In a significant development for international cybercrime enforcement, two key members of the notorious cybercrime group known as Scattered Spider have pleaded guilty in the United Kingdom to charges stemming from an August 2024 cyberattack that severely disrupted Transport for London (TfL), the crucial entity overseeing the public transport network across the Greater London area. The guilty pleas, entered by 20-year-old Thalha Jubair and 18-year-old Owen Flowers, came on the very first day of what was anticipated to be a six-week trial, underscoring the weight of the evidence amassed against them by law enforcement agencies. This case highlights the persistent and evolving threat posed by sophisticated cybercriminal organizations to critical national infrastructure and major corporations worldwide.
The Defendants and Their Admissions
Thalha Jubair, residing in East London, and Owen Flowers, from Walsall, each admitted to conspiring to commit unauthorized acts against Transport for London’s computer systems. More critically, they also pleaded guilty to causing a risk of serious damage to human welfare, a charge that reflects the profound potential consequences of disrupting a public transport network relied upon by millions daily. The August 2024 attack on TfL sent ripples of concern through government and cybersecurity circles, demonstrating the vulnerability of essential services to coordinated digital assaults. The image released by the UK National Crime Agency (NCA) shows Flowers (left) and Jubair, both young individuals at the heart of a complex and financially lucrative cyber operation.
Beyond the TfL attack, Owen Flowers separately admitted to his involvement in a conspiracy to hack into U.S.-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024. These admissions reveal a broader pattern of targeting critical sectors, from transportation to healthcare, where disruptions can have severe real-world impacts on public safety and well-being. The attack on healthcare providers, in particular, raises concerns about patient data compromise and the potential for life-threatening operational paralysis.
Jubair’s legal challenges extend across the Atlantic, as he is also a wanted individual by U.S. law enforcement agencies. In September 2025, prosecutors in New Jersey unsealed an indictment against Jubair and other alleged Scattered Spider members. This comprehensive indictment details charges of computer fraud, wire fraud, and money laundering in connection with an staggering 120 computer network intrusions affecting 47 U.S. entities between May 2022 and September 2025. The U.S. Department of Justice alleges that victims of these widespread attacks paid at least $115 million in ransom payments, illustrating the immense financial scale of Scattered Spider’s operations.
Scattered Spider: A Profile in Cybercrime
Scattered Spider, also known by various other monikers such as UNC3944, Muddled Libra, and Star Fraud, has gained notoriety for its sophisticated social engineering tactics and high-profile attacks. The group typically targets large organizations, often employing SIM-swapping and SMS phishing to gain initial access. Their strategy is frequently to leverage this initial access to compromise internal systems, exfiltrate sensitive data, and then deploy ransomware, demanding substantial payments from their victims.
The group’s track record includes a string of high-impact incidents that have made headlines globally. In September 2023, Scattered Spider was responsible for ransomware attacks that severely disrupted operations at Las Vegas casinos operated by MGM Resorts and Caesars Entertainment. These attacks caused significant financial losses and operational headaches for the casino giants, demonstrating the group’s capability to impact major corporate entities. Following these attacks, Owen Flowers was reportedly the Scattered Spider member who anonymously granted interviews to the media, a move that highlighted the group’s brazenness and confidence.
Prior to the TfL incident, Flowers and Jubair had already drawn the attention of UK authorities. In July 2025, it was reported that both individuals were arrested in the United Kingdom in connection with Scattered Spider ransomware attacks against prominent British retailers Marks & Spencer and Harrods, as well as the British food retailer Co-op Group. These arrests signaled a concentrated effort by UK law enforcement to dismantle the group’s operations within its borders and bring its members to justice.
The Modus Operandi: SIM-Swapping and SMS Phishing
Central to Scattered Spider’s success has been its mastery of social engineering techniques, particularly SIM-swapping and SMS phishing, which allow them to bypass even robust security measures like multi-factor authentication (MFA).
SIM-Swapping Explained: Thalha Jubair, according to prosecutors, played a pivotal role in co-running a bustling Telegram channel named "Star Chat." This channel served as the hub for a sophisticated SIM-swapping group. The method involved using voice and SMS-based phishing attacks to steal credentials from employees at major wireless providers in both the U.S. and the U.K. Once access to internal telecom systems was gained, the group would then offer a service to redirect a target’s phone number to a device controlled by the attackers. This enabled them to intercept the victim’s calls and text messages, including critical one-time codes for multi-factor authentication. A receipt from "Star Fraud Chat’s" SIM-swapping service, targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools, illustrates the technical sophistication of their operation. "Rocket Ace" was identified as one of Jubair’s hacker handles, according to U.S. prosecutors, further cementing his direct involvement. This technique effectively neuters a crucial layer of security, allowing attackers to gain access to a myriad of online accounts.

Mass SMS Phishing Campaigns: New Jersey prosecutors also implicate Jubair in a mass SMS phishing campaign during the summer of 2022. This weeks-long campaign was designed to steal single sign-on credentials from employees at hundreds of companies. The success of this broad phishing effort led to intrusions and data thefts at over 130 organizations, including high-profile names such as LastPass, DoorDash, Mailchimp, Plex, and Signal. The compromise of these services could lead to widespread data breaches, financial fraud, and privacy violations for millions of users. The scale of this operation underscores the group’s ambition and their ability to execute large-scale attacks simultaneously.
