Two members of Scattered Spider were sentenced to five years and six months each at Woolwich Crown Court on July 16, 2026, over the 2024 cyberattack on Transport for London. Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty in June. The attack cost TfL an estimated £29 million, disabled 148 systems, and forced all 27,000 employees through in-person password resets. The National Crime Agency called it the UK’s most significant cybercrime prosecution and said the arrests “severely disrupted” the group.
Who is Scattered Spider?
Scattered Spider is a loose, English-speaking cybercrime collective known for social engineering, help-desk impersonation, and SIM-swapping to breach large enterprises. It is tracked by vendors as UNC3944 and Muddled Libra and has been tied to intrusions at MGM, Caesars, and Okta customers. For the group’s structure and its place in the wider extortion ecosystem, see our threat-group catalogue.
What happened in the TfL attack?
The intrusion ran from August 31 to September 3, 2024. Attackers disabled 148 systems, disrupted Dial-a-Ride, Oyster photocards, and contactless refunds, and accessed data belonging to roughly 5,000 people, some including bank and sort-code details. TfL’s remediation was severe: every one of its 27,000 employees had to reset passwords in person because the identity systems could not be trusted remotely. Investigators estimated a full London transport outage could have cost the UK economy far more than the £29 million TfL actually spent.
Why this sentencing matters
This is the first UK conviction under Section 3ZA of the Computer Misuse Act 1990, which covers unauthorized acts that cause or create significant risk of serious damage. It sets precedent for prosecuting attacks on critical services as more than ordinary computer misuse. The NCA credited the arrests with materially degrading Scattered Spider’s ability to operate, echoing Microsoft’s assessment of the group’s decline. One defendant, Flowers, was arrested mid-attack against US healthcare providers and had acknowledged in chats that an attack “might kill some 90-year-old on life support.”
The sentencing-versus-damage debate
Not everyone reads 5.5 years as a win. Critics note the gap between the sentence and the £29 million in damage, arguing that penalties still lag the economic harm these intrusions cause. Supporters counter that the precedent, the ages of the defendants, and the disruption to an active group matter more than the raw term. Both readings are defensible. What is not in dispute is that the UK now has a template for charging service-disrupting intrusions at their true severity.
Frequently asked questions
How long were the Scattered Spider hackers sentenced?
Thalha Jubair and Owen Flowers were each sentenced to five years and six months at Woolwich Crown Court on July 16, 2026.
What was Section 3ZA of the Computer Misuse Act?
Section 3ZA covers unauthorized acts causing, or risking, serious damage to human welfare, the economy, or national security. The TfL case is its first successful use.
How much did the TfL attack cost?
Transport for London estimated the attack cost around £29 million, disabled 148 systems, and required all 27,000 employees to reset passwords in person.
Did the arrests hurt Scattered Spider?
The NCA said the arrests severely disrupted the group, and Microsoft assessed that its ability to operate was materially degraded. The collective remains loosely organized, so disruption is not the same as elimination.
Was data stolen in the TfL attack?
Yes. Roughly 5,000 people’s data was accessed, including some bank and sort-code details tied to Oyster refunds, alongside names, emails, and addresses.
