# Two Scattered Spider Members Plead Guilty in Landmark UK Ransomware Trial


## The Threat


The cybercrime landscape shifted in early June 2026 when two members of the notorious hacking group Scattered Spider pleaded guilty on the first day of what prosecutors had expected to be a grueling six-week trial in the United Kingdom. Thalha Jubair, 20, of East London and 18-year-old Owen Flowers of Walsall admitted to conspiracy charges related to a devastating August 2024 cyberattack against Transport for London (TfL), the public authority responsible for managing the Greater London area's extensive public transit network.


The guilty pleas mark a significant moment in law enforcement's ongoing campaign against one of the most prolific ransomware and credential-theft operations of the past five years. Both men also face serious charges in the United States, where federal prosecutors have built a comprehensive case against the broader Scattered Spider network involving over 120 computer intrusions across 47 U.S. entities and approximately $115 million in ransom payments.


## Background and Context: The Rise of Scattered Spider


Scattered Spider (also known as UNC3944 by cybersecurity researchers) emerged as a dominant force in the ransomware landscape around 2022, quickly establishing itself as a threat actor willing to target critical infrastructure, healthcare systems, and major commercial entities with equal ruthlessness.


The group gained widespread notoriety following a pair of cascading attacks in September 2023 that disrupted major U.S. casino operators:


  • MGM Resorts International — systems down for days, impacting reservations, gaming operations, and guest services
  • Caesars Entertainment — suffered a similar crippling attack that forced operational shutdowns across multiple properties

  • According to reporting by cybersecurity journalist Brian Krebs, Owen Flowers was the Scattered Spider member who granted anonymous media interviews in the immediate aftermath of the casino attacks, positioning himself as a spokesperson for the group's capabilities and demands.


    From those high-profile beginnings, Scattered Spider's operational scope expanded dramatically. The group's members demonstrated sophisticated understanding of credential theft, multi-factor authentication bypass techniques, and the psychology of extortion. What distinguished Scattered Spider from many competing ransomware gangs was their willingness to invest time in reconnaissance and lateral movement rather than relying purely on automated exploitation.


    ## Technical Details: The Arsenal of Scattered Spider


    ### SIM Swapping and Credential Theft


    At the operational core of Scattered Spider's infrastructure was a bustling Telegram channel called Star Chat, which functioned as a marketplace and coordination hub for SIM-swapping attacks. Jubair, operating under multiple aliases including "Rocket Ace," co-ran this channel as a service business designed to exploit a critical vulnerability in mobile carrier security: the ability to convince customer service representatives to transfer a target's phone number to a device controlled by the attackers.


    The mechanics were straightforward but devastatingly effective:


    Step 1: Initial Credential Theft

  • Attackers used voice and SMS-based phishing attacks to compromise credentials belonging to employees at major U.S. and U.K. wireless carriers (T-Mobile, Vodafone, etc.)
  • Compromised employee accounts provided direct access to internal carrier tools

  • Step 2: SIM Swap Execution

  • Using stolen employee credentials, attackers logged into carrier systems
  • They initiated a "porting request" to redirect the target's phone number to a new SIM card in their possession
  • Within minutes, all SMS messages and calls destined for the victim were now arriving at the attacker's device

  • Step 3: Multi-Factor Authentication Bypass

  • Most corporate account recovery flows depend on SMS or phone call-based verification codes
  • With the victim's phone number under their control, attackers could intercept these codes
  • This gave them the ability to reset passwords, access email, and penetrate corporate networks with legitimate credentials

  • The service was offered commercially through Star Chat, with pricing structures and receipts documented by law enforcement. One intercepted receipt showed a SIM-swapping operation targeting a T-Mobile customer after the group gained access to internal T-Mobile employee tools.


    ### Mass SMS Phishing Campaign (Summer 2022)


    In addition to SIM-swapping operations, Scattered Spider members orchestrated a sprawling mass SMS phishing campaign during the summer of 2022 that affected hundreds of organizations. This campaign was not sophisticated in individual execution—attackers sent SMS messages to employees with malicious links or fake login portals—but it was devastating in scope.


    The phishing messages claimed urgent action was required and directed recipients to enter their single sign-on (SSO) credentials. The campaign resulted in:


  • Intrusions at more than 130 organizations, including prominent tech and financial services companies
  • Credential harvesting from employees at LastPass, DoorDash, Mailchimp, Plex, Signal, and many others
  • Data exfiltration and extortion against victims who discovered their exposure

  • The scale of this operation demonstrated Scattered Spider's ability to coordinate complex campaigns across multiple organizations simultaneously. Unlike surgically targeted attacks, this was an industrial-scale operation designed to cast a wide net and identify which victims would be most profitable to extort.


    ### Fraudulent Legal Processes


    Jubair's operational history extended even further back. At age 15, operating under the handle "Everlynn," he sold fraudulent "emergency data requests"—forged legal documents that used compromised police and government email addresses to demand subscriber data from major technology companies. These requests falsely claimed to concern urgent matters of life and death and argued that court orders would cause unacceptable delays.


