UK Cybercrime Duo Pleads Guilty to Disruptive Transport for London Hack and International Scattered Spider Campaigns

Two prominent members of the notorious cybercrime syndicate known as Scattered Spider pleaded guilty in a United Kingdom court this week, marking a significant milestone in a multi-year international investigation into some of the most disruptive digital attacks in recent memory. Thalha Jubair, 20, and Owen Flowers, 18, admitted to a series of criminal charges related to a devastating August 2024 cyberattack on Transport for London (TfL) and several other high-profile intrusions targeting both British and American institutions. The guilty pleas, entered on the first day of what was scheduled to be a six-week trial, provide a rare glimpse into the operations of a group that has paralyzed major corporations and critical infrastructure across the globe.
Owen Flowers, a resident of Walsall, and Thalha Jubair, of East London, specifically admitted to conspiring to commit unauthorized acts against the computer systems of Transport for London. This particular breach was not merely a financial crime; the defendants pleaded guilty to causing a risk of serious damage to human welfare, a charge reflecting the critical nature of the public transport network in the Greater London area. Beyond the domestic charges, Flowers further admitted to involvement in a conspiracy to infiltrate U.S.-based healthcare providers, including SSM Health Care Corporation and Sutter Health, in September 2024.
The Rise and Reach of Scattered Spider
Scattered Spider, also tracked by security researchers as UNC3944, Star Fraud, or Muddled Libra, has emerged as one of the most effective and aggressive cybercrime organizations in the modern era. Unlike traditional ransomware groups that rely heavily on sophisticated malware or technical exploits, Scattered Spider is renowned for its mastery of social engineering. The group typically targets help desks and IT administrators through voice-based phishing (vishing) and SMS-based phishing (smishing) to gain initial access to corporate networks.
The group’s effectiveness lies in the youth and native English-speaking abilities of its members, which allow them to convincingly impersonate employees or technical support staff. This human-centric approach has allowed them to bypass robust technical defenses at some of the world’s largest companies. The UK National Crime Agency (NCA) and the U.S. Federal Bureau of Investigation (FBI) have been tracking the group’s evolution from SIM-swapping enthusiasts to sophisticated ransomware affiliates associated with the BlackCat/ALPHV operation.
The Transport for London Breach: A Case of Public Disruption
The August 2024 attack on Transport for London stands as one of the group’s most brazen acts within the United Kingdom. As the entity responsible for the London Underground, buses, and overground rail services, TfL is a cornerstone of the city’s daily functionality. The cyberattack forced the organization to take several systems offline, disrupting back-office functions and affecting the processing of contactless payment data.
While the primary motive appeared to be extortion, the collateral damage to public services was substantial. Prosecutors argued that the intrusion went beyond digital theft, creating potential hazards for the millions of commuters who rely on the network’s safety and operational systems. The guilty pleas from Jubair and Flowers acknowledge the severity of this risk, highlighting a shift in how law enforcement classifies cyberattacks that threaten the stability of essential public services.
A Trail of International Victimization
The legal troubles for Jubair and Flowers extend far beyond the borders of the United Kingdom. Jubair is currently a primary target for U.S. law enforcement. In September 2025, federal prosecutors in New Jersey unsealed a comprehensive indictment against him and other Scattered Spider members. The indictment alleges a massive campaign of computer fraud, wire fraud, and money laundering involving at least 120 computer network intrusions.
Between May 2022 and September 2025, the group is alleged to have targeted 47 U.S. entities. The financial scale of these operations is staggering; according to U.S. officials, the group’s victims have paid out at least $115 million in ransom payments. These figures place Scattered Spider among the most financially successful cybercriminal enterprises in history.
Flowers has also been linked to some of the group’s most publicized American exploits. Investigations suggest he was the member who provided anonymous media interviews following the September 2023 ransomware attacks on Las Vegas gaming giants MGM Resorts and Caesars Entertainment. Those attacks, which crippled hotel reservation systems and slot machines for days, resulted in hundreds of millions of dollars in operational losses and ransom payments.
Tactical Evolution: SIM Swapping and Star Chat
A central component of Jubair’s criminal activities involved the management of "Star Chat," a bustling Telegram channel dedicated to SIM-swapping and identity theft. SIM swapping involves tricking a mobile carrier into transferring a victim’s phone number to a device controlled by the attacker. This allows the hacker to intercept two-factor authentication (2FA) codes sent via SMS, granting them access to bank accounts, cryptocurrency wallets, and corporate networks.

