Teenage hackers jailed over TfL cyber-attack livestream
Developed over time first seen 3 months ago
Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, have each been sentenced to five years and six months in prison for a 2024 cyber-attack on Transport for London that they carried out as teenagers while livestreaming the 16-hour hack. Woolwich Crown Court heard the pair, both described as computer-obsessed loners with autism diagnoses and few offline friends, pleaded guilty in June to an attack linked to the Scattered Spider hacking collective, which the National Crime Agency says exemplifies the growing threat posed by young cyber criminals in the UK and has also been tied to attacks on Marks & Spencer and the Co-op.
The attackers tricked a phone help desk worker into resetting a TfL employee's password, gaining access to a database of Oyster card customers, searching it for celebrities' details and attempting to reach banking information; TfL says the breach exposed data on as many as 10 million customers, which is still circulating in criminal groups, and forced all 27,000 staff to reset passwords in person. The hack knocked out 148 technology systems, disrupting services including the Dial-a-ride scheme for disabled and vulnerable Londoners, and cost TfL an estimated £29m plus £10m in lost income. The judge cited the men's youth and autism diagnoses as mitigating factors in sentencing.
- Two Scattered Spider hackers jailed 5.5 years each over TfL cyber-attack
- Hack exposed data of up to 10 million TfL customers, cost £39m total
- Judge cited defendants' youth and autism as mitigating factors
New here? Start with this
Transport for London, usually known as TfL, runs much of the capital’s public transport network, including the Tube, buses and some rail services. It also manages Oyster cards, the electronic travel cards used by millions of people to pay for journeys.
Cyber-attacks often begin when criminals persuade a worker to give them access to an organisation’s computer systems, rather than breaking through technical defences directly. Once inside, they may seek personal data, disrupt services or use the access to reach other systems.
Scattered Spider is the name used for a loosely connected group of mainly young hackers linked to attacks on major companies in several countries. The case highlights concerns about the potential scale of disruption when organisations holding large amounts of customer data are targeted.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
These attacks caused severe, measurable harm—disrupting transport for disabled Londoners, exposing 10 million people's data, and inflicting over £39m in costs. The perpetrators demonstrated deliberate planning and technical sophistication; whilst courts properly weighed youth and autism as mitigating factors, proportionate sentencing reflecting the gravity of harm serves essential purposes of accountability and deterrence.
The case against
These are neurodivergent teenagers with significant social isolation, and lengthy custodial sentences risk entrenching rather than remedying the vulnerabilities that contributed to their offending. Autism spectrum conditions often impair understanding of social consequences, and research increasingly supports rehabilitation-focused, community-based interventions with mental health support as more effective at preventing reoffending, particularly for young people whose development continues into their twenties.
More coverage
Read the full article at the source →
Originally published by BBC Technology as “Teen hackers jailed after live streaming cyber-attack on TfL”.