Vishing Call Brought Down TfL: Scattered Spider Duo Jailed in Record UK Prosecution | #cybercrime | #infosec


A phone call to a helpdesk worker broke open one of the largest public transport networks in the world.

Two members of the Scattered Spider cybercrime collective — Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London — were each sentenced to five years and six months in prison at Woolwich Crown Court on Thursday, July 16, 2026, for a 2024 attack on Transport for London that disabled 148 systems, forced 27,000 employees to reset their passwords in person, and exposed the personal data of an estimated 10 million passengers. The National Crime Agency called it the largest cybercrime prosecution ever brought before UK courts.

They did not use a zero-day exploit. There was no sophisticated nation-state malware. Flowers and Jubair purchased partial TfL employee credentials from criminal forums, then called the IT helpdesk and impersonated a TfL employee to convince a worker to reset an account password and bypass two-factor authentication. That phone call was the entire entry point. Every subsequent harm — the 148 downed systems, the £29 million in losses and recovery costs, the personal records of millions of Londoners in criminal hands — traces back to a single helpdesk procedural failure.

How a Helpdesk Call Bypassed 2FA on 148 Systems

The attack ran from August 31 to September 3, 2024, across a network that handles roughly nine million journeys a day.

The kill chain was methodical. First, the pair bought previously leaked employee login data from dark web credential marketplaces, giving them enough detail to pass as a legitimate TfL employee. Then came the call. Using the stolen credentials as social proof, one of them phoned TfL’s IT helpdesk and talked a worker into resetting the account password. The 2FA protection on the account — the second layer of security that should have stopped an attacker who only had a password — was neutralized not by cracking it but by convincing a human being to issue a new credential.

That is the structural lesson the TfL case forces into the open: multi-factor authentication is only as strong as the procedure governing who can get a new factor issued. A helpdesk that will reset MFA devices after a phone call from an unverified caller is not an MFA-protected system. It is a system with an exploitable human bypass. CISA’s advisory on Scattered Spider’s tactics names exactly this gap: the group’s primary playbook is “push bombing” and “SIM swap attacks” to bypass MFA, but the TfL entry was simpler — a direct call to human customer service.

Once inside, Flowers and Jubair escalated their privileges and moved laterally through TfL’s internal network. They communicated in real time over Telegram while sharing an online workspace. Flowers recorded video of Jubair navigating TfL’s systems during the attack — footage investigators later found on his laptop.

What the Attack Shut Down

The consequences for ordinary Londoners were immediate and sustained. Dial-a-Ride — the booking service that provides transport to vulnerable Londoners with mobility difficulties — went offline. The digital payments channel failed. Applications for Oyster photocards, the discounted travel cards issued to London’s children and young people, were suspended. The rollout of contactless ticketing on additional routes was delayed. Refund processing slowed to a crawl.

All 27,000 TfL employees were recalled in person to reset their passwords — a logistical disruption that itself took weeks to work through.

Personal data was accessed: names, email addresses, and home addresses where TfL held them. Oyster refund data was also reached, including bank account numbers and sort codes for approximately 5,000 customers.

The full scale of the breach only emerged later. In March 2026, reporting from Computer Weekly and the BBC revealed that a stolen copy of TfL’s customer database contained the names, email addresses, mobile and home phone numbers, and physical addresses of an estimated 10 million people — making it one of the largest data thefts in British history. TfL confirmed it had emailed approximately 7.1 million customers whose addresses were registered on the system, but the database itself was larger. That data is still circulating, according to ESET security researcher Jake Moore, who warned that the 10 million records amount to “a treasure trove that is never deleted” and predicted the data will continue to be traded and exploited by criminals for years.

TfL avoided a far worse outcome only because it took its own network down to contain the attackers before they could execute what court documents describe as their apparent plan: wiping access on the way out. The NCA put the potential cost of a successful full shutdown of the TfL network at up to £56 billion to the UK economy.

UK’s First Confirmed Conviction Under Section 3ZA

The charge Flowers and Jubair pleaded guilty to is the most significant aspect of the case for UK cybercrime law.

Section 3ZA of the Computer Misuse Act 1990 is the statute’s most serious provision, reserved for cases where an unauthorized act causes or creates a significant risk of serious damage to human welfare, the economy, the environment, or national security. It was inserted into the Act by the Serious Crime Act 2015 — a specific amendment designed to address high-impact cyberattacks on critical infrastructure. The maximum sentence is 14 years, rising to life imprisonment if the offense causes or risks serious damage to human welfare or national security.