Prosecutors allege that Jubair used voice- and SMS-based phishing to steal credentials from employees at major wireless providers in both the U.S. and the U.K. Once they possessed internal access to carrier tools, the group sold "SIM-swapping as a service." One of Jubair’s known hacker handles, "Rocket Ace," was frequently associated with these transactions. Evidence presented in court included receipts from Star Fraud Chat’s services, demonstrating the group’s ability to compromise internal T-Mobile employee tools to redirect customer traffic.
Furthermore, Jubair is linked to a massive SMS phishing campaign in the summer of 2022. This campaign, often referred to by researchers as the "0ktapus" campaign, targeted employees at over 130 organizations, including high-profile tech firms such as LastPass, DoorDash, Mailchimp, Plex, and Signal. By harvesting single sign-on (SSO) credentials, the group was able to pivot into corporate environments with ease, leading to significant data thefts.
Exploiting Emergency Protocols
The depth of Jubair’s involvement in cybercrime dates back to his mid-teens. Operating under the alias "Everlynn" at age 15, he reportedly engaged in the sale of fraudulent "emergency data requests" (EDRs). This tactic involves using compromised government or police email accounts to send urgent requests to technology companies like Apple, Google, or Meta.
The requests typically claim that a situation involves an immediate threat to life and death, thereby legally compelling the companies to provide subscriber data—such as IP addresses, phone numbers, and physical locations—without a warrant or court order. By weaponizing the legal mechanisms designed to save lives, Jubair and his associates were able to gather intelligence on targets for further extortion or harassment.
The Global Crackdown: Chronology of Arrests and Convictions
The guilty pleas of Jubair and Flowers are part of a broader, successful effort by international law enforcement to dismantle the Scattered Spider leadership. The timeline of legal actions reflects a coordinated strategy to bring the group to justice:
- July 2025: Flowers and Jubair are arrested in the UK following investigations into attacks against British retailers Marks & Spencer, Harrods, and the Co-op Group.
- August 2025: Noah Michael Urban, a 20-year-old Scattered Spider member from Florida, is sentenced to 10 years in U.S. federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy.
- September 2025: The U.S. Department of Justice unseals indictments against Jubair and several others for the 120-intrusion campaign.
- April 2026: Tyler "Tylerb" Buchanan, a 24-year-old British national, pleads guilty to wire fraud and identity theft related to the 2022 phishing spree that netted the group $8 million in stolen cryptocurrency.
- October 2026: Tyler Buchanan is scheduled for sentencing in the United States.
While Jubair and Flowers await their sentencing in London, scheduled for July 15, 2026, the U.S. Department of Justice continues to pursue other members of the group. Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans all remain under indictment and face significant prison time if convicted.
Broader Implications for Cybersecurity
The activities of Jubair and Flowers underscore a critical shift in the cyber threat landscape. The success of Scattered Spider demonstrates that human psychology remains the weakest link in the security chain. Despite the widespread adoption of multi-factor authentication (MFA), the group’s ability to bypass these measures through SIM swapping and MFA fatigue attacks has forced a re-evaluation of corporate security protocols.
Security experts suggest that the "Scattered Spider" model—characterized by decentralized, highly skilled social engineers collaborating via platforms like Telegram—is likely to be emulated by other criminal groups. The case also highlights the growing overlap between the "Com" (a community of young, online-based threat actors) and professional ransomware-as-a-service (RaaS) operations.
The collaboration between the NCA and FBI in this case serves as a warning to cybercriminals that international borders offer little protection. The use of "risk to human welfare" charges in the TfL case also signals that prosecutors are increasingly willing to treat digital infrastructure attacks with the same gravity as physical terrorism or sabotage.
As the July 2026 sentencing date approaches, the legal proceedings against Owen Flowers and Thalha Jubair will likely remain a focal point for the cybersecurity industry. Their transition from teenage SIM-swappers to internationally wanted felons serves as a cautionary tale of the high stakes and severe consequences of modern cyber warfare. For now, the guilty pleas provide a sense of closure for the dozens of organizations and millions of individuals affected by their multi-year campaign of digital chaos.







