Duplicate » admin by request

Teenage Scattered Spider Members Sentenced Over £29 Million TfL Attack

Night aerial of a dense city at dusk with a bright orange highway interchange and glowing data lines converging at the center.

On 16 July 2026, Woolwich Crown Court sentenced Thalha Jubair and Owen Flowers to five years and six months each for the 2024 cyberattack on Transport for London. Both had changed their pleas to guilty on 22 June, the day they were due to stand trial, admitting offenses under Section 3ZA of the Computer Misuse Act. That section applies where an unauthorized act causes or creates a significant risk of serious damage, and it was only the second prosecution of its kind ever brought in the UK.

The intrusion ran from 31 August to 3 September 2024. TfL reported £29 million in loss and recovery costs, 148 systems rendered inoperable, and all 27,000 of its employees required to attend a TfL office in person to reset their passwords. Around 10 million people had personal data taken.

Jubair was 19 when the attack began and Flowers was 17. They worked from their family homes in East London and Walsall, messaging each other over Telegram and sharing a common online workspace while the intrusion was underway.

Four Days Inside TfL’s Network

TfL moved quickly to contain the attack, and the NCA credits that response with limiting the damage. Had the pair succeeded in shutting down the transport network, the agency estimated the cost to the UK economy could have reached £56 billion.

What did go down was still substantial. The Dial-a-Ride booking service, which provides transport for vulnerable Londoners, was disrupted. So were concessionary travel cards, the digital payments channel, and the application system for Oyster photocards used by children and young people. The rollout of contactless ticketing was delayed. Data from the Oyster refunds system was accessed, and the customer refund system itself was affected, leaving some people out of pocket far longer than normal.

Of the 148 systems knocked out, several were critical enough to require significant manual workarounds. Trains and buses kept running throughout.

The internal recovery tells its own story. Every one of TfL’s 27,000 employees had to physically attend an office to reset their password: no self-service reset, no call to the help desk, in-person identity verification for the entire workforce. An organization takes that step when remote identity checks can no longer be trusted.

Silhouette of a person wearing a hoodie and headset at a desk, with glowing red circuit graphics in the background, suggesting cybersecurity work. » admin by request

Who Jubair and Flowers Were Working With

The National Crime Agency identified both men as leading members of Scattered Spider, the criminal collective also tracked as Octo Tempest, UNC3944, and 0ktapus. Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, called the group the most significant cybercrime threat to the UK in recent years and described the case as the largest cybercrime prosecution ever brought before a UK court.

The group built its reputation on the 2023 attacks against MGM Resorts and Caesars Entertainment, and has since been linked to Marks & Spencer, Harrods, and Jaguar Land Rover. Those incidents share a method rather than a tool. FBI Cyber Division Assistant Director Brett Leatherman described the group as relying on data extortion, SIM-swap attacks, and other social engineering techniques to get inside networks.

Flowers was first arrested on 6 September 2024, days into the TfL incident. Investigators found him mid-intrusion against two US healthcare providers, SSM Health Care Corporation and Sutter Health, both of which had already been infiltrated and damaged. Devices seized from his home included a laptop holding a screenshot of network connectivity to TfL infrastructure and videos he had recorded of Jubair accessing TfL systems during the attack. Both men were arrested at their home addresses on 16 September.

Neither the NCA nor the CPS has published how the pair first got into TfL’s network. That gap is worth stating plainly rather than filling in, though the group’s established method points in a fairly specific direction.

Why Service Desks Keep Getting Called

Scattered Spider’s core technique is telephone-based social engineering against IT help desks. An operator calls posing as an employee, often armed with real details scraped from LinkedIn or pulled from earlier breaches, and talks an agent into resetting a password or enrolling a new MFA device. Where that fails, the fallbacks are MFA fatigue, SIM swapping, or real-time phishing kits that capture a password and a one-time code together.

The pattern is well documented in cases where the entry point was confirmed. M&S chairman Archie Norman has said publicly that attackers impersonated an employee and convinced a third-party service desk agent to reset credentials. In the Clorox breach, an intruder called the outsourced support desk, asked for a password reset, and received one.

The workflows these crews target are the same everywhere: password resets, device enrollment, and MFA changes. Every organization with a support function has them, and they are manual by design because they exist to help people who are locked out.

We covered this attack pattern in more detail in a recent post on securing the service desk against social engineering, including the verification controls and privilege limits that reduce what a successful call can achieve.

What Standing Privilege Turns a Stolen Login Into

A reset password gets an attacker one account. What that account can reach afterward determines whether the incident is a contained nuisance or a £29 million recovery.

Verification training at the service desk reduces how often the first call succeeds. The second half of the problem is what those credentials reach once they work. Controls that limit what a compromised account inherits include:

  • Removing standing local admin rights so a stolen login lands on an endpoint with no privileges attached to it
  • Elevating individual applications rather than users, keeping the rest of the session de-elevated
  • Requiring approval for elevation requests, adding a human checkpoint an attacker has to clear separately
  • Restricting help desk agents from resetting credentials for administrator and executive accounts without escalation
  • Logging every elevation and privileged action so unusual patterns surface while an intrusion is still in progress
  • Enforcing MFA at the point of elevation, not only at initial login

These controls operate after the phone call has already worked. In the minutes when an attacker with valid credentials starts looking for something worth taking, they determine how far that search gets.

Futuristic circular hub with a glowing user silhouette at the center, representing authentication or user access. » admin by request

Where This Leaves IT Teams

The TfL case is notable for how ordinary the attackers were. Two people in their teens, working from their bedrooms, cost a critical national infrastructure operator £29 million and disrupted services that vulnerable Londoners depend on. The NCA has warned repeatedly about the growth of domestic, English-speaking cybercrime, and Scattered Spider is its clearest example.

Foster made one other point worth repeating: the convictions would likely not have been possible had TfL not engaged with law enforcement early. Service desk verification is the control most organizations should review first, because it is where these attacks begin and because it costs relatively little to strengthen. The harder and more valuable review is working out what a single compromised employee account can reach in your environment today, and how much of that access is standing rather than requested.

Admin By Request EPM removes permanent local admin rights and replaces them with just-in-time elevation, so a stolen credential arrives at an endpoint with nothing attached to it. Book a free demo or sign up for our lifetime free plan, which gives you the full feature set for up to 25 endpoints, for as long as you want.

About the Author:

Picture of Pocholo Legaspi

Pocholo Legaspi

Pocholo Legaspi is a content writer at Admin By Request, where he covers privileged access management, endpoint security, threat analysis, and the wider cybersecurity issues facing IT teams. With over a decade in content marketing and SEO and a master's in business informatics, he writes about complex security topics in a way that's clear and useful for the IT teams putting them into practice.

Share this blog to your channels:

Lifetime Free Plan for 25 Endpoints,
No Strings Attached.

Fill out the form to create your account and get started.

Book a Demo

Orange admin by request circle tick logo. » admin by request