It started with two young men convinced their technical prowess made them untouchable. On 16 July at Woolwich Crown Court, Thalha Jubair, 20, from east London, and Owen Flowers, 18, from Walsall, learned otherwise. Each was sentenced to five years and six months in prison. The pair, both leading members of the Scattered Spider criminal group, had pleaded guilty to conspiring to commit unauthorised acts with intent to impair Transport for London systems under the most serious provisions of the Computer Misuse Act.
The attack unfolded over four days in late summer 2024, from 31 August to 3 September. By the time it was over, 148 of TfL's systems were rendered inoperable. All 27,000 employees had to attend in person to reset their passwords. Services including Dial-a-Ride, concessionary travel, customer payments and Oyster card refunds ground to a halt. The direct losses and recovery costs reached £29 million. These are not abstract figures. They represent real disruption to London's transport network and a direct hit to public funds.
The National Crime Agency has called this the UK's largest cyber crime prosecution to date. That label matters. It signals both the scale of the offending and the seriousness with which authorities finally responded. Jubair and Flowers were already known to law enforcement for prior cyber activity. Their membership in Scattered Spider placed them inside a loose but dangerous network that has targeted high-profile organisations on both sides of the Atlantic. Yet this time the net closed.
Bravado meets reality
Mr Justice Turner, passing sentence, did not mince words. He described the offending as
primarily motivated by selfish bravado, heedless of the severe consequences to others. The judge did take into account the defendants' young age and autism diagnoses as mitigating factors. Even so, the term handed down sends a clear message: talent turned to crime will be met with substantial prison time when critical national infrastructure is in the crosshairs.
Consider what the attack actually achieved. The hackers gained such deep access that some insiders likened it to holding the keys to the kingdom. They livestreamed elements of their intrusion and coordinated via Telegram. TfL eventually stopped the bleed by disconnecting systems and mandating physical password resets. The inconvenience to staff was immense. The cost to taxpayers was undeniable. And the erosion of confidence in systems millions rely on every day was palpable.
This case stands out for another reason. It is only the second prosecution under the toughest section of the Computer Misuse Act. That statute exists precisely for incidents like this, where the potential for serious damage to essential services is not theoretical but immediate. The fact it has been used successfully here should encourage other organisations facing similar threats to come forward quickly rather than hope the problem stays quiet.