UK Court Jails Two Men for Major Cyberattack on London’s Transport Network
Poinews.com – In a recent ruling, a UK court sentenced two individuals to prison terms for their involvement in a significant cyberattack on London’s public transport system. The breach, which occurred in 2024, led to the exposure of personal data for millions of passengers, marking one of the largest data incidents in Britain’s history.
Convictions and Sentences
Thalha Jubair, 20, from east London, and Owen Flowers, 18, from the West Midlands, received five-and-a-half-year sentences at Woolwich Crown Court. The pair admitted to hacking Transport for London’s network between August 31 and September 3, 2024, during which they accessed the names and contact details of approximately seven million customers.
“Two individuals have been convicted for orchestrating a cyber attack on Transport for London, resulting in substantial financial losses and affecting numerous passengers,” stated City of London Police on X.
Attack Details and Impact
The cyber intrusion did not halt daily operations but caused prolonged system outages, keeping parts of TfL’s infrastructure offline for three months. Judge Mark Turner noted the attack’s “very serious” consequences, citing damages of around £25 million. The hackers, who operated for 16 hours straight, used Telegram to coordinate their activities after tricking the helpdesk into resetting an employee’s password.
Method of Breach
Prosecutor Mark Fenhalls revealed that the attackers obtained TfL employee credentials through a dark web marketplace called “russianmarket.” With these login details, they infiltrated the network and explored data, including celebrities’ travel records and customers’ payment information. Over several days, they escalated their access, ultimately gaining full control of the transport system, according to the prosecutor.
“The hackers effectively held the keys to the kingdom, allowing them to manipulate the entire network,” said Fenhalls, emphasizing their technical skill and the extent of their access.
Connections to Cybercrime Group
Both men are associated with Scattered Spider, a cybercrime collective linked to multiple high-profile incidents. These include attacks on British retailers Marks & Spencer and the Co-op. The National Crime Agency (NCA) arrested the pair in September 2025, following an investigation that uncovered their long-standing ties to police records.
Flowers also confessed to targeting US healthcare organizations, Sutter Health and SSM Health Care Corporation. The NCA discovered his activities during a home raid on September 6, 2024, as part of the broader TfL probe. Jubair had earlier been convicted in a juvenile case for hacking the US chipmaker Nvidia and admitted to breaching the City of London Police’s systems.

