Scattered Spider Hackers Get Bail 5.5 Years for the £29M TfL Breach

Contents

Two teenagers behind one of the UK’s most disruptive cyberattacks were undone by a food delivery order — and became the second people ever convicted under Britain’s most serious hacking law.

5.5 yrseach, Woolwich Crown Court

£29Min losses & recovery costs

2nd everSection 3ZA conviction

On 16 July 2026, a judge at Woolwich Crown Court handed down sentences that authorities are calling the conclusion of the largest cybercrime prosecution ever brought before a UK court. Thalha Jubair, 20, and Owen Flowers, 18 — described as leading members of the hacking collective Scattered Spider — were each sentenced to five years and six months in prison for the 2024 attack on Transport for London.

Both had pleaded guilty in June 2026, on the day their trial was due to start, and received a 15 percent reduction in sentence for the plea. The charge was Section 3ZA of the UK’s Computer Misuse Act 1990 — reserved for unauthorised computer activity that causes, or creates a significant risk of, serious damage, where the offender intends the harm or is reckless as to whether it occurs. Flowers and Jubair admitted the offence on the basis of recklessness, meaning they did not need to be shown to have intended the disruption that followed.

What actually happened to TfL

The pair gained unauthorised access to TfL’s systems between 31 August and 3 September 2024, reportedly after impersonating an employee and socially engineering the transport authority’s IT helpdesk — a hallmark Scattered Spider technique. The fallout was significant: 148 TfL systems were knocked offline, and the authority had to bring roughly 27,000 to 28,000 employees into the office in person just to reset their passwords, since the usual remote process was no longer trustworthy.

Services disruptedOyster refunds, Dial a Ride, and online account access — though trains and buses kept running
Data exposedCustomer names, addresses, and contact details, disclosed by TfL on 12 September 2024

The financial toll is put at £29 million in direct losses and recovery costs by both the NCA and the Crown Prosecution Service, though estimates elsewhere have ranged as high as £39 million. Officials went further, estimating that if the group had succeeded in fully shutting down the transport network, the wider knock-on cost to the UK economy could have run as high as £56 billion.

How a takeaway order ended it

The investigation’s break came from an unglamorous source. Jubair had used a cryptocurrency wallet — the same one hosting tens of millions of dollars in Bitcoin collected from ransom payments — to buy food delivery gift vouchers. That transaction left a digital trail investigators could follow directly back to his address in Bow, East London.

reconstructed breadcrumb trail

$ wallet.tx –history btc_ransom_pool

→ inbound: ransom proceeds, multiple victims, 2023–2024

$ wallet.tx –outbound –recent

→ outbound: food delivery gift voucher purchase

$ trace –merchant-record –address

→ delivery address linked: Bow, East London

$ nca.action –execute

→ suspects arrested, 16 Sep 2024

Both were arrested at their homes just four days after TfL disclosed the breach. At the time of Flowers’ arrest, investigators reportedly found evidence on his devices that he was also in the process of hacking two US healthcare organisations, Sutter Health and SSM Health Care Corporation.

Why the legal precedent matters

Section 3ZA has been used only twice since it entered force. The first case involved a former GCHQ intern jailed for six years in a national security matter; the NCA has said there is no connection between that case and the TfL attack. Prosecutors and the CPS have described Jubair and Flowers as the first hackers successfully prosecuted specifically under this provision.

“This is the largest cybercrime prosecution ever brought before the UK courts.”

— Paul Foster, Deputy Director, NCA National Cyber Crime Unit, on the significance of the case.

Sentencing, Mr Justice Turner reportedly weighed both defendants’ youth and immaturity against the sophistication of the offending, the scale of harm to TfL, the planning involved, and the fact that both understood the criminality of what they were doing.

Does this actually stop Scattered Spider?

The NCA’s position is that removing Jubair and Flowers has done real damage to the group’s operating capacity — a claim it says is backed by an independent assessment from Microsoft, which found the arrests materially degraded the collective’s ability to keep running cybercriminal operations. At the same time, the agency acknowledges that other criminals may keep using the “Scattered Spider” name even without these two involved, since it functions more as a loose brand than a fixed membership.

City of London Police used the sentencing to push for a power it doesn’t currently have: so-called Cyber Crime Risk Orders, which would let courts restrict a convicted offender’s devices, online services, and technology access in proportion to the risk they pose — pitched by one commander as a kind of “digital prison.” For now, that tool doesn’t exist, and the only lever available was a conventional prison sentence — handed to two people who were 17 and 18 years old when they carried out the attack.

The bigger pattern: kids doing serious damage

Officials have repeatedly flagged the youth of those involved as part of a wider trend. NCA data from a 2024 survey found that one in five UK children aged 10 to 16 admitted to behaviour that breaches the Computer Misuse Act, a figure that rose to one in four among children who game online. Whether that reflects easier access to hacking tools and communities, weak deterrence, or something else, the TfL case puts a concrete cost on what that pipeline can produce: a national transport authority knocked partly offline, tens of millions of pounds in damage, and two defendants who were legally minors when they did it.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *