Scattered Spider Members Plead Guilty Over Transport for London Attack
Enable MFA on all accounts and monitor for SIM‑swap activity to mitigate attacks like those used by Scattered Spider.
Enable MFA on all accounts and monitor for SIM‑swap activity.
Summary
Two men, Owen Flowers (18) and Thalha Jubair (20), pleaded guilty in the United Kingdom on 15 June 2026 to charges stemming from an August 2024 cyberattack that crippled Transport for London.
The duo are key members of the Scattered Spider ransomware group, which also targeted U.S. healthcare providers SSM Health Care and Sutter Health in September 2024, and British retailers Marks & Spencer, Harrods and the Co‑op Group.
Jubair ran the Telegram channel Star Chat, a hub for SIM‑swap and phishing operations that stole credentials from major wireless providers and used them to intercept MFA codes.
The group’s summer 2022 mass SMS phishing campaign compromised credentials at more than 130 organizations, including LastPass, DoorDash, Mailchimp, Plex and Signal, and led to over $115 million in ransom payments.
Other Scattered Spider members have been sentenced or are awaiting sentencing, with the U.S. Department of Justice indicting 120 intrusions involving 47 U.S. entities.
Flowers and Jubair are scheduled for sentencing in a London court on 15 July 2026.
Key changes
- Two men pleaded guilty in the UK to charges from an August 2024 attack on Transport for London
- They are members of the Scattered Spider ransomware group
- They targeted U.S. healthcare providers SSM Health Care and Sutter Health in September 2024
- They also attacked British retailers Marks & Spencer, Harrods and the Co‑op Group
- Jubair ran the Telegram channel Star Chat that facilitated SIM‑swap and phishing operations
- The group’s summer 2022 SMS phishing campaign compromised credentials at 130+ organizations and led to $115 million in ransom