Scattered Spider Members Plead Guilty to Hacking Transport for London

Two members of the Scattered Spider gang pleaded guilty to the 2024 Transport for London hack, which disrupted TfL services and caused about £29 million in damages. Thalha Jubair, 20, and Owen Flowers, 18, had initially denied involvement but changed their pleas on the first day of their Woolwich Crown Court trial. The Aug. 31–Sept. 3, 2024 breach hit TfL’s systems, including Oyster refunds data, and led to data theft. The suspects were arrested in Sept. 2025; sentencing was moved to July 16 after the guilty pleas.

TechLogHub
June 23, 2026
4 min read
0 views

Share Article

Scattered Spider Members Plead Guilty to Hacking Transport for London

Scattered Spider Members Plead Guilty to TfL Hack

OverviewTwo members of the Scattered Spider cybercrime group have pleaded guilty to hacking the Transport for London (TfL) systems, marking a significant development in a case that disrupted one of the world’s busiest urban transport networks. The breach occurred in late August and early September of 2024, with investigations continuing for more than a year and leading to arrests in 2025 and a court ruling in 2026.

The Incident and Its Scope

  • TfL, the public body responsible for most of London’s transport infrastructure, faced a cybersecurity incident that began on August 31, 2024 and intensified on September 2–3, 2024.
  • The intrusion disrupted day-to-day operations and caused widespread delays, affecting thousands of journeys and the wider functioning of the city’s transport network.
  • Attackers gained access to data held within TfL’s Oyster refunds system, resulting in disruptions to customer refunds and affecting the ability of some users to receive timely reimbursements.

Impact on Customers and Operations

  • The breach led to operational disturbances that persisted for several days, prompting TfL to adjust its refund processes and respond to the security incident with urgent remediation steps.
  • By mid-September 2024, TfL acknowledged that customer data had been compromised in the attack, signaling the seriousness of the breach and its potential implications for users.

The Suspects: Jubair and Flowers

  • The two individuals identified as involved in the TfL intrusion were Thalha Jubair (20) and Owen Flowers (18). Both initially denied involvement when the case first came to light but later changed their pleas to guilty on the first day of court proceedings at Woolwich Crown Court.
  • Their alleged activities extended beyond TfL, with authorities linking Flowers to intrusions at U.S. healthcare organizations, including SSM Health Care Corporation and Sutter Health.

Investigation and Evidence Collected

  • Law enforcement, led by the National Crime Agency (NCA), conducted an extensive investigation that included the seizure of multiple devices from Flowers’ home.
  • Forensic analysis uncovered a laptop containing a screenshot showing connectivity to TfL infrastructure, evidence of access to a marketplace selling stolen credentials, and videos showing Jubair breaching TfL systems.
  • Interactions between the suspects occurred via Telegram and a shared online collaboration platform, which investigators described as part of the intrusion workflow.
  • The case also involved monitoring and analysis of communications and access patterns that helped establish the scope of the breach and the criminal network behind it.

Timeline of Key Events

  • August 31–September 3, 2024: TfL systems breached; Oyster refunds data accessed; refunds process disrupted.
  • September 12, 2024: TfL publicly confirms that customer data had been stolen in the cyberattack; NCA announces the arrest of Flowers as a suspect.
  • September 18, 2025: Jubair and Flowers are arrested in connection with the TfL attack (and related activities); investigators reveal extended incriminating evidence across the individuals’ activities.
  • March and May 2025: Flowers breached his bail conditions on two separate occasions, illustrating ongoing legal challenges around the case.
  • June 22, 2026: Trial was initially scheduled; sentencing delayed to July 16, 2026, as the suspects changed their pleas to guilty on the first day of proceedings.

Financial and Operational Consequences

  • The TfL cyberattack is estimated to have caused approximately £29 million in financial damage to the public transportation organization, with a corresponding impact on operations and customer experience.
  • The disruption prompted thousands of TfL staff to be recalled to in-person offices to reset passwords, illustrating the scale of the response required to restore secure access to systems.

Official Commentary and Reactions

  • The National Crime Agency’s Deputy Director, Paul Foster, highlighted that the attack represented a significant disruption to the UK’s critical national infrastructure and underscored the importance of early law enforcement engagement in such incidents.
  • Foster emphasized that collaboration with TfL and prompt action by investigators were instrumental in achieving the outcomes of the case and similar future protections for public infrastructure.

Evidence and Convictions

  • The investigations resulted in concrete, physical evidence connected to the cyber intrusion, including devices and digital artifacts that demonstrated both unauthorized access and the broader activity of the group.
  • The guilty pleas mark a turning point in the case, potentially accelerating proceedings and closing a chapter on a high-profile breach that affected millions of London residents and travelers.

Broader Context and Related Connections

  • In addition to TfL, Flowers’ alleged activities were connected to other intrusions in the United States, notably within healthcare networks, underscoring the cross-border reach of modern cybercrime rings and the varied targets they pursue.
  • The case illustrates how cybercriminal groups operate through coordinated channels, including the use of messaging apps and shared collaboration platforms to plan, execute, and manage intrusions.

Looking Ahead: Implications for Security and Public Infrastructure

  • The TfL incident serves as a case study in the vulnerabilities that can affect critical public services and the cascading effects on daily urban life.
  • It also highlights the importance of cross-agency cooperation, rapid incident response, and forensic readiness to detect and attribute sophisticated cyberattacks.
  • While the legal proceedings have progressed to a guilty plea, the broader lesson remains: robust cybersecurity practices, continuous monitoring, and swift remediation are essential to minimize disruption and protect sensitive transportation data.

Final ReflectionsThe Guilty Plea as a milestone in countering organized cybercrime demonstrates both the persistence of threat actors and the capacity of authorities to pursue, investigate, and bring charges to completion—even in cases involving complex, transnational criminal networks. The TfL episode reinforces the ongoing need for vigilance, advanced defense mechanisms, and coordinated responses to protect essential services that millions rely on daily.

Stay Updated

Get the next deep dive in your inbox

Subscribe for product analysis, engineering explainers, and practical guides published on TechLogHub.

See what launched this week

One email a week: new and trending developer tools, fresh comparisons, and what shipped. Unsubscribe in one click.