Cybersecurity & Privacy

Two Men Plead Guilty in UK to Cyberattacks Targeting Transport for London and U.S. Healthcare Providers

Two young men, identified as key figures within the notorious cybercrime syndicate Scattered Spider, have pleaded guilty in the United Kingdom to criminal charges stemming from a devastating cyberattack that crippled Transport for London (TfL) in August 2024. The guilty pleas from Thalha Jubair, 20, and Owen Flowers, 18, arrived on the very first day of a trial that was anticipated to span six weeks, marking a significant development in the ongoing international crackdown on sophisticated cybercriminal operations.

The charges admitted by Jubair, of East London, and Flowers, of Walsall, include conspiring to commit unauthorized acts against Transport for London’s computer systems and causing a risk of serious damage to human welfare. This latter charge underscores the potentially life-threatening consequences of cyberattacks that can disrupt critical public services. According to a report by the BBC, Flowers also admitted to his involvement in a broader conspiracy to hack into U.S.-based healthcare providers, specifically SSM Health Care Corporation and Sutter Health, during September 2024. These healthcare intrusions raise grave concerns about the potential compromise of sensitive patient data and the disruption of vital medical services.

The Scope of Scattered Spider’s Operations

The guilty pleas of Jubair and Flowers shed further light on the extensive and damaging reach of Scattered Spider, a group that has been linked to a series of high-profile cyberattacks targeting both public infrastructure and private enterprises across the globe. Their involvement in the TfL attack is particularly concerning due to the potential impact on millions of daily commuters in one of the world’s largest metropolitan areas. The disruption to TfL’s services could have led to widespread travel chaos, impacting businesses, emergency services, and the daily lives of London residents.

Thalha Jubair is also a figure of significant interest to U.S. law enforcement. In September 2025, prosecutors in New Jersey unsealed an indictment detailing a wide-ranging criminal enterprise allegedly orchestrated by Jubair and other Scattered Spider members. The indictment alleges a pattern of computer fraud, wire fraud, and money laundering that encompassed at least 120 network intrusions affecting 47 U.S. entities between May 2022 and September 2025. The scale of these operations is staggering, with victims reportedly paying out at least $115 million in ransom payments to the group.

A History of High-Profile Attacks

This latest development is not the first time Flowers and Jubair have been associated with significant cybercrimes. In July 2025, KrebsOnSecurity reported on their arrest in the United Kingdom in connection with Scattered Spider’s ransomware attacks against prominent British retailers, including Marks & Spencer, Harrods, and the Co-op Group. These attacks not only resulted in financial losses for these businesses but also caused significant disruption to their operations and potentially impacted consumer confidence.

Furthermore, sources familiar with these investigations have indicated that Owen Flowers was the individual who anonymously provided interviews to the media in the days following the group’s September 2023 ransomware attacks on MGM Resorts and Caesars Entertainment. These attacks, which disrupted operations at major Las Vegas casinos, highlighted the group’s ability to target high-value organizations and cause widespread operational paralysis. The fact that Flowers was willing to speak to the press after these attacks suggests a degree of audacity and a calculated effort to shape the narrative surrounding the group’s activities.

The Engine of Deception: SIM Swapping and Phishing

A central pillar of Scattered Spider’s modus operandi, as detailed by prosecutors, involved sophisticated SIM-swapping operations. Thalha Jubair is alleged to have co-managed a popular Telegram channel known as "Star Chat." This platform served as a hub for a SIM-swapping group that employed voice and SMS-based phishing attacks. The objective was to steal employee credentials from major wireless providers in both the U.S. and the UK. Once access was gained, the attackers could reroute a target’s phone number to a device under their control, enabling them to intercept calls and text messages. This capability is particularly dangerous as it allows for the interception of sensitive information, including one-time codes crucial for multi-factor authentication, thereby granting access to a wide array of online accounts.

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

The U.S. Department of Justice has also linked Jubair to a massive SMS phishing campaign conducted during the summer of 2022. This campaign successfully harvested single sign-on credentials from employees at hundreds of companies. The fallout from this operation was substantial, leading to intrusions and data thefts at over 130 organizations, including well-known entities such as LastPass, DoorDash, Mailchimp, Plex, and Signal. The compromise of these platforms underscores the systemic risk posed by credential theft and the cascading impact it can have across the digital ecosystem.

Early Ventures and Evolving Tactics

Even at a young age, the individuals involved in Scattered Spider have demonstrated a history of engaging in illicit online activities. KrebsOnSecurity reported previously that one of Jubair’s online personas at the age of 15 was "Everlynn." As Everlynn, this hacker reportedly sold fraudulent "emergency data requests." These requests, often made using compromised police and government email addresses, were designed to trick major tech companies into divulging subscriber data, such as usernames and IP/email addresses. The attackers would falsely claim these requests concerned urgent matters of life and death, circumventing the need for formal court orders. This tactic highlights an early pattern of exploiting trust and authority for illicit gain.

A Wider Net: Other Scattered Spider Members and Convictions

The convictions of Jubair and Flowers are part of a broader international effort to dismantle Scattered Spider. In April 2026, Tyler Buchanan, 24, a British national and fellow Scattered Spider member, pleaded guilty to wire fraud conspiracy and aggravated identity theft for his role in the 2022 SMS phishing spree. The government stated that Buchanan, Jubair, and others utilized the credentials obtained from that campaign to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan’s sentencing is scheduled for October 2.

In August 2025, Noah Michael Urban, 20, a Scattered Spider member from Florida, received a 10-year federal prison sentence and was ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy charges. Urban’s conviction is another testament to the severe legal consequences faced by individuals involved in these sophisticated cybercriminal activities.

The U.S. Department of Justice has indicated that three other alleged Scattered Spider defendants, indicted alongside Buchanan, are still facing charges. These individuals include Ahmed Hossam Eldin Elbadawy, 24, also known as "AD," of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, known as "joeleoli," of Jacksonville, North Carolina. The ongoing legal proceedings against these individuals suggest that the investigation into Scattered Spider’s operations remains active and comprehensive.

Sentencing and Future Implications

The sentencing of Owen Flowers and Thalha Jubair is scheduled to take place in a London court on July 15, 2026. The outcomes of these proceedings will not only determine their individual penalties but will also send a clear message about the United Kingdom’s commitment to prosecuting cybercriminals.

The implications of these convictions extend beyond the immediate legal ramifications. The successful prosecution of key members of Scattered Spider, particularly those involved in attacks on critical infrastructure like Transport for London and vital sectors like healthcare, demonstrates the growing capacity of law enforcement agencies to collaborate across borders and bring sophisticated cybercriminals to justice. This case serves as a stark reminder of the pervasive threat posed by organized cybercrime and the critical need for robust cybersecurity measures across all sectors. The financial and societal costs of such attacks are immense, and the ongoing efforts to dismantle groups like Scattered Spider are crucial for safeguarding digital infrastructure and public safety. The detailed nature of the charges and the extensive scope of the alleged criminal activities highlight the evolving sophistication of cyber threats and the constant need for vigilance and innovation in cybersecurity defenses.

Related Articles

Leave a Reply

Your email address will not be published. Required fields are marked *

Back to top button
Snapost
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.