Two Men Plead Guilty in UK to Cyberattacks Targeting Transport for London and U.S. Healthcare Providers

In a significant development in the ongoing battle against cybercrime, two young men, Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, have pleaded guilty in the United Kingdom to criminal charges stemming from a devastating August 2024 cyberattack that severely disrupted the operations of Transport for London (TfL), the agency overseeing public transportation in the vast Greater London area. Their admissions of guilt, made on the first day of what was anticipated to be a six-week trial, signal a potential turning point in the prosecution of members of the prolific cybercrime syndicate known as Scattered Spider.
The charges to which Jubair and Flowers admitted include conspiring to commit unauthorized acts against TfL’s computer systems and causing a significant risk of serious damage to human welfare. The gravity of these offenses underscores the far-reaching consequences of sophisticated cyberattacks, which can extend beyond financial loss to impact essential public services and potentially endanger lives.
Beyond the TfL incident, Owen Flowers also confessed to his involvement in a conspiracy to infiltrate the computer systems of two major U.S.-based healthcare providers, SSM Health Care Corporation and Sutter Health, in September 2024. This dual confession highlights the international scope of Scattered Spider’s operations and the diverse range of critical infrastructure they have targeted.
A Pattern of Devastating Attacks
The guilty pleas of Jubair and Flowers come after a series of high-profile incidents linked to Scattered Spider, a group notorious for its aggressive ransomware tactics and its ability to exploit vulnerabilities in corporate and governmental systems. The group has been implicated in numerous attacks across the globe, extorting millions of dollars from its victims and causing widespread disruption.
Timeline of Key Scattered Spider Incidents and Prosecutions:
- May 2022 – September 2025: U.S. prosecutors allege that Thalha Jubair and other Scattered Spider members engaged in computer fraud, wire fraud, and money laundering through 120 network intrusions targeting 47 U.S. entities. These attacks are reported to have yielded at least $115 million in ransom payments.
- Summer 2022: A mass SMS phishing campaign, allegedly involving Jubair and other Scattered Spider members, compromised single sign-on credentials for employees at hundreds of companies. This campaign led to data breaches and intrusions at prominent organizations such as LastPass, DoorDash, Mailchimp, Plex, and Signal.
- September 2023: Scattered Spider’s ransomware attacks crippled operations at major Las Vegas casinos operated by MGM Resorts and Caesars Entertainment. Owen Flowers was reportedly the individual who anonymously provided interviews to the media in the aftermath of these attacks, offering insights into the group’s methods.
- July 2025: The UK National Crime Agency (NCA) arrested Flowers and Jubair in connection with Scattered Spider’s ransomware attacks against prominent British retailers, including Marks & Spencer, Harrods, and the Co-op Group.
- September 2025: Prosecutors in New Jersey unsealed an indictment against Thalha Jubair, detailing his alleged role in widespread cybercriminal activities, including the aforementioned 120 network intrusions.
- April 2026: Tyler Buchanan, a 24-year-old British national and identified Scattered Spider member, pleaded guilty in the U.S. to wire fraud conspiracy and aggravated identity theft charges related to the 2022 SMS phishing spree. The government stated that Buchanan, Jubair, and others stole at least $8 million in cryptocurrency using credentials obtained from this campaign. Buchanan is scheduled for sentencing on October 2.
- August 2025: Noah Michael Urban, a 20-year-old Scattered Spider member from Florida, was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy charges.
- August 2024: The cyberattack that crippled Transport for London occurred, leading to the eventual guilty pleas of Jubair and Flowers.
- Present Day (June 2026 context): Jubair and Flowers have pleaded guilty in the UK.
The Sophistication of Scattered Spider’s Operations
The investigation into Scattered Spider has revealed a sophisticated and multi-faceted criminal enterprise. According to prosecutors, Thalha Jubair played a key role in managing a busy Telegram channel named "Star Chat." This channel served as a hub for a SIM-swapping group that employed voice and SMS-based phishing tactics to pilfer credentials from employees of major wireless providers in both the U.S. and the UK.
SIM swapping is a malicious technique where cybercriminals trick mobile carriers into transferring a victim’s phone number to a SIM card controlled by the attacker. This allows them to intercept calls and text messages, including crucial one-time passcodes (OTPs) used for multi-factor authentication. By gaining access to these OTPs, attackers can bypass security measures and gain unauthorized access to sensitive accounts, including financial and email services.

U.S. prosecutors have also linked Jubair to other illicit activities under various hacker handles, including "Rocket Ace." A receipt from "Star Fraud Chat" targeting a T-Mobile customer, obtained by KrebsOnSecurity, illustrates how the group leveraged access to internal T-Mobile employee tools to facilitate SIM-swapping services.
Furthermore, the New Jersey indictment alleges Jubair’s involvement in a large-scale SMS phishing campaign during the summer of 2022. This campaign, which targeted employees across hundreds of companies, successfully stole single sign-on credentials, paving the way for widespread data breaches and intrusions.
Even at a young age, Jubair was reportedly involved in cybercriminal activities. KrebsOnSecurity reported last year that at age 15, one of Jubair’s aliases was "Everlynn," a hacker who issued fraudulent "emergency data requests." These requests, often using compromised law enforcement or government email addresses, impersonated urgent matters of life and death to compel major tech companies into divulging subscriber data without a court order.
Broader Implications and the Fight Against Cybercrime
The guilty pleas of Jubair and Flowers represent a significant victory for law enforcement agencies in both the UK and the U.S. The successful prosecution of individuals linked to Scattered Spider sends a clear message to cybercriminals that their actions will not go unpunished.
The impact of the TfL cyberattack, while not fully detailed in the public domain, would have undoubtedly caused considerable disruption to London’s vital public transport system. Such disruptions can have cascading effects, impacting commuter schedules, affecting businesses reliant on public transit, and potentially hindering emergency services. The charge of "causing risk of serious damage to human welfare" highlights the potentially life-threatening consequences of attacks on critical infrastructure.
The U.S. Department of Justice continues to pursue charges against other alleged Scattered Spider members. Three defendants indicted alongside Tyler Buchanan still face charges: Ahmed Hossam Eldin Elbadawy, 24, of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans, 26, of Jacksonville, North Carolina. The ongoing pursuit of these individuals underscores a sustained commitment to dismantling the entire Scattered Spider network.
The sentencing of Flowers and Jubair is scheduled for July 15, 2026, at a London court. The outcomes of these sentencing hearings will likely provide further insights into the judiciary’s approach to cybercrime and the penalties deemed appropriate for such offenses.
The continued success in prosecuting members of groups like Scattered Spider is crucial for maintaining public trust in digital infrastructure and for safeguarding critical services. The evolving nature of cyber threats necessitates constant vigilance, international cooperation, and robust legal frameworks to ensure that perpetrators of these sophisticated crimes are brought to justice. The cases of Jubair and Flowers serve as a stark reminder of the pervasive threat posed by cybercrime and the significant efforts being made to combat it on a global scale.






