Scattered Spider Members Plead Guilty to Transport for London Cyberattack and Global Hacking Campaign

The landscape of international cybercrime faced a significant reckoning this week as two pivotal members of the notorious hacking collective known as Scattered Spider entered guilty pleas in a United Kingdom court. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, admitted to a series of devastating cyberattacks, most notably the August 2024 breach of Transport for London (TfL), the government body responsible for the vast majority of the capital’s transport network. The pleas, entered on the first day of what was anticipated to be a grueling six-week trial, mark a watershed moment for the National Crime Agency (NCA) and its international partners in their multi-year campaign to dismantle one of the world’s most aggressive social engineering syndicates.
The charges against Jubair and Flowers involve conspiring to commit unauthorized acts against TfL’s computer systems and, crucially, causing a risk of serious damage to human welfare. The August 2024 attack on TfL was not merely a data breach; it crippled internal systems, disrupted customer-facing applications, and forced the temporary suspension of certain Oyster card and contactless payment functionalities. Beyond the logistics of the transport network, Flowers alone admitted to a separate conspiracy targeting the United States healthcare sector, specifically SSM Health Care Corporation and Sutter Health, in September 2024. These admissions highlight the group’s lack of regional or sectoral boundaries, moving from metropolitan infrastructure to critical life-saving institutions with clinical efficiency.
The Rise of Scattered Spider and the Mechanics of Social Engineering
Scattered Spider, also identified by security researchers as UNC3944, Muddled Libra, and Star Fraud, has earned a reputation as a uniquely dangerous threat actor. Unlike traditional ransomware groups that rely heavily on sophisticated malware or technical exploits, Scattered Spider specializes in high-pressure social engineering. The group, largely composed of young, English-speaking individuals, excels at "vishing" (voice phishing) and SMS-based phishing to deceive corporate help desks and IT administrators.
By posing as employees or technical support staff, members of Scattered Spider frequently bypass multi-factor authentication (MFA) by tricking victims into sharing one-time passcodes or approving push notifications. Once inside a network, they move laterally with speed, escalating privileges and exfiltrating data for extortion purposes. The group’s activities gained global infamy in September 2023 following the high-profile attacks on Las Vegas casino giants MGM Resorts and Caesars Entertainment. While Caesars reportedly paid a multi-million dollar ransom to maintain operations, MGM resisted, resulting in a week-long shutdown of hotel systems, slot machines, and digital keys that cost the company an estimated $100 million in lost revenue.
Evidence presented by prosecutors suggests that Owen Flowers was a central figure in these events. Sources familiar with the investigation identified Flowers as the individual who provided anonymous media interviews following the casino attacks, taunting security researchers and detailing the group’s ease of access into supposedly secure corporate environments.
The Star Chat Operation and SIM-Swapping Infrastructure
While the TfL attack represented a direct hit on UK infrastructure, the scope of the group’s operations was truly global. Thalha Jubair is alleged to have co-managed a Telegram channel titled "Star Chat," which served as a central hub for a sophisticated SIM-swapping operation. SIM-swapping involves tricking mobile carrier employees into transferring a victim’s phone number to a SIM card controlled by the attacker. This allows the hacker to intercept phone calls and text messages, effectively neutralizing SMS-based MFA and granting access to bank accounts, cryptocurrency wallets, and corporate logins.
According to U.S. federal prosecutors, Jubair operated under several hacker handles, including "Rocket Ace." Through Star Chat, the group offered SIM-swapping services to other criminals, utilizing credentials stolen from employees at major wireless providers in both the U.S. and the U.K. A receipt recovered during the investigation showed a successful swap of a T-Mobile customer’s number after the group gained access to internal employee tools.
Furthermore, Jubair’s criminal history stretches back to his mid-teens. Under the alias "Everlynn," a then-15-year-old Jubair allegedly sold fraudulent "Emergency Data Requests" (EDRs). This technique involves using compromised police or government email accounts to send urgent requests to tech giants like Apple, Google, and Meta. These requests claim a situation involves an immediate threat to life, bypass legal review processes, and demand the immediate release of subscriber data such as IP addresses and private messages.