The Crown Prosecution Service says Flowers and Jubair are the first defendants to be successfully convicted under Section 3ZA. The NCA counts this as only the second prosecution of its kind — the two readings reflect a distinction between cases brought and cases concluded in conviction, which neither agency fully explained Thursday.

Both defendants pleaded guilty on June 22, 2026, the first day of what was scheduled to be a six-week trial. The guilty plea earned both a 15 percent reduction in their sentences from what the judge would otherwise have imposed.

Sentencing judge Mr Justice Turner acknowledged both defendants’ youth and neurodiversity but was clear about the gravity of the conduct. He cited the sophistication of the offense, the significant planning involved, the scale of the impact on TfL, and the fact that both defendants knew their actions were criminal. He noted the 16-month age gap between the two as a “potentially significant distinction in maturity” — but handed down identical five-and-a-half-year sentences regardless.

What Flowers Was Doing When Arrested

The picture of Owen Flowers that emerged in court was striking. When NCA officers and City of London Police arrived at his Walsall home on September 6, 2024 — three days after the TfL attack ended — he was actively attacking two American healthcare systems: SSM Health Care Corporation and Sutter Health.

Officers seized laptops, tower computers, hard drives, and USB sticks. One laptop contained a screenshot showing live network connectivity to TfL infrastructure; the same device held the videos Flowers had recorded of Jubair moving through TfL’s systems during the attack.

In chat logs entered into evidence, Flowers acknowledged that attacking the hospital systems “might kill some 90-year-old on life support.” His arrest halted both intrusions before they succeeded.

Flowers pleaded guilty to two additional counts over the US healthcare attacks: a conspiracy charge relating to SSM Health and an attempted attack on Sutter Health.

How Scattered Spider Works — and Why the Arrests May Not Be Enough

The NCA describes both Flowers and Jubair as leading members of Scattered Spider, the loosely organized, English-speaking cybercrime collective also tracked as Octo Tempest, UNC3944, and 0ktapus. The FBI’s Cyber Division, in a statement appended to the NCA announcement, ties the group to data extortion, SIM swapping, and social engineering.

CISA and FBI issued a joint advisory in 2023 documenting the group’s primary methods: phone calls to IT helpdesks claiming to be employees who need credentials reset, SMS-based phishing using adversary-in-the-middle domains, and SIM swapping to intercept authentication codes. The group’s attacks across dozens of US and UK organizations since 2022 have been characterized by rapid lateral movement after initial access and by the fact that they are conducted overwhelmingly in English — making the calls harder to flag as suspicious at helpdesks expecting attacks to arrive through technical channels.

The NCA said Thursday that its action against Flowers and Jubair “effectively halted the group’s criminal activity,” and cited Microsoft’s independent assessment that the arrests “materially degraded the group’s ability to continue conducting cybercriminal operations.” In the same statement, the NCA acknowledged that other criminals may continue operating under the Scattered Spider name.

That caveat matters. In January 2026, Mandiant identified an expansion of ShinyHunters-branded extortion using an identical methodology: vishing calls to employees, victim-branded credential harvesting pages to capture SSO logins and MFA codes, then attacker devices enrolled for MFA. The Scattered Spider playbook did not originate with Flowers and Jubair, and it did not die with their arrest.

Jubair Still Faces US Federal Charges

Jubair’s legal exposure extends beyond the UK conviction. A federal complaint unsealed in New Jersey in September 2025 accuses him of computer fraud, wire fraud, and money laundering conspiracies. US prosecutors allege involvement in approximately 120 network intrusions targeting at least 47 US victims between May 2022 and September 2025, with more than $115 million extracted in ransom payments across those attacks. The complaint additionally alleges he moved approximately $8.4 million in cryptocurrency out of a server wallet while agents were executing a seizure warrant.

Those are allegations, untested in court. The maximum sentence across all US counts is 95 years. Neither the DOJ’s Thursday announcements nor the UK proceedings addressed extradition.

Police Call for New Powers

Thursday’s sentencing was also used by the City of London Police to make a public case for a legal power it currently lacks.

