they bind the authentication credential to the specific domain being authenticated to, making the hardware token's response useless for a different site even if the code is captured.
Beyond authentication technology, the Scattered Spider case highlights the importance of helpdesk verification procedures as a security control. An attacker who can convince a helpdesk operator to reset an account, enrol a new MFA device, or provide temporary access bypass has achieved the equivalent of a technical vulnerability exploitation without touching any software. Procedures that require out-of-band verification for account changes affecting senior employees, executives, or accounts with privileged access, and that train helpdesk staff to recognise and escalate social engineering attempts that create unusual urgency, are controls that address the attack surface that Scattered Spider exploited most effectively. The human element of security is never solved by technical controls alone, and the TfL attack is a precise illustration of what that means in practice.
The evidence presented at the Woolwich Crown Court sentencing included digital artefacts that illustrate the forensic trail that sophisticated social engineering attacks leave despite their human-operated nature. Screenshots of TfL network connections, specifically images showing Jubair moving through TfL systems, were entered into evidence. Telegram communications between the perpetrators discussing the attack, its progress, and its consequences were recovered and presented. Physical evidence in the form of laptops, computers, hard drives, and USB sticks was seized in the arrests, with forensic analysis connecting these devices to the attack activity. Remote server connections traced to all three intrusion sites linked the defendants' activity to the TfL network and to the two US healthcare targets.
The Telegram communications are particularly significant as evidence. End-to-end encrypted messaging has long been promoted as investigation-resistant, and criminal groups routinely use platforms like Telegram, Signal, and Discord for operational communications precisely because of this perception. The Flowers case, where Telegram messages including the "might kill some 90-year-old on life support" statement became courtroom evidence, is a reminder that device seizure during or immediately after an attack can recover communications that the perpetrators believed were private. Both Flowers' arrest on 6 September 2024, described as a mid-attack arrest, and the subsequent seizure of devices under UK and US legal authority provided the forensic access that made the communications recoverable.
The Scattered Spider investigation reflects the multi-agency, cross-border cooperation that major cybercrime prosecutions now require. The National Crime Agency led the UK investigation into the TfL attack. The City of London Police and the Crown Prosecution Service supported the UK prosecution. The FBI and the US Department of Justice were involved in parallel US investigations, with the New Jersey complaint against Jubair unsealed in September 2025 representing the US dimension of the case against him specifically. The coordination between UK and US law enforcement on shared targets, combined with the exchange of evidence across jurisdictions, was the mechanism that allowed charges in both countries to proceed against the same individuals.
The NCA's assessment that the arrests "effectively halted" Scattered Spider's operations reflects the impact of removing the group's identified leading members, but the multi-jurisdictional charges that Jubair faces illustrate how complex the full legal reckoning will be. The 5.5-year UK sentence is one part of a larger legal picture. If Jubair is extradited to the US following the UK sentence, or if US charges are pursued through other mechanisms, his full legal exposure across 120 alleged network intrusions and $115 million in alleged ransoms could extend far beyond the UK sentence. The Flowers case has similar US exposure from the healthcare conspiracy charges, though Flowers was arrested in the UK and the immediate legal consequence is the UK sentence.
The TfL attack's success despite TfL's presumably substantial IT security resources underlines a fundamental challenge in enterprise identity security: the humans who operate helpdesks and manage IT support are part of the attack surface in a way that technical security controls cannot fully address on their own. Scattered Spider's operators were able to convince TfL IT staff to take actions that granted the attackers access through a combination of social pressure, convincing impersonation, and exploitation of the procedural expectations that helpdesk staff operate within.
The specific defences that address this attack surface are not primarily technical. They include helpdesk verification procedures that require out-of-band confirmation for account changes affecting accounts with sensitive access, particularly verification that cannot be conducted by calling a phone number the requestor provides. They include training that specifically covers social engineering over the phone, helping helpdesk staff recognise the emotional and procedural pressure tactics that vishing attacks employ. And they include detection controls that flag unusual account activity, such as a new MFA device being added to a privileged account from an unrecognised device or location, as events requiring security review rather than routine IT action.
The Scattered Spider prosecution also highlights the value of threat intelligence that specifically covers the TTPs of English-speaking cybercriminal groups targeting UK and US organisations. The vishing and credential harvesting techniques that Scattered Spider used were documented in multiple security advisories before the TfL attack. Organisations that had specifically adapted their helpdesk procedures and MFA policies in response to those advisories were better positioned than those that treated them as abstract risks rather than specific operational threats. The TfL attack is a case where advance intelligence was available and where the question is whether it was acted on with sufficient specificity to matter.
Vulnerabilities like CVE-2026-58644 are valuable to attackers not only for the immediate code execution they enable but for what comes after: credentials extracted from the compromised server, session tokens harvested from SharePoint's authentication layer, and sensitive documents accessed before remediation closes the window. These materials find their way into dark web markets, stealer logs shared on criminal forums, and initial access broker listings where the next buyer in the chain is already waiting.
Defendis monitors these channels in real time. If credentials or data linked to your organisation surface following an on-premises server compromise, Defendis surfaces the exposure with full context: the individual affected, the data exposed, and how the compromise likely unfolded. That context lets your team respond to the specific confirmed risk rather than running a broad, unfocused investigation from scratch.
Book a demo to see how Defendis approaches dark web monitoring for enterprise security teams.