Hackers Sentenced for TfL Cyberattack, Millions in Commuter Data Stolen
Scattered Spider members receive five-and-a-half-year sentences after compromising Transport for London systems and stealing 7 million commuter records.


Carla Rooney
Two members of the Scattered Spider cybercrime group have received five-and-a-half-year prison sentences for a sophisticated cyberattack that crippled Transport for London's (TfL) IT systems and exposed data from millions of commuters.
The audacious attack disabled 148 Transport for London (TfL) systems, including vital infrastructure, and accessed sensitive data from TfL's Oyster refunds system.
This direct assault significantly disrupted customer refund processes and compromised the transport network's operational integrity.
The intrusion exported approximately six million lines of data, a staggering volume, and compromised 28,000 employee accounts through stolen credentials.
TfL reported £29 million in loss and recovery costs, a direct financial impact stemming from the digital assault.
The hackers gained initial access by manipulating a phone help desk worker, tricking them into resetting an employee's password.
This method allowed them to penetrate deep into TfL's systems, accessing data from the Oyster refund system and causing widespread delays in contactless payment systems.
Beyond the financial and data breaches, applications for Oyster photo cards shut down, and the dial-a-ride service for disabled passengers could not process bookings during the incident.
TfL's systems shut down in a decisive measure to halt the duo's activity, effectively stopping the attack in its tracks.
Owen Flowers live-streamed parts of the hack, documenting the intrusion as it unfolded for an online audience, adding a brazen layer to the crime.
Authorities identified both individuals as 'leading members of the online criminal collective known as Scattered Spider,' a group with a notorious international footprint.
The prosecution, led by Mark Fenhalls KC, stated the hackers possessed the capability to shut out and shut down TfL completely, threatening to cause £56 billion of 'catastrophic damage' to the UK economy.
The hackers possessed the capability to shut out and shut down TfL completely, threatening to cause £56 billion of 'catastrophic damage' to the UK economy.
Jubair's defense team claimed he was groomed and exploited by much older criminals, driven largely by curiosity in targeting TfL, spending hours searching for celebrity TfL accounts.
His lawyer, Paul Keleher, KC, described Jubair as a 'modern day Oliver Twist,' groomed by criminals to hack companies from the age of 13, later becoming the 'Artful Dodger' by recruiting and teaching other young hackers.
Jubair was a 'modern day Oliver Twist,' groomed by criminals to hack companies from the age of 13, later becoming the 'Artful Dodger' by recruiting and teaching other young hackers.
Flowers' defense team claimed Flowers is immature; both defendants have received diagnoses of autism, a factor presented in mitigation.
Jubair's 22 previous convictions, including charges related to hacking, fraud, and harassment, further evidence this history of cyber criminal activity.
Prior to the TfL incident, Owen Flowers had already received a 'cease and desist notice' from West Midlands Police, indicating a pattern of escalating digital misconduct.
Flowers admitted to additional charges related to hacking US healthcare systems, specifically targeting SSM Health Care Corporation and Sutter Health, broadening the scope of his illicit activities.
Police seized cryptocurrency holdings worth around £1 million from Flowers, a tangible recovery from the digital crime that underscores the financial motivations behind such attacks.
The broader landscape of Scattered Spider's operations includes the MGM Grand casino in Las Vegas, which experienced widespread system failures on September 10, 2023, affecting slot machines, cash points, credit card payments, and digital room keys.
This collective unleashed malicious software on MGM and at least 46 other American organizations, demonstrating their extensive reach and impact.
Victims paid at least $115 million in ransom payments to Scattered Spider across various incidents, though no ransom was demanded in the TfL attack itself.
Despite these convictions, the stolen database, containing details of up to 10 million TfL customers, is still being shared within criminal groups, posing an ongoing risk to individuals.
The National Crime Agency stated on Thursday that these convictions had 'effectively halted the group’s criminal activity,' marking a significant victory against organised cybercrime.
Internationally, Jubair is wanted in the US in connection with cyber crimes against 47 US-based victims, which allegedly led to $115 million paid in ransoms to Jubair and his associates, highlighting the global reach of these digital threats.