Two Men Plead Guilty to Cyberattacks Crippling Transport for London and Targeting U.S. Healthcare Providers

Two young men have pleaded guilty in the United Kingdom to criminal charges stemming from a significant cyberattack in August 2024 that brought Transport for London (TfL), the agency responsible for the vast public transport network serving Greater London, to its knees. The guilty pleas from Thalha Jubair, 20, and Owen Flowers, 18, were entered on the very first day of what was anticipated to be a six-week trial, signaling a swift resolution to a case that has reverberated through the cybersecurity landscape. Both individuals are identified as key operatives within the notorious cybercrime syndicate known as Scattered Spider, a group that has been linked to a series of high-profile ransomware attacks and data breaches affecting organizations across the globe.
The TfL Attack and its Devastating Impact
The August 2024 attack on Transport for London was not merely an inconvenience; it represented a critical disruption to the daily lives of millions of Londoners and posed significant risks to public safety. While the exact nature and extent of the disruption are still being fully assessed, initial reports indicated that the cyberattack led to the paralysis of crucial operational systems, potentially impacting ticketing, scheduling, and communication networks. Such an event can have cascading effects, from causing widespread travel chaos to compromising the integrity of sensitive passenger data. The admission of guilt by Jubair and Flowers to "conspiring to commit unauthorized acts against Transport for London computer systems and causing risk of serious damage to human welfare" underscores the gravity of their actions and the potential real-world consequences.
A Pattern of Sophistication and Global Reach
The guilty pleas of Jubair and Flowers shed further light on the operational methods and extensive reach of Scattered Spider. The BBC reported that Owen Flowers, in addition to his role in the TfL attack, also admitted to participating in a conspiracy to hack into U.S.-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024. This dual targeting of critical infrastructure – public transport and healthcare – highlights a disturbing trend where cybercriminals are increasingly focusing on sectors vital to societal functioning, aiming to maximize pressure and potential ransom payouts.
Thalha Jubair, a resident of East London, is no stranger to law enforcement scrutiny on both sides of the Atlantic. In September 2025, prosecutors in New Jersey unsealed an indictment that painted a stark picture of Jubair’s alleged involvement in a wide-ranging criminal enterprise. The indictment detailed accusations of computer fraud, wire fraud, and money laundering, linked to an astonishing 120 computer network intrusions that impacted 47 U.S. entities between May 2022 and September 2025. The financial scale of these alleged activities is staggering, with victims reportedly paying at least $115 million in ransom payments to Scattered Spider and its affiliates.
Scattered Spider: A Global Menace
Scattered Spider, also known by other monikers such as "Gold Factory," has emerged as one of the most prolific and disruptive cybercrime groups in recent years. Their modus operandi often involves a sophisticated blend of social engineering, phishing, and the exploitation of known vulnerabilities. The group has been linked to a series of high-profile attacks, including those against major retailers like Marks & Spencer and Harrods, as well as the British food retailer Co-op Group.
KrebsOnSecurity reported in July 2025 that both Flowers and Jubair were arrested in the UK in connection with these earlier ransom attacks. Furthermore, sources familiar with the investigations indicated that Flowers was the individual who anonymously granted interviews to the media in the aftermath of the group’s September 2023 ransomware attacks that crippled operations at major Las Vegas casinos, including MGM Resorts and Caesars Entertainment. This willingness to engage with the media, albeit anonymously, suggests a level of boldness and a desire to control narratives surrounding their criminal activities.
The Mechanics of SIM-Swapping and Phishing
A significant aspect of Scattered Spider’s operations, particularly linked to Thalha Jubair, involves sophisticated SIM-swapping techniques. Prosecutors allege that Jubair co-managed a popular Telegram channel named "Star Chat," which served as a hub for a SIM-swapping group. This group employed a combination of voice- and SMS-based phishing attacks to pilfer credentials from employees at major wireless providers in both the U.S. and the UK. Once access was gained to internal systems, attackers could reroute a target’s phone number to a device under their control. This allowed them to intercept calls and text messages, critically including the one-time passcodes (OTPs) used for multi-factor authentication (MFA) on a wide range of online accounts. This method effectively bypasses one of the primary security measures designed to protect sensitive information.
The implications of such SIM-swapping capabilities are far-reaching. Beyond financial theft, it can enable account takeovers, identity theft, and the disruption of personal and professional communications. The ability to intercept OTPs renders many common security protocols vulnerable, forcing a re-evaluation of current digital security practices.
A Trail of High-Profile Breaches
The U.S. Department of Justice’s indictment against Jubair further implicates him in a massive SMS phishing campaign during the summer of 2022. This campaign successfully harvested single sign-on credentials from employees at hundreds of companies. The fallout from this campaign was significant, leading to intrusions and data breaches at over 130 organizations, including prominent names such as LastPass, DoorDash, Mailchimp, Plex, and Signal. The compromise of credentials from these companies likely provided attackers with access to a wealth of sensitive user data and internal systems, exacerbating the impact of the breaches.

