LIVE · cybersecurity feed
Live wire
scattered spiderhigh

Two Scattered Spider members sentenced to 66 months for London transport cyberattack

Two individuals, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in prison in the UK for their roles in a cyberattack that disrupted Transport for London's operations. The pair were identified as leading members of the Scattered Spider hacking group. Authorities linked them to significant cryptocurrency transactions and numerous cyberattacks, including extortion of US organizations and an attack on the federal court system.

zeroday.news · 15d ago

Two individuals identified as leading members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, have been sentenced to 66 months in jail in the United Kingdom for a 2024 cyberattack that disrupted Transport for London operations. The UK's National Crime Agency announced the sentencing on Thursday, following their arrests in September 2025 and subsequent guilty pleas.

Jubair, 20, and Flowers, 18, were described by researchers as core members of Scattered Spider, a subset of a broader collective known as "The Com." US authorities had previously accused Jubair of involvement in at least 120 cyberattacks, including the extortion of 47 US-based organizations and a January 2025 attack on the federal court system. Officials traced approximately $89.5 million in cryptocurrency, at the time of payment, to Bitcoin addresses and servers controlled by Jubair, including two payments of $25 million and $36.2 million from financial services firms between June and November 2023.

Flowers had been arrested in connection with the Transport for London attack in 2024 but was released after questioning. At the time of his initial arrest, investigators stated he was actively attempting to hack into the systems of US healthcare companies SSM Health Care Corporation and Sutter Health, which had already experienced infiltration and damage. Both Jubair and Flowers reportedly did not cooperate with authorities after their arrests.

The National Crime Agency characterized the prosecution as the largest cybercrime case brought before UK courts, representing the culmination of nearly two years of investigative work. Paul Foster, head of the National Cybercrime Unit, stated that the investigation had "severely disrupted" the threat posed by Scattered Spider, which he described as the most significant cybercrime threat to the UK in recent years.

Despite the UK authorities' positive assessment, the lasting impact of the arrests and imprisonment on Scattered Spider's activities remains unclear. While UK authorities assert the arrests effectively halted the group's criminal operations, they also acknowledged that other cybercriminals continue to use the Scattered Spider brand in more recent attacks. The FBI, in a LinkedIn post, echoed this sentiment, noting that members of Scattered Spider continue to victimize organizations globally, causing significant financial and operational harm.

Industry analysts indicated that Jubair was considered one of the four principal individuals associated with Scattered Spider, and one of its two most central figures, at the time of his arrest. These analysts also noted that Jubair and Flowers possessed substantial resources and support, with victim payments being reinvested into their criminal enterprise. Some observers expressed concern that the 66-month sentence might be lenient given the duration of the defendants' alleged reoffending, which reportedly exceeded the sentence length. There is hope that the US may seek extradition to pursue additional charges.

Scattered Spider is known for its reliance on data extortion, SIM-swap attacks, and other social engineering techniques to infiltrate networks and compromise critical services. The FBI Cyber Division's Assistant Director, Brett Leatherman, emphasized the significance of holding these two members accountable.

scattered spidercybercrimeransomwaretransportation securityuk
ShareXLinkedInWhatsAppFacebook

More News

view all →
breach

Hermes AI agent used to automate attack on Thai Finance Ministry

A threat actor used the open-source Hermes AI agent in unattended "YOLO" mode to automate post-exploitation activity during an alleged breach of Thailand's Ministry of Finance. [...]

security

Hackers hijack hotel Wi-Fi DNS to steal Microsoft 365 accounts

Hackers are changing the DNS settings on Wi-Fi devices at hotels and conference centers to redirect users to fake Microsoft 365 login pages. [...]

security

BGP ORIGIN attribute manipulation and its impact on the Internet

By doing in-depth testing, we found nearly 70% of BGP paths experience ORIGIN attribute rewrites by transit providers seeking traffic advantages. We examine the global impact of this practice and argue for deprecating ORIGIN in route selection.

security

Andy Burnham signals continuity on UK cyber policy, reappoints minister despite scrapping ministry

The new British prime minister is retaining Liz Lloyd in a cyber policy role, making her one of the few Keir Starmer allies remaining in government.

security

'Wrench' attacks against crypto holders appear to be on the rise

There are more reports than ever before of strong-arm tactics like home invasions and kidnappings against cryptocurrency holders, researchers say.

vulnerability

Microsoft blames massive Microsoft 365 outage on maintenance bug

Microsoft says a bug in its automated network maintenance request system caused Thursday's massive outage by mistakenly removing IP routes from more devices than intended, disrupting Azure and Microsoft 365 services. [...]