Wire
16:45ZPRESSTVWatch as a Russian Su-35 fighter jet attempts to intercept a Ukrainian drone over the Leningrad region.16:42ZWFWITNESSIDF: Armed suspect stole weapon from Israeli civilian in southern Hebron Hills16:41ZFRANCE24ENFrance grapples with hidden toxins including pesticides, PFAS, cadmium in food16:41ZPALESTINECYemen strikes Saudi Aramco facilities following attacks on Hodeidah, warns of escalation16:39ZTASNIMNEWSIRGC says Iran strike destroyed 11 US aircraft, helicopters on ground16:35ZIRIRANMILINew human remains discovered at Minab school, Iranian families mourn16:35ZWARTRANSLARussia could fake peace push due to Graham sanctions bill, Sybiha warns16:34ZSHAAMNETWOSyrian parliament speaker offers condolences for Damascus-Deir ez-Zor road accident victims
  • S&P 500 ETF 0.10%
  • Nasdaq 0.64%
  • Nasdaq 100 1.15%
  • Dow ETF 0.48%
Terminal ↗
← The MonexusEurope

Two Scattered Spider hackers sentenced in London: what the case actually closes off

Owen Flowers and Thalha Jubair admitted their role in the 2024 attack on London’s transport authority. The case closes a chapter, but the underlying labour market for young English-speaking hackers is unchanged.

A black placeholder graphic displays "MONEXUS NEWS" and "DESK" with the word "EUROPE" centered, noting "No photograph on file."
A black placeholder graphic displays "MONEXUS NEWS" and "DESK" with the word "EUROPE" centered, noting "No photograph on file." Monexus News

At 11:00 UTC on 16 July 2026, two young British men walked out of the dock at London’s Southwark Crown Court with their sentence read into the record: five years and six months each, with three years and three months served on licence, after pleading guilty to charges connected to the August 2024 cyber-attack on Transport for London, the public body that runs the capital’s Underground, Overground, bus network and ticketing infrastructure. Owen Flowers, 21, of Walsall, and Thalha Jubair, 20, of East London, were identified by the UK’s National Crime Agency as members of Scattered Spider, a loose, English-speaking collective that has, in the space of three years, become the single most disruptive criminal hacking outfit the country has faced.

The TfL breach, which TfL disclosed on 1 September 2024, exposed the contact details of around 5,000 customers and may have reached the home addresses of roughly 30,000 more. Passengers were asked to reset their Oyster and contactless payment credentials; some staff were pulled off email entirely for weeks. The financial damage has not been publicly costed, but the operational ripple was visible on the network itself.

A conviction of this clarity is unusual in the cybercrime space, where suspects are often minors by the time the indictments are signed, and where the investigative reach of UK policing is constrained by the global, asynchronous nature of the offences. Flowers and Jubair are not alleged to have written the malware, nor to have called in the original SIM-swap that opened the door. They are alleged, in court filings summarised by the NCA and reported in the UK press, to have been the UK-based operational tier of a group that bought access, laundered proceeds, and taunted victims online in fluent English. Sentencing them is therefore a narrow win: the courtroom closure of a specific case, not the dismantling of the network.

What the court actually proved

The guilty pleas, entered in late spring, are the part of the story that matters most for the public record. They came after a long NCA and Metropolitan Police investigation in which the agencies worked with the FBI and counterparts in Romania and Canada; both defendants were first arrested at their home addresses in the West Midlands and East London in July 2024, then re-arrested once the indictment was finalised. The charges they admitted to include offences under the Computer Misuse Act 1990 and conspiracy to commit fraud; the sentencing judge described their role, in remarks reported by the BBC, as “sophisticated, persistent, and motivated entirely by financial gain.”

A sentence of five years and six months for two men in their early twenties, with just over half to be served inside, is on the upper end of what a British crown court typically imposes for non-violent, non-sexual offences committed by first-time adult offenders. The judge is reported to have accepted that the men’s roles were operational rather than architect-level, but to have given weight to the fact that the attack targeted public infrastructure at a moment of peak commuter load. Flowers was, at the time of the offence, 19; Jubair was 18. Both had turned 20 and 21 respectively by the date of sentencing.