KrebsOnSecurity also previously reported on one of Jubair’s earlier hacker personas, "Everlynn," active when he was just 15 years old. As "Everlynn," he allegedly sold fraudulent "emergency data requests." These requests, often using compromised police and government email addresses, were used to demand subscriber data from major tech companies. The attackers falsely claimed these requests pertained to urgent, life-or-death matters that could not await a court order, leveraging a false sense of official authority to bypass normal data access protocols.
A Broader Network of Accused Individuals
The case of Jubair and Flowers is not an isolated incident but part of a larger ongoing effort by law enforcement to dismantle Scattered Spider. Several other individuals associated with the group have faced legal consequences:
- Tyler "Tylerb" Buchanan: In April 2026, this 24-year-old British national and Scattered Spider member pleaded guilty to wire fraud conspiracy and aggravated identity theft for his participation in the 2022 SMS phishing spree. The U.S. government stated that Buchanan, Jubair, and others used the credentials obtained during that campaign to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan is scheduled for sentencing on October 2.
- Noah Michael Urban: In August 2025, this 20-year-old Scattered Spider member from Florida was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy charges. His case, also linked to SIM-swapping activities, underscores the significant prison sentences associated with these crimes.
The U.S. Department of Justice has indicated that three other defendants indicted alongside Buchanan remain subject to charges. These individuals include:
- Ahmed Hossam Eldin Elbadawy, 24, also known as "AD," of College Station, Texas.
- Evans Onyeaka Osiebo, 21, of Dallas, Texas.
- Joel Martin Evans, 26, also known as "joeleoli," of Jacksonville, North Carolina.
The continued prosecution of these individuals demonstrates a coordinated, multi-jurisdictional effort to combat the pervasive threat posed by Scattered Spider.
Timeline of Key Events and Prosecutions:
- Summer 2022: A large-scale SMS phishing campaign, allegedly involving Jubair and others, steals single sign-on credentials from employees at hundreds of companies, leading to over 130 subsequent intrusions and data thefts, including at LastPass, DoorDash, Mailchimp, Plex, and Signal.
- September 2023: Scattered Spider’s ransomware attacks disrupt operations at MGM Resorts and Caesars Entertainment in Las Vegas. Owen Flowers allegedly gives anonymous media interviews post-attack.
- July 2025: KrebsOnSecurity reports the arrest of Flowers and Jubair in the UK in connection with ransomware attacks against Marks & Spencer, Harrods, and Co-op Group.
- September 2025: U.S. prosecutors in New Jersey unseal an indictment against Thalha Jubair, alleging his involvement in 120 network intrusions and $115 million in ransom payments.
- August 2025: Noah Michael Urban, a Scattered Spider member, is sentenced to 10 years in federal prison for wire fraud and conspiracy.
- April 2026: Tyler "Tylerb" Buchanan, a UK national and Scattered Spider member, pleads guilty to wire fraud conspiracy and aggravated identity theft related to the 2022 SMS phishing campaign.
- August 2026 (specific date not provided in source, assumed context): The cyberattack crippling Transport for London occurs.
- Early 2027 (exact date not provided, assumed context): Thalha Jubair and Owen Flowers plead guilty in the UK to charges related to the TfL attack and other offenses.
- July 15, 2027: Flowers and Jubair are scheduled to be sentenced in a London court.
- October 2, 2027: Tyler Buchanan is scheduled for sentencing.
Analysis and Implications:
The guilty pleas of Jubair and Flowers represent a significant victory for law enforcement agencies in both the UK and the U.S. and a step towards accountability for the disruptive cyber activities of Scattered Spider. The group’s targeting of critical infrastructure like public transport and healthcare, alongside major corporations, signals an escalating threat landscape where the line between financial gain and societal disruption is increasingly blurred.
The ease with which Scattered Spider members, often at very young ages, have managed to execute complex and damaging attacks underscores a persistent challenge in cybersecurity: the availability of sophisticated hacking tools and techniques on the dark web, coupled with a growing pool of technically adept individuals willing to engage in criminal enterprises. The group’s reliance on SIM-swapping and sophisticated phishing highlights the enduring vulnerability of human factors and the need for continuous improvement in security awareness and protocols within organizations, particularly those in critical sectors.
The substantial ransom demands and payments indicate the lucrative nature of these cybercrimes, creating a powerful incentive for further illicit activities. The ongoing prosecutions of other Scattered Spider members suggest that law enforcement agencies are committed to a long-term strategy to dismantle such organizations. However, the fluid nature of cybercrime means that new groups and individuals will likely emerge to fill the void.
For Transport for London, the incident serves as a stark reminder of the need for robust cybersecurity defenses and continuous investment in network resilience. For the healthcare sector, the attack on SSM Health Care Corporation and Sutter Health emphasizes the critical importance of protecting patient data and ensuring the uninterrupted delivery of medical services. The global reach of Scattered Spider’s operations necessitates international cooperation and intelligence sharing to effectively combat these transnational criminal threats.
The sentencing of Jubair and Flowers, scheduled for July 15, 2027, will provide a measure of justice and serve as a deterrent. However, the broader implications of this case extend to the ongoing arms race between cybercriminals and cybersecurity professionals, and the critical need for individuals and organizations alike to remain vigilant in the face of evolving digital threats.







