Scattered Spider Jailed Over TfL: Bought Credentials and One Help Desk Call Took Down 148 Systems

Jubair and Flowers got five years six months each for the 2024 TfL attack: 148 systems down, ~28,000 staff resetting passwords in person, £29m lost. The court heard the way in was partial credentials bought on a forum and a social-engineered help desk call. The playbook has not changed.

Share
Scattered Spider Jailed Over TfL: Bought Credentials and One Help Desk Call Took Down 148 Systems

Two members of Scattered Spider received prison terms at Woolwich Crown Court today, five years and six months each, for their 2024 attack on Transport for London. Thalha Jubair, 20, and Owen Flowers, 18, were both teenagers at the time.

Thalha Jubair, 20 on the left and Owen Flowers, 18 right side.

The attack left 148 TfL systems unable to operate. Approximately 28,000 employees had to attend an office to have their passwords reset in person. Customer data was exposed. It cost TfL somewhere in the region of £29m in losses and recovery. Trains and buses kept running. Almost everything else did not.

A telephone call was how they got in, according to what the court heard.

Jubair and Flowers purchased incomplete TfL credentials through well-known criminal forums. They then contacted the TfL help desk, impersonated an employee, and convinced the worker on the other end to reset that account's password. From there they reset the two-factor authentication (2FA) on employee accounts, which took several attempts before it finally worked. No zero-day. No exotic malware. A fragment of a credential bought off a forum and a compelling phone call to an organisation that exists to be helpful. Neither the NCA's nor the CPS's written releases describe this method - it only came out during the hearing, which is the only reason defenders get to learn from it.

This is the entire modus operandi behind Scattered Spider, and the reason they are so difficult to disrupt. They use native English speakers who telephone your help desk. The manner in which this occurs bypasses nearly every expenditure a security department makes, because nothing is being exploited. Everything is being handed over.

The legal aspect is worth a moment too. Both men pleaded guilty on 22 June, the day their trial was due to start, qualifying for a 15% reduction in sentence. The charge was Section 3ZA of the Computer Misuse Act 1990, the most severe offence within the Act, covering unauthorised acts that cause, or create a significant risk of, serious damage. They admitted it on the basis that they were reckless as to whether they created a significant risk of serious damage to human welfare, rather than that they intended it. The NCA considers this only the second prosecution of its kind, while the CPS believes they are the first hackers successfully convicted under 3ZA - the previous case involved a former GCHQ intern, and the NCA has said there are no parallels between the two.

How two Scattered Spider members breached Transport for London and what it cost. Panels cover the impact (148 systems down, ~28,000 staff resetting passwords in person, £29m), the entry route of bought credentials plus a social-engineered help desk call, the five year six month sentences under Section 3ZA of the Computer Misuse Act 1990, and the help desk controls that stop the technique.

This next part should put an end to any consideration of this as a closed matter. Jubair is also currently wanted in the United States. In September 2025, a complaint was made public in the District of New Jersey charging him with conspiracies to commit computer fraud, wire fraud and money laundering over at least 120 separate network intrusions from May 2022 through September 2025, affecting 47 US entities, with victims paying no less than $115m in ransom payments. Alleged targets included US critical infrastructure and the federal court system. According to investigators, a cryptocurrency wallet on a server linked to Jubair held approximately $36m when it was seized, and approximately $8.4m was transferred out while the FBI was gaining control of the server. Flowers, for his part, also admitted breaking into two US healthcare organisations, SSM Health and Sutter Health.

FBI Statement

This is not some lone-teenager story. Jubair appears throughout years of the same ecosystem under handles including EarthtoStar and Operator, and Krebs on Security identified him in LAPSUS$ internal chats in 2022 under the nicknames Amtrak and Asyntax. Prosecutors also connect him to a large-scale SMS phishing run in 2022 that harvested single sign-on credentials from employees at hundreds of companies using fake Okta login pages. The NCA has repeatedly refused to confirm or deny whether either individual participated in other incidents attributed to Scattered Spider.

The model keeps producing people. An additional alleged Scattered Spider member was extradited to the US this month on conspiracy, computer intrusion and fraud charges. The method has outlasted its practitioners, too: in January, Mandiant reported activity branded as ShinyHunters using the same play - vishing calls to employees, victim-branded credential harvesting pages to capture single sign-on (SSO) logins and multi-factor authentication (MFA) codes, then registering the attacker's own device for MFA. Same phone call, different brand. The NCA's 2024 research found that 20% of UK children aged 10 to 16 engage in behaviour that violates the Computer Misuse Act, rising to 25% among those who game. That is the recruitment pool for a crew whose main tool is a credible voice on the telephone.

Where This Leaves Defenders

The sentencing does not decrease your vulnerability by even one percent. Two people have been convicted and sentenced, yet the technique that cost TfL £29m remains unchanged, continues to be used today, and has now been detailed publicly in an open courtroom as the reason they succeeded.

The failure at TfL was a lack of control over a human workflow, and that is where the fix has to go. Every identity-changing action your service desk can perform requires verification that a caller cannot simply talk their way through: password resets, MFA and 2FA resets, and device enrolment. Never rely on voice alone, and treat urgency and seniority as pressure tactics rather than evidence. Call back on a number from the directory rather than one the caller supplies, require manager attestation or video verification for privileged accounts, and log every reset so that repeated 2FA reset attempts against the same account generate an alert instead of being quietly retried until one lands.

Google's guidance from the same body of research says the same thing: verify identity on password resets, device enrolment and MFA changes, because those manual workflows are exactly what these crews ring up and talk through.

Two things beyond the service desk. This attack began with partial credentials purchased on a forum, so monitor credential markets and stealer logs for your own domains, and treat any partial credential you find as a live lead rather than noise - it is the raw material for exactly this call. And note that the group works in waves through one sector at a time: if a peer in your industry has just been hit, you are not a bystander, you are in the wave, and your help desk is about to get a phone call.

Read more