Scattered Spider Cybercriminals Plead Guilty to Transport for London Attack and Global Hacking Campaign

In a landmark legal victory against one of the world’s most disruptive cybercrime syndicates, two young men pleaded guilty in a United Kingdom court this week to charges stemming from a series of high-profile digital intrusions. The defendants, Thalha Jubair, 20, and Owen Flowers, 18, admitted to their roles in a August 2024 cyberattack that targeted Transport for London (TfL), the local government body responsible for the majority of the transport network in Greater London. The guilty pleas, entered on the first day of what was scheduled to be a six-week trial, provide a rare glimpse into the operations of Scattered Spider, a prolific hacking collective that has caused hundreds of millions of dollars in damages across the globe.
The prosecution of Jubair and Flowers marks a significant milestone for the UK’s National Crime Agency (NCA) and its international partners, including the United States Federal Bureau of Investigation (FBI). The duo admitted to conspiring to commit unauthorized acts against TfL’s computer systems, specifically acknowledging that their actions caused a significant risk of serious damage to human welfare. This specific charge underscores the severity of the attack, which disrupted critical infrastructure used by millions of commuters daily.
The Targeted Strike on London’s Transit Infrastructure
The August 2024 attack on Transport for London was characterized by its audacity and the direct impact it had on public services. While TfL officials initially worked to contain the breach, the intrusion led to the suspension of various digital services, including Oyster card management, contactless payment history, and internal employee systems. Prosecutors argued that by targeting the backbone of London’s transit system, the hackers demonstrated a reckless disregard for the safety and logistical stability of the city.
Owen Flowers, a resident of Walsall, also pleaded guilty to a separate conspiracy involving U.S.-based healthcare providers. According to court records, Flowers was involved in hacking attempts against SSM Health Care Corporation and Sutter Health in September 2024. These attacks on the healthcare sector further illustrate the group’s strategy of targeting essential services where the pressure to restore operations often leads to higher likelihoods of ransom payments.
The Global Reach of Scattered Spider
Scattered Spider, also known by aliases such as UNC3944 or Starfraud, has gained international notoriety for its sophisticated social engineering tactics. Unlike many ransomware groups that rely primarily on technical exploits, Scattered Spider excels at manipulating human psychology. The group frequently employs "vishing" (voice phishing) and "smishing" (SMS phishing) to trick corporate help desks and employees into surrendering their credentials or bypass multi-factor authentication (MFA).
The scale of the group’s operations is vast. In September 2025, U.S. prosecutors in New Jersey unsealed a comprehensive indictment against Thalha Jubair and other members of the collective. The indictment alleges that between May 2022 and September 2025, the group conducted at least 120 computer network intrusions involving 47 different U.S. entities. These attacks were not merely for prestige; they were highly lucrative. U.S. law enforcement estimates that Scattered Spider’s victims have paid a staggering $115 million in ransom payments to date.
Among the group’s most famous targets were the Las Vegas gaming giants MGM Resorts and Caesars Entertainment. In September 2023, the group successfully disrupted operations at these facilities, leading to widespread system outages that affected everything from hotel room keys to slot machines. Investigations revealed that Owen Flowers was likely the individual who gave anonymous media interviews following those attacks, boasting about the group’s ability to bypass modern security defenses.
The Modus Operandi: SIM Swapping and Social Engineering
The technical prowess of Jubair and Flowers was rooted in their mastery of the "Com"—a decentralized community of young hackers who specialize in identity theft and telecommunications fraud. A central component of their operation was a Telegram channel known as "Star Chat." Managed in part by Jubair, this channel served as a hub for SIM-swapping services.
SIM swapping involves transferring a victim’s phone number to a device controlled by the attacker. By gaining access to a target’s mobile number, the hackers can intercept one-time passwords (OTPs) used for multi-factor authentication, granting them full access to the victim’s bank accounts, email, and corporate internal systems. To facilitate this, the group used phishing attacks to steal credentials from employees at major wireless providers in both the U.S. and the U.K., effectively gaining the "keys to the kingdom" of the telecommunications infrastructure.

