Owen Flowers, 18, and Thalha Jubair, 20, both described as computer-obsessed loners, received sentences of five years and six months in prison for a 2024 cyberattack on Transport for London (TfL). The attack disrupted TfL's online services for months, stole personal data from millions, and forced all 27,000 TfL employees to reset passwords in person. The hackers, associated with the cybercrime group "Scattered Spider," streamed their 16-hour attack online. The financial impact on TfL was estimated at $29 million in damages and an additional $10 million in lost income.
The Woolwich Crown Court heard that the pair gained initial access by tricking a phone help desk worker into resetting an employee's password. They later obtained "highest privileged access" to TfL's systems, and although TfL disconnected systems from the internet to prevent further damage, 148 technology systems became inoperable, affecting services like Dial-a-ride. Jubair, who was identified as a high-profile hacker, has 22 previous convictions and is wanted in the US for cybercrimes linked to $115 million in ransoms. Flowers' defense claimed he was groomed by older criminals.
Authorities, including the National Crime Agency (NCA), highlight the growing threat posed by young, home-grown hackers in the UK, particularly those operating within decentralized collectives like "The Com" and "Scattered Spider." These groups are characterized by young, English-speaking males, often working from their bedrooms, motivated by online notoriety more than financial gain, although $1 million in cryptocurrency was seized from the hackers. Cybersecurity experts warn that while arrests may degrade specific groups, the underlying issue of young individuals being drawn into cybercrime persists, requiring broader societal intervention.