Teenage hackers sentenced to 5.5 years for Transport for London cyber-attack costing £39m
Two teenagers, Thalha Jubair (20) and Owen Flowers (19), have been jailed for five and a half years following a 2024 cyber-attack on Transport for London that compromised critical IT systems. The breach, which granted the pair extensive unauthorized access to TfL's digital infrastructure, resulted in an estimated £39m in damages and was described in court as providing the attackers with "the keys to the kingdom" to the transport authority's network.
The duo conducted their 16-hour breach while livestreaming their activities online, exploiting vulnerabilities in TfL's domain systems. Both were characterised during sentencing as computer-focused teenagers with autism who had limited social connections outside their technical interests, highlighting how skilled threat actors operating independently of organised crime networks can inflict substantial damage on critical infrastructure.
- Two teenagers sentenced to 5.5 years for a 2024 cyber-attack on Transport for London's systems
- The breach provided extensive access to critical infrastructure and caused approximately £39m in damages
- The pair livestreamed their 16-hour attack and were both described as socially isolated individuals with autism
New here? Start with this
Two teenagers, Thalha Jubair and Owen Flowers, have been sentenced over a major cyber-attack on Transport for London, the body that runs London's buses, tubes and other transport services. The attack took place in 2024 and allowed the pair to break deep into TfL's computer systems, causing an estimated £39m in damage and disruption.
TfL manages transport for millions of people daily, so an attack that breaches its core IT systems raises concerns well beyond one organisation, touching on how vulnerable public infrastructure can be to attacks carried out by individuals rather than large criminal or state-backed groups. The case has also drawn attention because the two men were young, self-taught and acting independently, rather than as part of an organised hacking operation.
The sentencing marks the legal conclusion of the case, but it sits within wider ongoing debate about the cybersecurity of public services and how the justice system should treat young offenders with advanced technical skills.
Both sides, in good faith
The strongest fair case each way — we don't pick a winner.
The case for
Those who support the severity of this sentence argue that critical national infrastructure demands robust deterrence regardless of the perpetrators' age or personal circumstances. Transport for London serves millions of people daily, and a 16-hour breach causing £39m in damage demonstrates the real-world harm such intrusions can inflict on essential services. Courts, they argue, must send an unambiguous signal that compromising infrastructure of this scale carries serious consequences, both to deter other technically skilled young people tempted by similar exploits and to reassure the public that critical systems are protected by meaningful legal consequences.
The case against
Those who view this sentence as too harsh argue that the defendants' youth, autism, and apparent lack of connection to organised crime or malicious profit motives should have weighed more heavily in sentencing, pointing to concerns that the justice system risks treating technically gifted but socially isolated young people as hardened criminals rather than addressing the underlying vulnerabilities that led them down this path. They contend that a lengthy custodial sentence may do little to rehabilitate individuals whose actions, however damaging, appear to stem from technical fascination and thrill-seeking rather than calculated criminal intent, and that alternative approaches focused on redirecting such skills constructively might better serve both the individuals and society.
Coverage
- The Guardian — ‘Keys to the kingdom’: hackers who gained access to heart of London transport network jailed
- BBC Technology — Teenage hackers jailed over TfL cyber-attack livestream