Drooid Logo
Back to story perspectives

Full Breakdown

Scattered Spider Hackers Plead Guilty for Disruptive TfL Cyberattack

6/24/2026, 2:39:17 AM

The Attack and Its Immediate Fallout

Between 31 August and 3 September 2024, two members of the Scattered Spider collective breached Transport for London’s internal network. The intrusion accessed the Oyster-card refund database, halted the photocard-application service for children, and forced all 28,000 TfL staff to attend a physical office for mandatory password resets. TfL reported approximately £29 million in direct losses and recovery costs, marking one of the most financially damaging assaults on UK public infrastructure.

Timeline of Key Events

  • 31 Aug – 3 Sep 2024: TfL network compromised.
  • 6 Sep 2024: Owen Flowers arrested (initial arrest).
  • 16 Sep 2024 (or 2025, per differing reports): Thalha Jubair and Flowers arrested at home addresses.
  • 22 Jun 2026: Both pleaded guilty at Woolwich Crown Court.

Key Figures & Groups

  • Thalha Jubair (20, East London) – accused of navigating TfL systems during the breach.
  • Owen Flowers (18, Walsall) – linked to the intrusion and to prior attacks on U.S. health providers SSM Health and Sutter Health.
  • National Crime Agency (NCA) – led the investigation; Deputy Director Paul Foster provided briefings.
  • City of London Police (COLP) – Deputy Commissioner Nik Adams coordinated arrests.
  • Transport for London (TfL) – victim organisation and cooperating partner.

Scope of the Breach (Data & Statistics)

  • £29 million (some sources cite £39 million) in losses.
  • Oyster-card refund data accessed; photocard-application service disabled.
  • Hackread claims personal details of 10 million customers were viewed, though other reports do not disclose the full extent.

Why It Matters: Impact on Public Services and Cybercrime Trends

The incident demonstrated that cyber intrusions can translate into tangible public inconvenience, financial damage, and erosion of trust in critical transport services. It also highlighted the growing participation of young, English-speaking actors in organized cybercrime, raising concerns about future threat vectors against national infrastructure.

Official Statements & Responses

The NCA described the probe as “lengthy, highly complex and painstaking,” emphasizing that the breach showed cybercrime’s real-world consequences for essential services. Police officials stressed a “hostile environment for cyber criminals” and affirmed that those who target critical organisations will face consequences. TfL’s cooperation was cited as pivotal to securing the convictions.

Criticism & Opposition: Youth Involvement in Cybercrime

NCA data released in 2024 indicated that 20 percent of children aged 10-16 engage in activities breaching the Computer Misuse Act, rising to 25 percent among frequent gamers. Analysts argue that the case underscores a systemic failure to deter young offenders and the need for stronger preventative education.

Conflicting Reports & Gaps

  • Loss figures differ: £29 million (multiple sources) vs. £39 million (Hackread).
  • Arrest dates for Jubair vary between 16 September 2024 and 16 September 2025.
  • The exact number of customers whose data were compromised remains undisclosed, with only one source citing 10 million.
  • Full technical details of the intrusion method have not been publicly released.

Verbatim Quotes

  • “This has been a lengthy, highly complex and painstaking investigation,” — Paul Foster, Deputy Director, NCA National Cyber Crime Unit
  • “Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public.” — Paul Foster
  • “Those who target critical organisations, cause substantial financial harm, and disrupt the daily lives of the public will not do so without consequence,” — Nik Adams, Deputy Commissioner, City of London Police
  • “The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries, epitomised by Scattered Spider,” — Paul Foster
  • “A recent survey of children aged 10-16 showed that 20% engage in behaviours that violate the Computer Misuse Act, which criminalises unauthorised access to computer systems and data. The figure is higher for those who game, standing at 25%,” — NCA report