Commander Ollie Shaw called for the introduction of Cyber Crime Risk Orders — court-imposed restrictions on an individual’s access to devices, online services, and technologies, calibrated to the risk that person poses. Shaw described the proposed measure as a “digital prison” for those who have demonstrated a propensity to cause harm online. The orders would be overseen by courts and reviewed regularly.

No such power exists in UK law. The existing toolkit available to prosecutors after a conviction is a custodial sentence.

Security Minister Dame Angela Eagle welcomed the convictions and said the government is “bolstering the UK’s defenses from cyber crime with new legislation,” though she did not confirm a timetable for Cyber Crime Risk Order legislation.

NCA Deputy Director Paul Foster, head of the National Cyber Crime Unit, drew one practical lesson from the case for every organization that operates an IT helpdesk: call law enforcement early. He said the convictions “likely would not have been possible” without TfL’s early engagement with law enforcement.

What Organizations Can Do Before the Next Call Arrives

The TfL attack succeeded without a line of custom malware. That means the defenses that would have stopped it are not primarily technical.

Security researchers and the Google Mandiant hardening guidance cited in post-case analysis identify a consistent set of controls. Helpdesks must require verified, out-of-band identity confirmation before processing any account change — password reset, MFA device re-enrollment, or device registration. A secondary confirmation through a manager sign-off or a verified callback to a known number adds a step that impersonation alone cannot bypass. Phishing-resistant MFA — FIDO2 hardware keys, device-bound passkeys — cannot be relayed or captured by a phishing kit, unlike push notifications and SMS codes, and should be deployed on any high-value system. SIM swap risk deserves separate attention: removing SMS as an account recovery option removes the attack surface entirely. Finally, auditing what a helpdesk can do without additional authorization — and then requiring that authorization — closes the gap that Scattered Spider found open at TfL.

The data those two phone calls unlocked is still out there. TfL’s 10 million affected passengers have not had it returned.


Frequently Asked Questions

How did Scattered Spider actually bypass TfL’s two-factor authentication?

The attack did not defeat the cryptographic mechanism of 2FA. Instead, Flowers and Jubair called the IT helpdesk, impersonated a TfL employee using partial credentials purchased from criminal forums, and convinced a worker to issue a password reset — bypassing 2FA entirely by exploiting the helpdesk’s identity verification process rather than the authentication token itself. This is a documented weakness in how most organizations handle helpdesk-initiated account changes: the reset process, if it can be triggered by an unverified phone call, effectively nullifies whatever MFA technology protects the account normally.

What data was stolen, and are TfL passengers still at risk?

A database containing the names, email addresses, home phone numbers, mobile numbers, and physical addresses of approximately 10 million people was accessed, according to a BBC investigation published in March 2026 after a hacker sent the broadcaster a copy of the database. Bank account numbers and sort codes for approximately 5,000 customers with active Oyster refund requests were also potentially reached. TfL notified roughly 7.1 million customers who had email addresses registered on the system. Security researchers have warned that this data is likely circulating among criminal networks and will continue to be used for phishing, identity fraud, and social engineering attacks for years.

What is Section 3ZA of the Computer Misuse Act, and why does this conviction matter?

Section 3ZA, inserted into the Computer Misuse Act 1990 by the Serious Crime Act 2015, is the law’s most serious provision. It applies when an unauthorized act causes or creates a significant risk of serious damage to human welfare, the economy, the environment, or national security. The Crown Prosecution Service says Flowers and Jubair are the first defendants to be successfully convicted under it. The sentence — five and a half years each — establishes that social engineering attacks on critical national infrastructure can and will be prosecuted to the full severity the law allows, not just charged under lesser computer crime statutes.

Is Scattered Spider finished after these arrests?

The NCA said Thursday that its action against Flowers and Jubair effectively halted the group’s criminal activity, and Microsoft’s independent assessment confirmed the arrests materially degraded the group’s operational capability. However, the NCA simultaneously acknowledged that other criminals may continue operating under the Scattered Spider name. Security researchers at Mandiant identified a January 2026 extortion campaign using an identical vishing-and-MFA-re-enrollment methodology under the ShinyHunters brand, suggesting the underlying playbook remains in active use by actors unaffected by the TfL convictions.



Click Here For The Original Source.

——————————————————–

..........

.

.

National Cyber Security

FREE
VIEW