A Chronology of Global Intrusion: 2022 to 2025
The legal proceedings in London are part of a broader timeline of criminal activity and subsequent law enforcement intervention. The group’s most prolific period began in the summer of 2022 with a massive SMS phishing campaign. This operation targeted employees at hundreds of companies, leading to successful intrusions at over 130 organizations. Notable victims included password manager LastPass, food delivery service DoorDash, and communication platforms like Mailchimp, Plex, and Signal.

The 2022 campaign laid the groundwork for the group’s financial success. By harvesting single sign-on (SSO) credentials, the group managed to steal at least $8 million in cryptocurrency from individual and corporate victims across the United States. This period of high-volume attacks eventually led to the identification of several key members:
- August 2025: Noah Michael Urban, a 20-year-old member from Florida, was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy.
- April 2026: Tyler "Tylerb" Buchanan, a 24-year-old British national, pleaded guilty to wire fraud conspiracy and aggravated identity theft. He is scheduled for sentencing in October 2026.
- September 2025: A New Jersey grand jury unsealed an indictment against Thalha Jubair and several others, alleging 120 network intrusions involving 47 U.S. entities between 2022 and 2025. The indictment claims the group’s victims collectively paid over $115 million in ransom payments.
The arrest of Flowers and Jubair in July 2025 followed a coordinated effort between the NCA and the FBI, which also linked the duo to ransomware attacks against major British retailers, including Marks & Spencer, Harrods, and the Co-op Group.
Official Responses and Impact on Critical Infrastructure
The guilty pleas have drawn responses from law enforcement and cybersecurity experts, who view the conviction of such young but high-impact offenders as a warning to the burgeoning "com" (a community of young hackers focused on social engineering). A spokesperson for the National Crime Agency emphasized that the attack on Transport for London was a direct assault on the functionality of the city, stating that the group’s actions showed a "callous disregard for public safety and the essential services that millions of Londoners rely upon."
Transport for London has spent the months following the August 2024 attack fortifying its digital defenses. The breach necessitated a complete reset of thousands of employee passwords and a massive audit of third-party vendor access. While TfL has not publicly disclosed the total financial cost of the recovery, industry analysts suggest that the remediation of such a large-scale infrastructure breach likely reaches into the tens of millions of pounds.
The U.S. Department of Justice continues to pursue other alleged members of the syndicate. Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans remain under indictment, facing charges related to the same phishing and money laundering schemes that Jubair and Flowers have now admitted to participating in.
Broader Implications for Cybersecurity
The case of Scattered Spider highlights a shift in the threat landscape. The group’s success demonstrates that human psychology remains the weakest link in the security chain. Even organizations with multi-billion dollar security budgets, such as MGM Resorts, proved vulnerable to a well-spoken teenager with a convincing script.
The guilty pleas of Flowers and Jubair also underscore the increasing "professionalization" of youth-driven cybercrime. The use of Telegram for "crime-as-a-service" (CaaS), the monetization of SIM-swapping, and the exploitation of emergency legal frameworks like EDRs suggest a level of organizational maturity that belies the ages of the defendants.
For the cybersecurity industry, the Scattered Spider saga has accelerated the move toward "phishing-resistant" MFA, such as hardware security keys (FIDO2/WebAuthn), which cannot be easily bypassed through social engineering or intercepted via SIM-swapping. It has also prompted a re-evaluation of how telecommunications companies verify the identity of their employees and customers.
Thalha Jubair and Owen Flowers are currently in custody and are slated to be sentenced in a London court on July 15, 2026. Given the severity of the charges—particularly those involving the risk to human welfare and the scale of the financial theft—legal experts anticipate significant custodial sentences. Additionally, Jubair faces the prospect of extradition to the United States to answer for the New Jersey indictment, ensuring that the legal ramifications for his role in the Scattered Spider syndicate will persist for years to come.







