London, UK – July 17, 2026 – Two individuals, Owen Flowers (18) and Thalha Jubair (20), associated with the notorious Scattered Spider hacking group, have been sentenced to five and a half years in prison each at Woolwich Crown Court on Thursday, July 16, 2026. The sentencing marks a significant legal victory in the fight against sophisticated cybercrime, following their roles in a 2024 cyberattack that crippled Transport for London (TfL) systems and caused estimated losses of £29 million.

Chronology of the Attack and Legal Proceedings

The cyber intrusion, attributed to Flowers and Jubair, occurred between August 31 and September 3, 2024. The attack severely impacted TfL's operational capabilities, rendering 148 of its systems inoperable. The aftermath required all 27,000 TfL employees to physically report to an office to have their passwords reset, highlighting the profound disruption caused.

The individuals pleaded guilty on June 22, 2026, the day their trial was scheduled to commence. They admitted to charges under Section 3ZA of the Computer Misuse Act 1990, the most severe section of the Act, on the basis that they were reckless about causing or creating a significant risk of serious damage to human welfare. The National Crime Agency (NCA) and the Crown Prosecution Service (CPS) have cited TfL's total losses and recovery costs from the incident at £29 million. This case is considered one of the biggest cybercrime prosecutions the UK courts have witnessed.

Impact and Broader Implications

The attack on TfL serves as a stark reminder of the vulnerability of critical infrastructure to cyber threats. The significant financial cost, coupled with the widespread operational disruption, underscores the potential for cyber incidents to impact public services and daily life. The necessity for 27,000 employees to undergo in-person password resets demonstrates the severity of the compromise and the extent of the recovery efforts required.

This sentencing also sends a strong message to cybercriminals worldwide. It illustrates that law enforcement agencies are increasingly capable of tracking, prosecuting, and securing convictions against individuals involved in sophisticated hacking operations. The involvement of the Scattered Spider group, known for its social engineering prowess and targeting of large organizations, emphasizes the ongoing need for robust security measures across all sectors.

How Organizations and Individuals Can Enhance Protection

While this case highlights the consequences for attackers, it also offers valuable lessons for prevention and resilience:

The successful prosecution of these individuals underscores the increasing commitment of global law enforcement to counter cybercrime. However, vigilance and proactive defense remain paramount for organizations to protect themselves from evolving threats.