Two members of the Scattered Spider cybercriminal collective have pleaded guilty to the 2024 cyberattack on Transport for London (TfL), one of the UK’s most critical public infrastructure operators. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, entered guilty pleas on June 22, 2026, at Woolwich Crown Court on what was to have been the first day of trial.

What Happened

According to the National Crime Agency, the breach unfolded between August 31 and September 3, 2024. The attackers infiltrated TfL’s internal network, compromised the Oyster refund system, and exfiltrated customer data. The disruption forced all 28,000 TfL employees to attend offices in person to complete mandatory password resets, an operational paralysis with no precedent for the organization.

Forensic evidence recovered from Flowers’ residence included laptops containing a screenshot of active network connectivity to TfL infrastructure and screen-recorded video of Jubair actively accessing TfL systems during the breach. The NCA described the investigation as “lengthy, highly complex, and painstaking.” TfL reported approximately £29 million in losses and recovery costs. Sentencing is scheduled for July 16, 2026.

Why It Matters

The Scattered Spider collective has demonstrated a consistent pattern of targeting large organizations through social engineering, SIM swapping, and help-desk impersonation rather than technical zero-day exploitation. Other victims attributed to the group include MGM Resorts and Caesars Entertainment. As Deputy Director Paul Foster of the NCA’s National Cyber Crime Unit stated: “Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences.”

The guilty pleas mark a significant law enforcement outcome at a time when prosecution of financially motivated cybercriminals operating within Western jurisdictions is accelerating.

For Defenders

The Scattered Spider attack method of choice remains social engineering and credential abuse rather than complex technical exploits. Identity governance, out-of-band verification for privileged access changes, and persistent security awareness training for help-desk staff are the primary defensive layers against this threat profile. For deeper context on credential-based attack risks, see our earlier analysis: Brute Force Attacks on Password Managers: Risks and Mitigation Strategies for CISOs.

Source: National Crime Agency