One of Jubair’s known hacker handles, "Rocket Ace," was frequently associated with these activities. Evidence presented by prosecutors included receipts from Star Chat’s services, showing the successful redirection of T-Mobile customer accounts. This infrastructure allowed the group to launch a massive SMS phishing campaign in the summer of 2022, which compromised the internal data of more than 130 organizations, including major tech firms like LastPass, DoorDash, Mailchimp, Plex, and Signal.
Exploiting Emergency Protocols
The investigation into Jubair also uncovered a disturbing history of digital fraud dating back to his mid-teens. Under the alias "Everlynn," a 15-year-old Jubair allegedly sold fraudulent "Emergency Data Requests" (EDRs). These requests are a legitimate tool used by law enforcement to obtain subscriber data from tech companies in urgent situations involving an immediate threat to life.
By using compromised police and government email accounts, Jubair bypassed the standard legal process of obtaining a court order. He claimed the requests were matters of life and death, forcing companies like Apple, Google, and Meta to hand over sensitive user information, including IP addresses and usernames. This data was then sold or used to further the group’s extortion schemes.
A Growing List of Convictions
The guilty pleas of Flowers and Jubair are part of a broader crackdown on Scattered Spider. In April 2026, 24-year-old Tyler "Tylerb" Buchanan, another British national associated with the group, pleaded guilty to wire fraud conspiracy and aggravated identity theft. Buchanan was involved in the 2022 phishing spree that resulted in the theft of at least $8 million in cryptocurrency from victims across the United States.
In August 2025, Noah Michael Urban, a 20-year-old member from Florida, was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution. The U.S. Department of Justice continues to pursue other members of the group, including Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans, all of whom face charges related to the group’s international crime spree.
Chronology of Key Events
- Summer 2022: Scattered Spider launches a massive SMS phishing campaign targeting 130+ organizations, including LastPass and Mailchimp.
- September 2023: The group attacks MGM Resorts and Caesars Entertainment, causing massive operational disruptions in Las Vegas.
- August 2024: The cyberattack on Transport for London (TfL) occurs, leading to the eventual arrest of Flowers and Jubair.
- July 2025: Owen Flowers and Thalha Jubair are arrested in the United Kingdom for attacks on retailers Marks & Spencer, Harrods, and the Co-op Group.
- August 2025: Noah Michael Urban is sentenced to 10 years in U.S. federal prison.
- September 2025: U.S. prosecutors unseal an indictment against Jubair for 120 network intrusions.
- April 2026: Tyler Buchanan pleads guilty to wire fraud and identity theft in the U.S.
- June 2026: Flowers and Jubair plead guilty in London on the first day of their trial.
Implications for Global Cybersecurity
The rise and fall of these Scattered Spider members highlight a shift in the cybercrime landscape. The group’s success was not predicated on "zero-day" exploits or complex coding, but rather on the exploitation of human vulnerabilities and the interconnected nature of modern digital identity. The use of SIM swapping and social engineering has forced many organizations to rethink their reliance on SMS-based multi-factor authentication, moving instead toward hardware security keys and biometric verification.
Furthermore, the case demonstrates the increasing effectiveness of cross-border law enforcement cooperation. The ability of the NCA and the FBI to link digital personas to physical individuals across different jurisdictions has sent a clear message to the "Com" community. Despite their attempts at anonymity via Telegram and encrypted messaging, the digital footprint left by these young hackers eventually led to their downfall.
The conviction of Flowers and Jubair is also a warning regarding the vulnerability of public infrastructure. The "risk to human welfare" charge serves as a legal precedent for how future cyberattacks on transit, power, or water systems will be prosecuted, emphasizing that digital crimes have real-world physical consequences.
Sentencing and Final Remarks
Owen Flowers and Thalha Jubair are currently scheduled to be sentenced in a London court on July 15, 2026. Given the scale of their crimes and the admitted risk to public safety, legal experts anticipate substantial prison terms. Meanwhile, Jubair remains a person of interest for U.S. authorities, and it is expected that extradition proceedings may follow his sentencing in the United Kingdom to answer for the $115 million in damages alleged in the New Jersey indictment.
As the legal proceedings against the remaining members of Scattered Spider continue, the cybersecurity community remains on high alert. The tactics pioneered by this group continue to be refined by other threat actors, ensuring that the battle between digital defenders and social engineering specialists remains a central conflict in the modern era of information security.







