Two young hackers linked to the notorious cybercrime group Scattered Spider have been sentenced to five years and six months in prison for carrying out a devastating cyber-attack on Transport for London (TfL) in 2024. The attack disrupted London’s transport network for months, compromised the personal data of millions of customers, and cost TfL an estimated £29 million.
Authorities say the hackers, who were teenagers at the time of the offence, live-streamed their 16-hour cyber intrusion and boasted about accessing sensitive customer information.
Who Are the Teen Hackers Jailed Over the TfL Cyber Attack?
The convicted hackers are:
- Owen Flowers, 18, from Walsall.
- Thalha Jubair, 20, from East London.
The pair pleaded guilty in June to carrying out the large-scale cyber attack while they were teenagers. Flowers was 17, and Jubair was 18 when they infiltrated TfL’s systems on 31 August 2024.
Investigators described both as computer-obsessed individuals who spent most of their time online and were associated with the English-speaking cybercrime collective Scattered Spider.
How the TfL Hack Was Carried Out
According to prosecutors, the hackers gained access by impersonating a TfL employee and convincing a help desk worker to reset the employee’s password.
The cyber attack reportedly began on a Saturday evening to reduce the likelihood of being detected by IT staff.
Once inside TfL’s systems, the hackers:
- Accessed customer databases.
- Retrieved Oyster card information.
- Searched for the personal details of well-known London personalities.
- Attempted to obtain banking information.
- Streamed the attack online for nearly 16 hours.
Messages presented in court showed the pair celebrating their success, with Flowers joking, “Scattered Spider is creating webs on the London Underground.”
Millions of Customers Affected by the Data Breach
The cyber attack resulted in one of the most significant data breaches faced by TfL.
According to investigators:
- Personal data belonging to millions of customers was stolen.
- Up to 10 million customer records are believed to have been compromised.
- The stolen database reportedly continues circulating within cybercriminal networks.
The breach also forced all 27,000 TfL employees to reset their passwords in person as part of emergency security measures.
TfL Services Severely Disrupted and £29 Million Lost
The attack caused widespread disruption across Transport for London’s digital infrastructure.
Officials revealed:
- 148 IT systems became inoperable.
- Online customer services remained affected for months.
- Dial-a-Ride, a transport service for elderly and disabled passengers, experienced major disruption.
- TfL disconnected parts of its systems from the internet to contain the breach.
The transport authority estimates the incident ultimately cost around £29 million, revised from an earlier estimate of £39 million.
Hackers’ Criminal Backgrounds and International Links
Both hackers had extensive histories involving cybercrime.
Owen Flowers
Investigators found Flowers actively hacking two U.S. healthcare providers during his arrest in September 2024.
Police also seized cryptocurrency valued at around £1 million.
Court documents revealed disturbing messages in which Flowers joked that the healthcare attacks could potentially harm vulnerable hospital patients.
Thalha Jubair
Jubair had already accumulated 22 previous convictions related to hacking, fraud, and harassment.
He had earlier received a Youth Rehabilitation Order for offences linked to the Lapsus$ hacking group, which targeted several multinational companies.
U.S. authorities are also seeking Jubair in connection with cyber attacks affecting 47 American victims, allegedly generating around $115 million in ransom payments.
Scattered Spider Remains a Major Cybersecurity Concern
Authorities believe the pair were members of Scattered Spider, a loosely organised cybercrime group linked to numerous high-profile attacks against global organisations.
The group has previously been associated with cyber incidents targeting:
- Marks & Spencer
- Co-op
- Major telecommunications firms
- International healthcare organisations
- Technology companies
Investigators say members frequently target organisations using sophisticated social engineering techniques rather than advanced malware.
NCA Warns of Growing Threat from Young UK Hackers
Following the sentencing, the National Crime Agency (NCA) warned that young homegrown hackers remain one of the UK’s most significant cybersecurity threats.
NCA Deputy Director Paul Foster urged parents, educators, technology companies, and law enforcement agencies to work together to prevent young people from being drawn into online criminal communities.
Cybersecurity expert Allison Nixon also cautioned that prison sentences alone may not deter aspiring hackers, arguing that authorities should treat organised cybercrime networks similarly to violent youth gangs because of the scale of harm they can inflict.
The sentencing of Owen Flowers and Thalha Jubair marks a significant victory for UK law enforcement against organised cybercrime. However, the case also highlights the growing challenge posed by young, highly skilled hackers recruited into online criminal communities. As cyber threats continue to evolve, authorities warn that stronger digital security, greater public awareness, and early intervention will be essential to protecting critical infrastructure and preventing future attacks.