2 Young Hackers Jailed for Disrupting London Underground | #cybercrime | #infosec


Cybercrime
,
Fraud Management & Cybercrime
,
Geo Focus: The United Kingdom

Police Say Arrests ‘Effectively Halted’ Scattered Spider Cybercrime Collective

Pictured from left: Owen Flowers and Thalha Jubair (Image: National Crime Agency)

Two leaders of the Scattered Spider hacking group each received 66-month jail sentences in the culmination of Britain’s biggest cybercrime case to date.

See Also: Does Office 365 Deliver The Email Security and Resilience Enterprises Need?

Thalha Jubair, 20, from East London, and Owen Flowers, 18, from England’s West Midlands, last month pleaded guilty to violating British anti-hacking law in 2024 when they disrupted the transport authority of London’s payment system.

The pair’s attack ran from Aug. 31, 2024, through Sept. 3, 2024, although Transport for London – which runs the London subway and bus systems – has said the hack’s effects lingered for months.

Jubair and Flowers changed their not-guilty pleas under Britain’s Computer Misuse Act on June 22, on what was set to be the first day of a six-week trial at Woolwich Crown Court in London (see: 2 British Men Plead Guilty to Transport for London Hacks).

At the conclusion of a two-day sentencing hearing on Thursday, Flowers and Jubair were each sentenced to five years and six months of imprisonment.

Judge Justice Turner told the defendants that despite their youth and neurodiversity, as well as being “primarily motivated by selfish bravado,” their crimes were “so serious that I have no alternative but to pass a sentence of immediate custody,” Sky News reported.

The judge added: “The sentence I will pass is the lowest, which is consistent with adequately reflecting your criminality.”

Police celebrated the disruption of a major, homegrown hacking group. “Scattered Spider has been the most significant cybercrime threat to the U.K. in recent years. Through this investigation, we have severely disrupted that threat and brought key offenders to justice,” said Deputy Director Paul Foster, head of the National Cyber Crime Unit.

This appears to be only the second case in U.K. history – and the first to succeed – involving a prosecution under the Computer Misuse Act Section 3ZA, which “is the most serious section as it applies where the unauthorized act causes or creates a significant risk of serious damage, and the person intends or is reckless as to that damage,” the NCA said.

Transport for London runs the capital city’s Underground, as well as multiple railways, trams, buses and riverboats. The transport authority said the attack cost it $38 million in losses and recovery costs and left it temporarily unable to process payments for the Oyster public transport payment smartcard and degraded Dial-a-Ride public transport service for wheelchair users and others with disabilities.

Prosecutors told the court the hackers stole data of 7 million Oyster card users.

The pair’s disruptions led to all 28,000 Transport for London employees being required to attend the organization’s headquarters office to reset their passwords.

Western Adolescent Hackers

Scattered Spider is one of a number of English-speaking cyberattack groups to emerge from the anarchic cybercrime collective known as The Com, which has been tied not just to hack attacks but also sextortion attacks against minors and swatting (see: What’s in a Name? The Quest to Understand Scattered Spider).

At least in its current incarnation, Scattered Spider appears to be no more.

“Although other cybercriminals may continue to use the damaged Scattered Spider brand, the NCA’s action against Jubair and Flowers effectively halted the group’s criminal activity. Independent assessment supports this, with Microsoft confirming that the arrests materially degraded the group’s ability to continue conducting cybercriminal operations,” the NCA said (see: Scattered Spider Suspect Extradited From Finland to US).

Cybercrime chatter further supports the assessment that Scattered Spider is done. “That group has been dismantled and is gone now. Nobody from that group remains,” a ShinyHunters spokesperson recently told ISMG.

At the same time, many other loosely knit groups – some springing from the Com, others not – filled with native English-speaking hacking enthusiasts continue to operate like Scattered Spider, meaning not in the model of a traditional criminal gang, said Xabier Eizaguirre, a threat intelligence analyst at cybersecurity firm Group-IB.

“Think of it more like Anonymous – a movement, not an organization. It’s made up of entirely independent clusters of individuals who share a common playbook but operate separately, with no central leadership and in many cases no awareness of each other’s existence,” Eizaguirre said.

Authorities Seek New Powers

How to effectively combat the rise of young hackers, including repeat offenders, is an ongoing challenge.

Jamie MacColl, a senior research fellow in cyber and tech at British think tank Royal United Services Institute, said in a post to LinkedIn that one takeaway from Jubair and Flowers’ sentencing is “the complete failure of the U.K. system – policing, social care, schools, etc. – to effectively intervene in the early stages of their offending.”

The NCA and City of London Police arrested Jubair and Flowers at their home addresses on Sept. 16, 2025. Police said they later rearrested Flowers for breaching his bail conditions by failing to comply with restrictions on his use of computer devices. He still faces charges in the United States tied to alleged ransomware offenses, for which he remains on bail.

Jubair, the older of the pair, wasn’t a first-time offender. “Before the TfL conviction, Jubair had been convicted of 22 offences as a teenager, including 13 counts of fraud, two of unauthorized access to a computer, one of obtaining access to a computer and one of blackmail. He had also been convicted in a youth court of stalking two young women and hacking into a City of London police server,” The Guardian reported.

The government is pursuing new powers to combat young hackers, in the form of Cyber Crime Risk Orders, announced in the King’s Speech in May. These are designed to facilitate better monitoring of suspects, including when individuals first start offending or are on bail, and to give police more power to intervene.

Commander Ollie Shaw at City of London Police said the orders would be tailored to individuals, “could include limits on devices, online services or technologies that are often used to commit cybercrime,” and regularly reviewed by courts.

“The aim is not just to punish offenders, but also to help them rebuild their lives and use technology safely and legally – as the vast majority of people already do,” Shaw said.

RUSI’s MacColl said orders might help tackle a part of the young, cybercrime-curious population, but he sees a gap “for an important segment of teenagers already offending or at risk of offending” who need stronger forms of intervention.

What might also be needed is something akin to the country’s counterterrorism program Prevent, which focuses on providing early support to vulnerable people at risk of being radicalized, as well as to help de-radicalize individuals already engaged in some activities and combat the ideological causes of terrorism, MacColl said.

MacColl said this type of more focused de-radicalization effort might be better suited for rehabilitating many young cybercriminals, “particularly for individuals involved in The Com-type online spaces, which are driven by misogyny and sociopolitical dynamics more than the desire to make money.”





Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW