# Two Scattered Spider Members Sentenced to 5.5 Years for £29 Million Transport for London Hack
UK Courts Hand Down Landmark Conviction in Major Infrastructure Attack as Law Enforcement Escalates Cybercrime Prosecutions
Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years in prison on July 16, 2026, for orchestrating a devastating attack on Transport for London in August 2024. The sentencing at Woolwich Crown Court marks a significant escalation in UK cybercrime enforcement, representing the first successful conviction under the Computer Misuse Act 1990's most serious provision—Section 3ZA—which carries penalties for attacks posing serious risk to human welfare.
The attack left 148 TfL systems inoperable, disabled critical services used by millions of Londoners daily, and forced the entire 27,000-person workforce into physical locations to reset passwords. Combined investigation and recovery costs reached £29 million, making this one of the costliest infrastructure breaches in UK history.
## The Threat: Cascading Failures Across London's Transit Network
The intrusion, which ran from August 31 through September 3, 2024, targeted an organization managing 9 million journeys daily across London's transportation system. The damage was immediate and extensive:
Services Disabled:
Data Compromised:
The National Crime Agency (NCA) estimates that a successful complete network shutdown could have cost the UK economy up to £56 billion, though TfL's rapid containment response prevented this scenario. However, the operational disruption alone caused significant economic impact and service degradation for millions of Londoners who depend on public transport.
## Background and Context: Scattered Spider's Infrastructure Campaign
Flowers and Jubair are identified as leading members of Scattered Spider, a prolific extortion gang tracked by cybersecurity researchers under multiple aliases—Octo Tempest, UNC3944, and 0ktapus. The FBI and international law enforcement link the group to hundreds of attacks spanning 2022 to 2025, primarily targeting critical infrastructure, large enterprises, and healthcare organizations.
The group's operational approach combines multiple attack vectors: traditional ransomware deployment, data extortion, SIM swapping for account takeovers, and sophisticated social engineering. Their targets have ranged from financial institutions to energy providers to healthcare systems, suggesting a capability to rapidly adapt to different security environments.
Scattered Spider's Known Tactics:
The TfL attack represents an unusually bold public infrastructure target, suggesting either confidence in their technical capabilities or deliberate escalation in targeting critical services.
## Technical Details: Multi-Stage Intrusion and Forensic Evidence
According to evidence presented by the Crown Prosecution Service (CPS) and uncovered during investigation:
Attack Infrastructure:
Forensic Discoveries:
When National Crime Agency officers arrested Flowers at his home on September 6, 2024—just three days after the TfL intrusion concluded—they discovered critical evidence:
Critically, investigators discovered that Flowers had been actively attacking two major US healthcare organizations at the time of his arrest. The timing and evidence suggest Scattered Spider operated multiple concurrent campaigns.
## Dangerous Convergence: Threats to Healthcare Infrastructure
The prosecution revealed that Flowers faced additional charges for attacking SSM Health Care Corporation and Sutter Health, two major US healthcare providers. Prosecutors documented threats wherein Flowers acknowledged potential fatal consequences: he stated the attacks "might kill some 90-year-old on life support" while threatening to lock down healthcare systems.
This convergence—criminals willing to attack critical healthcare infrastructure while consciously acknowledging potential loss of life—represents an escalation in threat posture. Healthcare providers, already under pressure from ransomware campaigns, now face attackers willing to weaponize service disruption as a tactic without regard for patient safety implications.
## Legal Significance: Landmark Prosecution Under Section 3ZA
The convictions represent a watershed moment in UK cybercrime prosecution. Both defendants pleaded guilty on June 22, 2026, to charges under Section 3ZA of the Computer Misuse Act 1990—specifically, being reckless as to whether they caused or created a significant risk of serious damage to human welfare.
Prosecution Significance:
The section's language—focused on recklessness toward "human welfare"—proved decisive. By disrupting transport, healthcare access, and mobility services, Scattered Spider created demonstrable risk to public safety. Prosecutors successfully argued this exceeded typical data breach or financial fraud thresholds.
## Implications: Infrastructure Remains Vulnerable
The TfL case exposes critical gaps in UK infrastructure security:
Operational Risk:
Governance Questions:
Precedent for Future Attacks:
The case demonstrates that infrastructure operators and hostile actors both now understand Section 3ZA liability. Future attacks may:
## Recommendations for Defenders
For Critical Infrastructure Operators:
For Government and Law Enforcement:
---
## HackWire Analysis
The Scattered Spider convictions arrive at an inflection point for infrastructure security globally. These were not sophisticated APT operators with nation-state backing—they were young offenders leveraging social engineering and existing TTPs to extract ransom and cause damage. That such actors could disable a major capital city's transit system for days should alarm every infrastructure organization.
What makes this case significant isn't the technical sophistication; it's the normalization of infrastructure targeting and the callous disregard for human consequence. Flowers' casual acknowledgment that his healthcare attacks "might kill some 90-year-old on life support" wasn't a restraining factor—it was context he communicated while continuing the intrusions. This reflects a fundamental shift in attacker psychology: infrastructure disruption and data extortion are now viewed as interchangeable commodities, with human impact treated as an acceptable cost of business.
The Section 3ZA convictions also signal that UK courts will hold attackers accountable for systemic risk even when worst-case scenarios don't materialize. TfL contained the attack, mitigating hypothetical £56 billion damages. But the precedent is clear: recklessness toward infrastructure and human welfare now carries serious prison time.
The remaining question is enforcement scope. Scattered Spider has been attributed to "hundreds of attacks between 2022 and 2025." The NCA and CPS secured convictions against two members. This leaves hundreds of incidents unresolved and potentially dozens of other group members still operating. The deterrent effect is real but limited. Infrastructure organizations should assume Scattered Spider operatives remain active and adapt their defenses accordingly.
— HackWire Editorial
## Related Coverage