Close Menu
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) Instagram Threads
Ransomnews
  • Home
  • News
  • Security
  • Privacy
  • Cybercrime
    • Threat Groups
    • Ransomware
    • Explainers
    • Stealer Logs
  • AI
  • OSINT
  • Tools
    • Ransomtracker
    • Stealercheck
    • FortiBleed Checker
  • About Us
Facebook X (Twitter) LinkedIn
Ransomnews
Cybercrime

Scattered Spider duo jailed 5.5 years over £29M TfL hack

Ransomnews Research TeamBy Ransomnews Research TeamJuly 16, 2026Updated:July 18, 2026No Comments4 Mins Read72 Views
Share Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Scattered Spider duo jailed 5.5 years over TfL hack, ransomnews.com
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Two members of Scattered Spider were sentenced to five years and six months each at Woolwich Crown Court on July 16, 2026, over the 2024 cyberattack on Transport for London. Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty in June. The attack cost TfL an estimated £29 million, disabled 148 systems, and forced all 27,000 employees through in-person password resets. The National Crime Agency called it the UK’s most significant cybercrime prosecution and said the arrests “severely disrupted” the group.

// KEY FACTS

Threat actor
Scattered Spider
Victim
Transport for London · Public transport / government · United Kingdom
Timeline
Attack: 2024-08-31  ·  Disclosed: 2026-07-16
Data claimed
~5,000 people's data accessed, some with bank/sort-code details · Names, emails, home addresses, Oyster refund banking details
Ransom status
N/A; criminal prosecution and sentencing
Verification
Confirmed via guilty pleas and Woolwich Crown Court sentencing

Who is Scattered Spider?

Scattered Spider is a loose, English-speaking cybercrime collective known for social engineering, help-desk impersonation, and SIM-swapping to breach large enterprises. It is tracked by vendors as UNC3944 and Muddled Libra and has been tied to intrusions at MGM, Caesars, and Okta customers. For the group’s structure and its place in the wider extortion ecosystem, see our threat-group catalogue.

What happened in the TfL attack?

The intrusion ran from August 31 to September 3, 2024. Attackers disabled 148 systems, disrupted Dial-a-Ride, Oyster photocards, and contactless refunds, and accessed data belonging to roughly 5,000 people, some including bank and sort-code details. TfL’s remediation was severe: every one of its 27,000 employees had to reset passwords in person because the identity systems could not be trusted remotely. Investigators estimated a full London transport outage could have cost the UK economy far more than the £29 million TfL actually spent.

TfL ATTACK // BY THE NUMBERS £29M cost to TfL 148 systems disabled 27,000 in-person resets 5.5 yrs each, sentenced FIRST UK CONVICTION UNDER COMPUTER MISUSE ACT SECTION 3ZA Section 3ZA: unauthorised acts causing, or risking, serious damage Attack window: Aug 31 – Sep 3, 2024 | Guilty pleas: June 2026 Defendants aged 18 and 20 | NCA: group operations “severely disrupted”

Why this sentencing matters

This is the first UK conviction under Section 3ZA of the Computer Misuse Act 1990, which covers unauthorized acts that cause or create significant risk of serious damage. It sets precedent for prosecuting attacks on critical services as more than ordinary computer misuse. The NCA credited the arrests with materially degrading Scattered Spider’s ability to operate, echoing Microsoft’s assessment of the group’s decline. One defendant, Flowers, was arrested mid-attack against US healthcare providers and had acknowledged in chats that an attack “might kill some 90-year-old on life support.”

The sentencing-versus-damage debate

Not everyone reads 5.5 years as a win. Critics note the gap between the sentence and the £29 million in damage, arguing that penalties still lag the economic harm these intrusions cause. Supporters counter that the precedent, the ages of the defendants, and the disruption to an active group matter more than the raw term. Both readings are defensible. What is not in dispute is that the UK now has a template for charging service-disrupting intrusions at their true severity.

Frequently asked questions

How long were the Scattered Spider hackers sentenced?

Thalha Jubair and Owen Flowers were each sentenced to five years and six months at Woolwich Crown Court on July 16, 2026.

What was Section 3ZA of the Computer Misuse Act?

Section 3ZA covers unauthorized acts causing, or risking, serious damage to human welfare, the economy, or national security. The TfL case is its first successful use.

How much did the TfL attack cost?

Transport for London estimated the attack cost around £29 million, disabled 148 systems, and required all 27,000 employees to reset passwords in person.

Did the arrests hurt Scattered Spider?

The NCA said the arrests severely disrupted the group, and Microsoft assessed that its ability to operate was materially degraded. The collective remains loosely organized, so disruption is not the same as elimination.

Was data stolen in the TfL attack?

Yes. Roughly 5,000 people’s data was accessed, including some bank and sort-code details tied to Oyster refunds, alongside names, emails, and addresses.

Sources and further reading

  • The Hacker News: Two Scattered Spider hackers get 5.5 years (July 16, 2026)
  • TechCrunch: UK cops say arrests disrupted the group (July 16, 2026)
  • Help Net Security: Prison time for TfL cyberattack (July 16, 2026)
  • Ransomnews threat-group catalogue
Share. Facebook Twitter Pinterest LinkedIn Tumblr Telegram Email Copy Link
Previous ArticleWorld Leaks dumps 19,000 files tied to India nuclear plant
Next Article Deutsche Bank breached via supplier as Unsafe gang leaks data
Ransomnews Research Team

The Ransomnews Research Team is the collective byline used for collaborative pieces, editorial briefings, and articles drawing on contributions from multiple researchers. Coverage spans ransomware operations, breach economics, threat actor profiling, OSINT methodology, and emerging risks across security, privacy, and AI.

Related Posts

Deadlock: ransomware that hides its C2 on the blockchain

July 18, 2026

Clover Health discloses social-engineering breach in 8-K

July 18, 2026

DragonForce: the cartel that absorbed its rivals

July 17, 2026

Comments are closed.

Facebook X (Twitter) LinkedIn
© 2026 Ransomnews.com

Type above and press Enter to search. Press Esc to cancel.

Cookies on Ransomnews

We use strictly-necessary cookies to run the site and may use first-party analytics to understand which articles are read. Some pages contain affiliate links — when you click one, the affiliate network sets cookies on the merchant's domain to attribute the referral. See the Cookie Policy and Affiliate Disclosure for detail.

RANSOMNEWS.COM

Tracking the criminal infrastructure of the internet.

Independent coverage of ransomware, breach economics, threat actors, privacy, AI security, and the open-source investigation toolkit.

// Topics

  • News
  • Security
  • Privacy
  • Cybercrime
  • AI
  • OSINT
  • Threat Groups
  • Stealer Logs
  • Ransomtracker
  • Stealercheck
  • FortiBleed Checker

// Site

  • About Us
  • Editorial Team
  • Contact
  • Tip Line
  • Editorial

// Legal

  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Funding & Independence
  • RSS Feed
© 2026 Ransomnews.com · Tracking the criminal infrastructure of the internet.