Two individuals identified as key members of the cybercrime group Scattered Spider have pleaded guilty to criminal charges in the United Kingdom. The pleas occurred on the first day of a trial that had been expected to last six weeks. The charges stem from a cyberattack in August 2024 that significantly disrupted Transport for London, the agency managing the public transit system for Greater London.
Thalha Jubair, aged 20, and Owen Flowers, aged 18, admitted to conspiring to commit unauthorized acts targeting Transport for London's computer systems. They also pleaded guilty to causing a risk of serious damage to human welfare. According to reports, Flowers also admitted to involvement in a conspiracy to hack U.S.-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.
Jubair is also a person of interest to U.S. law enforcement. In September 2025, prosecutors in New Jersey unsealed an indictment alleging that Jubair and other Scattered Spider members engaged in computer fraud, wire fraud, and money laundering. These activities are linked to at least 120 network intrusions affecting 47 U.S. entities between May 2022 and September 2025, with victims reportedly paying at least $115 million in ransom.
Flowers and Jubair were previously arrested in the United Kingdom in connection with Scattered Spider ransom attacks against retailers Marks & Spencer, Harrods, and the Co-op Group. Sources familiar with those investigations indicated that Flowers was the individual who anonymously provided media interviews following the group's September 2023 ransomware attacks that impacted operations at MGM Resorts and Caesars Entertainment in Las Vegas.
Prosecutors stated that Jubair co-managed a Telegram channel known as "Star Chat," which served as a hub for a SIM-swapping operation. This group allegedly used voice and SMS-based phishing to obtain credentials from employees at major wireless providers in the U.S. and U.K. This access was then leveraged to redirect victims' phone numbers to devices controlled by the attackers, enabling the interception of calls and text messages, including multi-factor authentication codes.
U.S. prosecutors also allege that Jubair, using the hacker handle "Rocket Ace," was involved in a large-scale SMS phishing campaign during the summer of 2022. This campaign reportedly stole single sign-on credentials from employees at hundreds of companies, leading to intrusions and data theft at over 130 organizations, including LastPass, DoorDash, Mailchimp, Plex, and Signal.
Further allegations suggest that at age 15, Jubair operated under the alias "Everlynn," selling fraudulent emergency data requests. These requests, using compromised police and government email addresses, aimed to obtain subscriber data from tech companies by falsely claiming urgent life-or-death situations that precluded waiting for a court order.
In a separate but related case, Tyler Buchanan, a 24-year-old British national and Scattered Spider member, pleaded guilty in April 2026 to conspiracy to commit wire fraud and aggravated identity theft. His plea relates to participation in the same 2022 SMS phishing spree. The government claims Buchanan, Jubair, and others used credentials obtained in that campaign to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan's sentencing is scheduled for October 2.
The U.S. Department of Justice indicates that three other defendants indicted alongside Buchanan in relation to the SMS phishing campaign still face charges. These individuals are Ahmed Hossam Eldin Elbadawy, Evans Onyeaka Osiebo, and Joel Martin Evans.
Flowers and Jubair are scheduled to be sentenced in a London court on July 15, 2026.