The "Everlynn" Persona and Fraudulent Emergency Data Requests:
Further delving into Jubair’s past activities, it was revealed that at the age of 15, one of his alter egos was "Everlynn." Under this persona, Jubair was involved in selling fraudulent "emergency data requests" (EDRs). This illicit practice involved using compromised police and government email addresses to demand subscriber data (such as usernames, IP addresses, and email addresses) from major tech companies. The requests falsely claimed to concern urgent matters of life and death, thereby bypassing the typical legal requirements for obtaining such sensitive information. This tactic not only exploited the trust placed in law enforcement agencies but also put individuals’ private data at severe risk without due process. It demonstrates a profound understanding of administrative processes and a willingness to manipulate them for illicit gain from a remarkably young age.
A Broader Crackdown: International Cooperation and Other Convictions
The arrests and guilty pleas of Flowers and Jubair are part of a wider, internationally coordinated effort to dismantle Scattered Spider and bring its members to justice. Law enforcement agencies, particularly the UK’s National Crime Agency (NCA) and the U.S. Department of Justice (DOJ) and FBI, have been working in concert to track, identify, and apprehend members of this globally distributed cybercrime syndicate.
In April 2026, 24-year-old British national and another alleged Scattered Spider member, Tyler "Tylerb" Buchanan, pleaded guilty to wire fraud conspiracy and aggravated identity theft. Buchanan’s admissions were related to his participation in the group’s extensive SMS phishing spree in the summer of 2022. The government stated that Buchanan, Jubair, and others used the credentials harvested from that campaign to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan is currently scheduled to be sentenced on October 2, serving as another testament to the ongoing success of these investigations.
Further demonstrating the reach of law enforcement, in August 2025, 20-year-old Scattered Spider member Noah Michael Urban, from Florida, was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution. Urban had pleaded guilty to charges of wire fraud and conspiracy, highlighting the severe penalties faced by those involved in such illicit activities.
The U.S. Department of Justice has also indicated that three other alleged Scattered Spider defendants, indicted alongside Buchanan, still face charges. These include Ahmed Hossam Eldin Elbadawy, 24, also known as "AD," from College Station, Texas; Evans Onyeaka Osiebo, 21, from Dallas, Texas; and Joel Martin Evans, 26, also known as "joeleoli," from Jacksonville, North Carolina. These ongoing cases underscore the persistent efforts to fully dismantle the group and hold all its members accountable.
Implications for Cybersecurity and Critical Infrastructure
The Transport for London cyberattack and the broader activities of Scattered Spider carry significant implications for global cybersecurity, particularly concerning critical national infrastructure.
- Vulnerability of Essential Services: The successful targeting of TfL, a lifeline for millions of Londoners, highlights that even highly protected critical infrastructure remains vulnerable to determined and sophisticated cybercriminal groups. A prolonged disruption could have catastrophic economic, social, and even public safety consequences. This case serves as a stark reminder that robust digital defenses are as crucial as physical security for such entities.
- The Evolving Threat Landscape: Scattered Spider’s reliance on social engineering, SIM-swapping, and SMS phishing demonstrates a shift from purely technical exploits to human-centric attacks. This emphasizes the need for comprehensive security strategies that include not only advanced technological safeguards but also continuous employee training, robust incident response plans, and strict adherence to security protocols.
- Challenges of Attribution and Prosecution: The geographically dispersed nature of Scattered Spider’s members, operating across different countries and jurisdictions, presents immense challenges for law enforcement. The success in prosecuting Flowers and Jubair, alongside other members, is a testament to the increasing effectiveness of international cooperation and intelligence sharing between agencies like the NCA, FBI, and DOJ.
- The "Young Hacker" Phenomenon: The relatively young age of many individuals involved in Scattered Spider, including Flowers and Jubair, raises questions about the motivations and pathways that lead young talent into cybercrime. It also presents a challenge for legal systems to balance punitive measures with potential rehabilitation, while sending a clear deterrent message.
- Economic and Reputational Damage: The staggering sum of over $115 million in ransom payments alone, alongside the operational costs, reputational damage, and recovery efforts for affected organizations, underscores the immense economic toll of such cyber-attacks. For companies like MGM Resorts, Caesars Entertainment, and various healthcare providers, the impact goes far beyond immediate financial losses.
The guilty pleas by Owen Flowers and Thalha Jubair mark a crucial milestone in the ongoing fight against sophisticated cybercrime. It sends a strong message that despite the perceived anonymity of the internet, law enforcement agencies possess the capabilities and international partnerships to identify, track, and prosecute those who seek to exploit digital vulnerabilities for illicit gain.
Flowers and Jubair are now slated to be sentenced in a London court on July 15, 2026. The outcomes of their sentencing, and those of the other indicted Scattered Spider members, will be closely watched by the cybersecurity community and by potential cybercriminals alike, as they will further define the consequences for engaging in such damaging digital transgressions. This case will undoubtedly serve as a critical precedent in the global effort to secure our increasingly digital world.