The narrowness matters. The indictment does not name the network’s leadership, the original intrusion vector into TfL’s supplier chain, or the financial beneficiaries. The court heard that the two defendants handled tens of thousands of pounds in cryptocurrency for the wider group, and that they used Telegram, Discord and dedicated leak sites to coordinate. It did not hear, because no such evidence was tendered, who sits at the top of the arrangement.

The pattern the case sits inside

Scattered Spider first drew public attention in 2022 with SIM-swap attacks on US telecom carriers, then escalated through 2023 and 2024 into breaches at MGM Resorts, Caesars Entertainment, and a long list of mid-tier software and insurance firms. A persistent feature of the group’s playbook is social engineering of corporate IT helpdesks: callers in fluent, native English, with personal details harvested from LinkedIn, Instagram and data-brokers, convincing an outsourcing vendor to reset a privileged account. The TfL breach followed the same template, with the difference that the target was a public body rather than a casino operator. The public-interest stakes were, in that sense, higher, even if the dollar value of the ransom was not.

UK policing has, on the available evidence, become better at the early triage of these incidents. The Metropolitan Police’s cybercrime unit, the NCA’s National Cyber Crime Unit, and the regional organised-crime teams now coordinate within hours rather than weeks. The FBI’s presence in the case, with two American agents formally noted on the indictment, is the giveaway that the underlying investigation was, in part, a foreign-domestic joint operation. That cross-jurisdictional muscle is, however, expensive: it tends to be deployed against cases where victims are large enough to absorb the legal cost and patient enough to wait the years it takes.

What the sentence does not change

The labour market that produced Flowers and Jubair has not been altered by their removal. Scattered Spider is, by the consensus of private-sector incident responders and the FBI, a fluid network of mostly young, mostly native-English speakers, some of whom are teenagers when they first gain access. Replacement is not the bottleneck; the bottleneck is recruitment. The economics are stark: a successful social-engineering engagement can yield low-five-figure payouts in Bitcoin or Monero for a participant who spends a few evenings on a Discord server and a weekend on the phone. A legal apprenticeship in London, by contrast, is several years of unpaid work before a £50,000 starting salary.

The UK’s response, in policy terms, has so far been to treat the issue as a criminal-justice problem and a corporate-resilience problem. The Sentencing Council is consulting on guidelines that would treat attacks on public infrastructure as aggravating factors, and the National Cyber Security Centre has issued repeated advisories on helpdesk verification. Neither line of effort addresses the upstream question of how a teenager in Walsall or East London ends up, at 18, running a phone-pretending-to-be-Apple-Support operation against a public body. The court, correctly, did not claim to address it either.

What to watch next

The next 12 months will test whether the TfL case marks a turning point or a one-off. Three filings are worth tracking. First, the outcome of any further US indictments against alleged Scattered Spider principals, which the FBI signalled last autumn remain active. Second, the National Crime Agency’s next annual assessment of cybercrime-as-a-service, due early in 2027, which will give the first post-conviction read on whether the network’s UK recruitment pipeline has measurably slowed. Third, the Home Office response to the consultation on mandatory reporting of ransomware payments by critical-infrastructure operators, which has been sitting in draft since 2025 and which the TfL conviction will be cited in favour of. None of these moves closes the market. They do, in aggregate, raise the cost of doing business in it.

What remains uncertain, and what the open court record does not resolve, is the question of how many of Flowers and Jubair’s immediate associates are still at large in the UK. The NCA has not named further suspects in this case. Police sources quoted in the UK press suggest the agency is “aware of the wider network” but have not indicated whether further arrests are imminent. The honest read is that a five-and-a-half-year sentence, served in full at roughly three years and three months, is the cost of two specific operational roles in one specific attack. The wider problem, on the available evidence, is larger than that.

This piece stays close to the court record and the NCA’s public statements; the underlying economics of the group, including its corporate-target selection, are inferred from prior reporting and from the indictment summary, both of which are listed below.

Wire provenance

This editorial synthesis draws on the following public wire/social posts:

  • https://en.wikipedia.org/wiki/Scattered_Spider
  • https://en.wikipedia.org/wiki/2024_Transport_for_London_cyber_attack
  • https://en.wikipedia.org/wiki/National_Crime_Agency
© 2026 Monexus Media · AI-native reporting from public-source material