Two men in the United Kingdom have pleaded guilty to criminal charges stemming from an August 2024 cyberattack that crippled Transport for London , the agency responsible for the public transport network in Greater London. The duo were key members of a notorious cybercrime group called Scattered Spider , and their guilty pleas came on the first day of a trial expected to last six weeks.

Scattered Spider: Who are the two defendants and what did they do?
Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, admitted conspiring to commit unauthorised acts against computer systems . According to a report from the BBC, Flowers himself admitted taking part in a conspiracy to hack healthcare providers in the US, including SSM Health Care Corporation and Sutter Health, in September 2024.
See also: Are Scattered Spider hackers behind the attack on Marks & Spencer?
Jubair was also wanted by U.S. law enforcement. In September 2025, prosecutors in New Jersey unsealed an indictmentalleging that Jubair and other members of Scattered Spider committed computer fraud, wire fraud, and money laundering in connection with 120 computer network intrusions at 47 entities in the U.S. The attacks took place between May 2022 and September 2025, and victims paid at least $115 million in ransom.
In July 2025, KrebsOnSecurity reported that Flowers and Jubair were arrested in the United Kingdom in connection with Scattered Spider on retailers Marks & Spencer and Harrods and British food retailer Co-op Group. Multiple sources familiar with these investigations also said that Flowers was the Scattered Spider member who anonymously gave media interviews in the days following the September 2023 attacks, which disrupted operations at Las Vegas casinos operated by MGM Resorts and Caesars Entertainment.
See also: Member of Scattered Spider hackers arrested

According to prosecutors, Jubair co-managed a popular Telegram channel called Star Chat, which was home to a group SIM-swapping that used voice and SMS phishing attacks to steal credentials from employees of major wireless carriers in the U.S. and the U.K.The group then used that access to sell a service that could redirect a target’s phone number to a device controlled by the attackers. The attackers could intercept the victim’s calls and text messages, including one-time codes for multi-factor authentication.
New Jersey prosecutors also allege that Jubair was involved in a massive SMSin the summer of 2022 that stole single sign-on credentials from employees at hundreds of companies. This weeks-long phishing campaign led to hacks and data theft at more than 130 organizations, including LastPass, DoorDash, Mailchimp, Plex and Signal.
See also: Scattered Spider hackers collaborate with RansomHub

The case of the two young members of Scattered Spider highlights in the most characteristic way the ever-growing threat of organized cybercrime and the serious impact it can have on critical infrastructure, businesses and public organizations. Their attacks proved that even large organizations with advanced security systems can be faced with highly sophisticated and coordinated cyberattacks.
At the same time, the case highlights the need for strengthening cybersecurity mechanisms, investments in human resource training and closer international cooperation between law enforcement authorities. In a digital environment where cyber threats are constantly evolving, their prevention and timely response are now critical priorities for the protection of society and the economy.
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
