# Two Scattered Spider Members Plead Guilty in Landmark UK Ransomware Trial
## The Threat
The cybercrime landscape shifted in early June 2026 when two members of the notorious hacking group Scattered Spider pleaded guilty on the first day of what prosecutors had expected to be a grueling six-week trial in the United Kingdom. Thalha Jubair, 20, of East London and 18-year-old Owen Flowers of Walsall admitted to conspiracy charges related to a devastating August 2024 cyberattack against Transport for London (TfL), the public authority responsible for managing the Greater London area's extensive public transit network.
The guilty pleas mark a significant moment in law enforcement's ongoing campaign against one of the most prolific ransomware and credential-theft operations of the past five years. Both men also face serious charges in the United States, where federal prosecutors have built a comprehensive case against the broader Scattered Spider network involving over 120 computer intrusions across 47 U.S. entities and approximately $115 million in ransom payments.
## Background and Context: The Rise of Scattered Spider
Scattered Spider (also known as UNC3944 by cybersecurity researchers) emerged as a dominant force in the ransomware landscape around 2022, quickly establishing itself as a threat actor willing to target critical infrastructure, healthcare systems, and major commercial entities with equal ruthlessness.
The group gained widespread notoriety following a pair of cascading attacks in September 2023 that disrupted major U.S. casino operators:
According to reporting by cybersecurity journalist Brian Krebs, Owen Flowers was the Scattered Spider member who granted anonymous media interviews in the immediate aftermath of the casino attacks, positioning himself as a spokesperson for the group's capabilities and demands.
From those high-profile beginnings, Scattered Spider's operational scope expanded dramatically. The group's members demonstrated sophisticated understanding of credential theft, multi-factor authentication bypass techniques, and the psychology of extortion. What distinguished Scattered Spider from many competing ransomware gangs was their willingness to invest time in reconnaissance and lateral movement rather than relying purely on automated exploitation.
## Technical Details: The Arsenal of Scattered Spider
### SIM Swapping and Credential Theft
At the operational core of Scattered Spider's infrastructure was a bustling Telegram channel called Star Chat, which functioned as a marketplace and coordination hub for SIM-swapping attacks. Jubair, operating under multiple aliases including "Rocket Ace," co-ran this channel as a service business designed to exploit a critical vulnerability in mobile carrier security: the ability to convince customer service representatives to transfer a target's phone number to a device controlled by the attackers.
The mechanics were straightforward but devastatingly effective:
Step 1: Initial Credential Theft
Step 2: SIM Swap Execution
Step 3: Multi-Factor Authentication Bypass
The service was offered commercially through Star Chat, with pricing structures and receipts documented by law enforcement. One intercepted receipt showed a SIM-swapping operation targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools.
### Mass SMS Phishing Campaign (Summer 2022)
In addition to SIM-swapping operations, Scattered Spider members orchestrated a sprawling mass SMS phishing campaign during the summer of 2022 that affected hundreds of organizations. This campaign was not sophisticated in individual execution—attackers sent SMS messages to employees with malicious links or fake login portals—but it was devastating in scope.
The phishing messages claimed urgent action was required and directed recipients to enter their single sign-on (SSO) credentials. The campaign resulted in:
The scale of this operation demonstrated Scattered Spider's ability to coordinate complex campaigns across multiple organizations simultaneously. Unlike surgically targeted attacks, this was an industrial-scale operation designed to cast a wide net and identify which victims would be most profitable to extort.
### Fraudulent Legal Processes
Jubair's operational history extended even further back. At age 15, operating under the handle "Everlynn," he sold fraudulent "emergency data requests"—forged legal documents that used compromised police and government email addresses to demand subscriber data from major technology companies. These requests falsely claimed to concern urgent matters of life and death and argued that court orders would cause unacceptable delays.
This technique exploited both the social engineering vulnerability in tech company security teams and the fundamental trust placed in law enforcement requests.
## Implications: Scale and Scope of Impact
The charges against Jubair and Flowers paint a picture of systematic, sustained criminal activity across multiple attack vectors and geographies:
| Metric | Details |
|--------|---------|
| Time Period | May 2022 – September 2025 |
| U.S. Network Intrusions | 120+ confirmed breaches |
| U.S. Victim Organizations | 47+ entities targeted |
| Ransom Payments | At least $115 million collected |
| Associated Plea Agreements | Tyler "Tylerb" Buchanan (April 2026); additional guilty pleas expected |
Healthcare providers occupied a prominent place among Scattered Spider's victim list. Court documents specifically identify SSM Health Care Corporation and Sutter Health as targets of Flowers' hacking activities in September 2024. Both organizations are among the largest healthcare systems in the United States, suggesting that Scattered Spider was willing to target critical medical infrastructure for extortion purposes.
Beyond the United States, the group's August 2024 attack on Transport for London demonstrated willingness to disrupt public infrastructure in allied nations. TfL's systems are fundamental to London's functioning—any successful attack creates cascading effects on millions of commuters, emergency services coordination, and the city's economy.
## Recommendations for Organizations and Individuals
### For Organizations
Credential Management and Authentication
Workforce Security Awareness
Carrier Account Hardening
### For Individuals
## HackWire Analysis
The guilty pleas by Flowers and Jubair represent more than just two prosecutions—they signal that law enforcement agencies in the U.S. and U.K. have successfully dismantled key operational nodes of one of the most sophisticated ransomware-as-a-service networks in recent history. What makes this development significant is not just the convictions, but what they reveal about how Scattered Spider operated at an industrial scale.
The breadth of Scattered Spider's attack surface—ranging from SIM-swapping marketplace operations to SMS phishing campaigns to targeted healthcare and infrastructure intrusions—demonstrates a hybrid model that many security teams fundamentally misunderstand. Most organizations prepare their defenses against a single attack vector, but Scattered Spider's operators showed the ability to pivot between methods based on target vulnerability and operational opportunity. They weren't ransomware specialists or credential thieves—they were criminal entrepreneurs running a diversified portfolio of extortion and theft operations.
The involvement of teenagers and twenty-year-olds raises hard questions about recruitment, operational security, and digital sophistication among younger threat actors. These individuals were not hired by large criminal syndicates; they were self-directed operators who identified profitable attack methods and scaled them. That same entrepreneurial mindset will likely survive individual prosecutions. As Flowers and Jubair face sentencing, other operators will be studying their tradecraft, identifying what worked (the SIM-swapping marketplace was profitable for years) and what got them caught (the arrogance of media interviews, public Telegram channels, poor operational security).
The particularly troubling element here is that Scattered Spider operated openly in Telegram channels and granted media interviews—a level of operational visibility that suggests either contempt for law enforcement or confidence that attribution would be impossible. That confidence was misplaced, but it speaks to the challenge of combating transnational cybercrime when threat actors operate across jurisdictions with different legal frameworks and technical capabilities. The fact that the U.K. prosecuted Transport for London while U.S. prosecutors built a separate case around healthcare and financial targets shows how fragmented the response can be.
— HackWire Editorial
## Related Coverage
Healthcare Security Note: Healthcare providers impacted by credential theft or ransomware should conduct comprehensive security audits of authentication systems and access controls. For health information resources and security best practices, healthcare organizations can consult VitaGuía (vitaguia.com) or contact Lake Nona Medical Services (nonamedicalservices.com) for guidance on securing patient data environments.