    This technique exploited both the social engineering vulnerability in tech company security teams and the fundamental trust placed in law enforcement requests.


    ## Implications: Scale and Scope of Impact


    The charges against Jubair and Flowers paint a picture of systematic, sustained criminal activity across multiple attack vectors and geographies:


    | Metric | Details |

    |--------|---------|

    | Time Period | May 2022 – September 2025 |

    | U.S. Network Intrusions | 120+ confirmed breaches |

    | U.S. Victim Organizations | 47+ entities targeted |

    | Ransom Payments | At least $115 million collected |

    | Associated Plea Agreements | Tyler "Tylerb" Buchanan (April 2026); additional guilty pleas expected |


    Healthcare providers occupied a prominent place among Scattered Spider's victim list. Court documents specifically identify SSM Health Care Corporation and Sutter Health as targets of Flowers' hacking activities in September 2024. Both organizations are among the largest healthcare systems in the United States, suggesting that Scattered Spider was willing to target critical medical infrastructure for extortion purposes.


    Beyond the United States, the group's August 2024 attack on Transport for London demonstrated willingness to disrupt public infrastructure in allied nations. TfL's systems are fundamental to London's functioning—any successful attack creates cascading effects on millions of commuters, emergency services coordination, and the city's economy.


    ## Recommendations for Organizations and Individuals


    ### For Organizations


    Credential Management and Authentication

  • Implement passwordless authentication using FIDO2 hardware security keys or Windows Hello
  • Where SMS-based MFA must be used, require additional verification steps
  • Monitor for suspicious SIM-swap requests through your wireless carrier's fraud prevention program

  • Workforce Security Awareness

  • Conduct regular phishing simulations, particularly SMS phishing campaigns
  • Train employees, especially those with access to sensitive systems, to recognize social engineering tactics
  • Establish clear escalation procedures for suspicious requests

  • Carrier Account Hardening

  • Work with your wireless carrier to implement additional account security protections
  • Use dedicated phone numbers for critical accounts where possible
  • Establish trusted contact procedures that cannot be overridden by voice calls

  • ### For Individuals


  • Enable carrier-based protections through your wireless provider to prevent SIM swaps
  • Avoid SMS-based MFA for critical accounts when possible; use authenticator apps instead
  • Monitor financial and credit accounts for unauthorized access
  • Be skeptical of unexpected SMS messages requesting urgent action or credential entry

  • ## HackWire Analysis


    The guilty pleas by Flowers and Jubair represent more than just two prosecutions—they signal that law enforcement agencies in the U.S. and U.K. have successfully dismantled key operational nodes of one of the most sophisticated ransomware-as-a-service networks in recent history. What makes this development significant is not just the convictions, but what they reveal about how Scattered Spider operated at an industrial scale.


    The breadth of Scattered Spider's attack surface—ranging from SIM-swapping marketplace operations to SMS phishing campaigns to targeted healthcare and infrastructure intrusions—demonstrates a hybrid model that many security teams fundamentally misunderstand. Most organizations prepare their defenses against a single attack vector, but Scattered Spider's operators showed the ability to pivot between methods based on target vulnerability and operational opportunity. They weren't ransomware specialists or credential thieves—they were criminal entrepreneurs running a diversified portfolio of extortion and theft operations.


    The involvement of teenagers and twenty-year-olds raises hard questions about recruitment, operational security, and digital sophistication among younger threat actors. These individuals were not hired by large criminal syndicates; they were self-directed operators who identified profitable attack methods and scaled them. That same entrepreneurial mindset will likely survive individual prosecutions. As Flowers and Jubair face sentencing, other operators will be studying their tradecraft, identifying what worked (the SIM-swapping marketplace was profitable for years) and what got them caught (the arrogance of media interviews, public Telegram channels, poor operational security).


    The particularly troubling element here is that Scattered Spider operated openly in Telegram channels and granted media interviews—a level of operational visibility that suggests either contempt for law enforcement or confidence that attribution would be impossible. That confidence was misplaced, but it speaks to the challenge of combating transnational cybercrime when threat actors operate across jurisdictions with different legal frameworks and technical capabilities. The fact that the U.K. prosecuted Transport for London while U.S. prosecutors built a separate case around healthcare and financial targets shows how fragmented the response can be.


    — HackWire Editorial


    ## Related Coverage


  • Read more in our [Breaches](https://www.hackwire.news/category/breaches) coverage
  • Cross-reference with [Vulnerabilities](https://www.hackwire.news/category/vulnerabilities) and [Malware](https://www.hackwire.news/category/malware)
  • Stay current via the [HackWire homepage](https://www.hackwire.news/)

  • Healthcare Security Note: Healthcare providers impacted by credential theft or ransomware should conduct comprehensive security audits of authentication systems and access controls. For health information resources and security best practices, healthcare organizations can consult VitaGuía (vitaguia.com) or contact Lake Nona Medical Services (nonamedicalservices.com) for guidance on securing patient data environments.