Scattered Spider Hackers Plead Guilty in Transport for London Attack

Two members of the notorious Scattered Spider cybercrime group admit to roles in a crippling August 2024 attack on London's transport network.

By Central
Thalha Jubair and Owen Flowers pleaded guilty in London court for the Transport for London cyberattack.
Highlights
  • Scattered Spider members Thalha Jubair and Owen Flowers pleaded guilty to conspiring against Transport for London systems.
  • The group's tactics include SIM-swapping and SMS phishing, bypassing multi-factor authentication to steal credentials.
  • Victims of Scattered Spider's broader campaign have paid at least $115 million in ransom payments.

Two members of the prolific cybercrime group Scattered Spider have pleaded guilty in the United Kingdom to charges stemming from a cyberattack that crippled Transport for London (TfL) in August 2024. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, entered their pleas on the first day of what was expected to be a six-week trial, admitting to conspiring to commit unauthorized acts against TfL computer systems and causing risk of serious damage to human welfare.

Scattered Spider’s Broader Campaign of Ransomware and SIM-Swapping

The guilty pleas in the TfL case represent a significant development in the long-running investigation into Scattered Spider, a loose-knit but highly effective group known for its sophisticated social engineering tactics, including SIM-swapping and targeted SMS phishing. Flowers separately admitted to being part of a conspiracy to hack into U.S.-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.

Jubair remains wanted by U.S. law enforcement. In September 2025, prosecutors in New Jersey unsealed an indictment alleging he and other Scattered Spider members committed computer fraud, wire fraud, and money laundering in connection with 120 computer network intrusions involving 47 U.S. entities between May 2022 and September 2025. The government states that victims of the group paid at least $115 million in ransom payments.

Star Chat Telegram Channel and SIM-Swapping Operations

According to prosecutors, Jubair co-ran a Telegram channel called Star Chat, which operated as a marketplace for SIM-swapping services. The group used voice- and SMS-based phishing to steal credentials from employees at major wireless providers in the U.S. and U.K., then sold the ability to redirect a target’s phone number to a device the attackers controlled. This allowed them to intercept calls and text messages, including one-time codes for multi-factor authentication, effectively bypassing a key security control.

New Jersey prosecutors also allege Jubair was involved in a mass SMS phishing campaign during the summer of 2022 that stole single sign-on credentials from employees at hundreds of companies. That weeks-long campaign led to intrusions and data thefts at more than 130 organizations, including LastPass, DoorDash, Mailchimp, Plex, and Signal.

One of Jubair’s earlier hacker aliases, “Everlynn,” was linked to the sale of fraudulent “emergency data requests” that used compromised police and government email addresses to demand subscriber data from major tech companies, bypassing normal legal processes.

Flowers Identified as Anonymous Media Source After MGM Attack

Multiple sources familiar with the investigations have identified Flowers as the Scattered Spider member who anonymously gave interviews to the media in the days after the group’s September 2023 ransomware attacks disrupted operations at Las Vegas casinos operated by MGM Resorts and Caesars Entertainment. Flowers and Jubair were arrested in the U.K. in connection with Scattered Spider ransom attacks against retailers Marks & Spencer and Harrods, as well as the British food retailer Co-op Group.

Other Scattered Spider Members Facing Justice

The guilty pleas follow a series of legal actions against Scattered Spider members. In April 2026, 24-year-old British national Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft for his role in the group’s 2022 SMS phishing spree. The government stated that Buchanan, Jubair, and others used stolen credentials to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan is scheduled for sentencing on October 2.

In August 2025, 20-year-old Scattered Spider member Noah Michael Urban of Florida was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy. Three other alleged Scattered Spider defendants indicted alongside Buchanan still face charges: Ahmed Hossam Eldin Elbadawy (a.k.a. “AD”), 24, of College Station, Texas; Evans Onyeaka Osiebo, 21, of Dallas, Texas; and Joel Martin Evans (a.k.a. “joeleoli”), 26, of Jacksonville, North Carolina.

Sentencing and What Affected Users Should Do Now

Flowers and Jubair are slated to be sentenced in a London court on July 15, 2026. For individuals and organizations concerned about similar attacks, the primary takeaway is that SIM-swapping and SMS-based phishing remain highly effective because they target the weakest link in authentication: the phone number. Users should protect their mobile accounts with a PIN or password set directly with the carrier, and avoid using SMS as a sole method for multi-factor authentication. A zero-knowledge password manager combined with an authenticator app or hardware security key provides substantially stronger defense. Organizations should implement phishing-resistant multi-factor authentication, restrict employee access to carrier tools, and deploy endpoint protection solutions capable of detecting social engineering attempts. Anyone who suspects they may have been targeted by the 2022 SMS phishing campaign should immediately change passwords for all sensitive accounts, review account recovery settings, and monitor financial accounts for unauthorized activity.

Share This Article