Policy & Regulation
U.K. jails two teenage hackers behind Scattered Spider attacks
Two U.K. teenagers were sentenced to five years and six months in prison for a London transit hack costing around £29 million; police say it severely disrupted Scattered Spider.
Owen Flowers, 18, and Thalha Jubair, 20, pleaded guilty earlier this year to hacking Transport of London (TfL), the government body overseeing the U.K. capital’s public transit system, in 2024. The cyberattack, carried out in summer 2024, took TfL’s infrastructure offline for weeks and caused losses of around £29 million (around $47 million), according to authorities. The pair was sentenced to five years and six months in prison on Thursday.
U.K. police said Thursday that jailing the two hackers has severely hampered the activities of Scattered Spider, the infamous cybercrime group, and British authorities say the convictions represent a significant blow to the network. The hackers had such deep access to TfL’s systems that they could have shut out and shut down TfL completely, according to the Guardian. Paul Foster, the head of the U.K. National Crime Agency’s National Cyber Crime Unit (the U.K.’s national law enforcement agency), said: “Scattered Spider has been the most significant cybercrime threat to the U.K. in recent years. Through this investigation, we have severely disrupted that threat and brought key offenders to justice.”
Scattered Spider and ShinyHunters, another cybercriminal collective, often target and exploit employees and individuals rather than computer systems, a tactic that’s both effective and hard to counter. The FBI accused Jubair of being involved in attacks on more than 120 companies using social engineering tactics. Scattered Spider itself has been linked to dozens of high-profile attacks, including those against casino giant MGM, airline WestJet, and cybersecurity firm Okta. Hacking groups’ members tend to come and go, and the groups themselves can rebrand.
Why it matters
The convictions mark a major blow against Scattered Spider, showing that law enforcement can dismantle decentralized cybercrime networks that rely on social engineering rather than sophisticated software.