The cyberattack in question, which took place in August 2024, inflicted significant operational paralysis upon Transport for London (TfL), the vital public transportation authority responsible for the vast network serving the Greater London area. The severity of the attack and its impact on a critical infrastructure entity underscore the sophisticated and destructive capabilities of groups like Scattered Spider. The guilty pleas entered by Thalha Jubair, a 20-year-old from East London, and Owen Flowers, an 18-year-old from Walsall, represent a major victory for law enforcement agencies on both sides of the Atlantic.
Both Jubair and Flowers admitted to serious criminal offenses. Specifically, they pleaded guilty to conspiring to commit unauthorized acts against Transport for London’s computer systems, a charge that highlights their direct involvement in the technical execution of the hack. Furthermore, they admitted to causing risk of serious damage to human welfare, a grave accusation that reflects the potential life-threatening consequences of disrupting essential public services. The BBC reported that Owen Flowers also confessed to his participation in a separate conspiracy to hack into U.S.-based healthcare providers, specifically SSM Health Care Corporation and Sutter Health, in September 2024. This dual confession demonstrates the group’s broad operational scope and their willingness to target diverse and sensitive sectors.
Thalha Jubair’s legal troubles extend significantly into the jurisdiction of U.S. law enforcement. In September 2025, prosecutors in New Jersey unsealed a comprehensive indictment that paints a detailed picture of Jubair’s alleged criminal activities and those of his Scattered Spider associates. The indictment accuses Jubair and other members of the group of engaging in a pattern of sophisticated criminal behavior, including computer fraud, wire fraud, and money laundering. These charges are linked to an astonishing 120 separate computer network intrusions that targeted 47 entities across the United States between May 2022 and September 2025. The financial scale of these operations is equally staggering, with the indictment alleging that the group’s victims collectively paid at least $115 million in ransom demands. This figure highlights the immense financial motivation behind Scattered Spider’s cybercrime campaigns.
The arrests of Flowers and Jubair in the United Kingdom in July 2025 were not an isolated event. KrebsOnSecurity had previously reported on these arrests in connection with Scattered Spider’s involvement in high-profile ransomware attacks. These attacks specifically targeted prominent British retailers, including Marks & Spencer, Harrods, and the Co-op Group. Multiple sources with intimate knowledge of these investigations indicated that Owen Flowers was the individual who, under an anonymous guise, granted interviews to the media in the immediate aftermath of the group’s September 2023 ransomware attacks. These attacks notoriously disrupted operations at major Las Vegas casinos operated by MGM Resorts and Caesars Entertainment, causing widespread chaos and significant financial losses. Flowers’ role as a media spokesperson, even anonymously, suggests a calculated effort to control the narrative and potentially deflect scrutiny.
Delving deeper into the operational mechanics of Scattered Spider, prosecutors have shed light on Thalha Jubair’s pivotal role in managing a highly active Telegram channel known as "Star Chat." This platform served as a hub for a sophisticated SIM-swapping operation. SIM swapping, a malicious technique, involves tricking mobile carriers into transferring a victim’s phone number to a device controlled by the attacker. Jubair’s group employed a combination of voice- and SMS-based phishing attacks to steal employee credentials from major wireless providers in both the U.S. and the U.K. Once access to internal carrier systems was gained, the attackers could then reroute a victim’s phone number, intercepting all incoming calls and text messages. This capability is particularly dangerous as it allows for the bypass of multi-factor authentication (MFA) protocols, including the one-time passcodes (OTPs) crucial for securing online accounts. The image accompanying the original report, a receipt from "Star Fraud Chat" demonstrating a SIM-swapping service targeting a T-Mobile customer, vividly illustrates the tangible nature of these illicit operations. The alias "Rocket Ace," identified as one of Jubair’s hacker handles by U.S. prosecutors, further personalizes the threat.

The New Jersey prosecutors’ indictment also implicates Jubair in a large-scale SMS phishing campaign that occurred during the summer of 2022. This weeks-long campaign was designed to steal single sign-on (SSO) credentials from employees across hundreds of companies. The harvested credentials led to significant intrusions and data thefts at over 130 organizations, including highly recognizable names like LastPass, DoorDash, Mailchimp, Plex, and Signal. The breadth of these targets underscores the pervasive reach of Scattered Spider’s operations. Furthermore, KrebsOnSecurity previously revealed that one of Jubair’s aliases, used when he was just 15 years old, was "Everlynn." As "Everlynn," he was involved in selling fraudulent "emergency data requests." These requests, often impersonating law enforcement or government agencies by using compromised email addresses, were designed to coerce major tech companies into surrendering sensitive subscriber data, such as usernames, IP addresses, and email addresses, under the guise of urgent, life-or-death matters that could not await a court order.
The legal consequences for Scattered Spider members are mounting. In April 2026, Tyler Buchanan, a 24-year-old British national and another alleged member of Scattered Spider, pleaded guilty to conspiracy to commit wire fraud and aggravated identity theft. His plea was in direct connection with the group’s 2022 SMS phishing spree. The U.S. government stated that Buchanan, along with Jubair and others, used the credentials obtained through this phishing campaign to steal at least $8 million in cryptocurrency from victims across the United States. Buchanan is currently awaiting sentencing, scheduled for October 2.
Adding to the tally of apprehended and convicted members, Noah Michael Urban, a 20-year-old Scattered Spider member from Florida, was sentenced to 10 years in federal prison in August 2025. He was also ordered to pay $13 million in restitution after pleading guilty to charges of wire fraud and conspiracy. Urban’s significant sentence reflects the severity of his involvement and the financial impact of his crimes.
The U.S. Department of Justice continues to pursue charges against other alleged Scattered Spider defendants who were indicted alongside Buchanan. These individuals include Ahmed Hossam Eldin Elbadawy, 24, also known as "AD," from College Station, Texas; Evans Onyeaka Osiebo, 21, from Dallas, Texas; and Joel Martin Evans, 26, known as "joeleoli," from Jacksonville, North Carolina. These ongoing legal actions signal a sustained effort by U.S. authorities to dismantle the Scattered Spider organization.
The immediate future for Owen Flowers and Thalha Jubair involves their sentencing, which is slated to take place in a London court on July 15, 2026. Their guilty pleas, occurring on the first day of their trial, represent a significant turning point, potentially sparing the court system a prolonged legal battle and offering a measure of closure to the victims of their criminal activities. The swiftness of their admission of guilt suggests a calculated strategy, possibly to mitigate harsher sentences or to avoid the full public exposure of their modus operandi during a lengthy trial. The downfall of these young operatives marks a notable success in the global fight against sophisticated cybercrime, highlighting the persistent threat posed by groups like Scattered Spider and the evolving nature of digital law enforcement.

