Crime

Two hackers sentenced in UK's largest cyber crime case against TfL

Thalha Jubair and Owen Flowers, leading figures in the Scattered Spider group, have each received five-and-a-half-year prison terms for crippling Transport for London systems in a brazen 2024 attack that cost £29 million and forced thousands of staff to reset passwords in person.
Listen
AI-generated image: Two hackers sentenced in UK's largest cyber crime case against TfL
AI-generated image for illustrative purposes.
Intelligent summary
  • Thalha Jubair, 20, and Owen Flowers, 18, each received five years and six months in prison at Woolwich Crown Court on 16 July 2026 for the TfL cyber attack.
  • The Scattered Spider members caused £29 million in losses, disabled 148 systems and forced 27,000 staff to reset passwords in person.
  • Judge Mr Justice Turner cited selfish bravado as the motivation while noting the pair's youth and autism as mitigating factors.
  • The National Crime Agency described the case as the UK's largest cyber crime prosecution, highlighting effective law enforcement coordination.

It started with two young men convinced their technical prowess made them untouchable. On 16 July at Woolwich Crown Court, Thalha Jubair, 20, from east London, and Owen Flowers, 18, from Walsall, learned otherwise. Each was sentenced to five years and six months in prison. The pair, both leading members of the Scattered Spider criminal group, had pleaded guilty to conspiring to commit unauthorised acts with intent to impair Transport for London systems under the most serious provisions of the Computer Misuse Act.

The attack unfolded over four days in late summer 2024, from 31 August to 3 September. By the time it was over, 148 of TfL's systems were rendered inoperable. All 27,000 employees had to attend in person to reset their passwords. Services including Dial-a-Ride, concessionary travel, customer payments and Oyster card refunds ground to a halt. The direct losses and recovery costs reached £29 million. These are not abstract figures. They represent real disruption to London's transport network and a direct hit to public funds.

The National Crime Agency has called this the UK's largest cyber crime prosecution to date. That label matters. It signals both the scale of the offending and the seriousness with which authorities finally responded. Jubair and Flowers were already known to law enforcement for prior cyber activity. Their membership in Scattered Spider placed them inside a loose but dangerous network that has targeted high-profile organisations on both sides of the Atlantic. Yet this time the net closed.

Bravado meets reality

Mr Justice Turner, passing sentence, did not mince words. He described the offending as

primarily motivated by selfish bravado, heedless of the severe consequences to others
. The judge did take into account the defendants' young age and autism diagnoses as mitigating factors. Even so, the term handed down sends a clear message: talent turned to crime will be met with substantial prison time when critical national infrastructure is in the crosshairs.

Consider what the attack actually achieved. The hackers gained such deep access that some insiders likened it to holding the keys to the kingdom. They livestreamed elements of their intrusion and coordinated via Telegram. TfL eventually stopped the bleed by disconnecting systems and mandating physical password resets. The inconvenience to staff was immense. The cost to taxpayers was undeniable. And the erosion of confidence in systems millions rely on every day was palpable.

This case stands out for another reason. It is only the second prosecution under the toughest section of the Computer Misuse Act. That statute exists precisely for incidents like this, where the potential for serious damage to essential services is not theoretical but immediate. The fact it has been used successfully here should encourage other organisations facing similar threats to come forward quickly rather than hope the problem stays quiet.