A UK court sentences an 18-year-old and a 20-year-old to five and a half years each for a 2024 attack that exposed seven million passengers’ data and cost £29 million to remediate.
Summary
- Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five years and six months at Woolwich Crown Court — the largest cybercrime prosecution in UK history.
- The attackers bought partial TfL credentials from criminal forums, socially engineered a helpdesk worker to reset 2FA, and maintained network access for four days.
- Data on approximately seven million users was accessed; remediation costs reached £29 million, and roughly 28,000 staff had to attend offices in person to reset passwords.
- The convictions relied heavily on forensic analysis of a seized laptop, which contained attack videos, spreadsheets of stolen credentials, and cryptocurrency payment trails.
- The NCA flagged a legislative gap: proposed Cyber Crime Risk Orders could have enabled earlier intervention, as existing serious crime powers do not apply to offenders under 18.
The sentences
Owen Flowers and Thalha Jubair were sentenced on Thursday at Woolwich Crown Court to five years and six months’ imprisonment each. Both pleaded guilty in June, receiving a 15 percent sentence reduction as a result. Sentencing judge Mr Justice Turner acknowledged the defendants’ youth and neurodiversity — both have autism; Jubair also carries diagnoses of depression and severe mood disorder — but weighed those factors against the sophistication of the offending, the scale of impact on critical infrastructure, and the pair’s clear awareness that their conduct was criminal.
A landmark prosecution
The NCA described this as the largest cybercrime prosecution ever brought before UK courts and only the second conviction under Section 3ZA of the Computer Misuse Act 1990, a provision reserved for unauthorised computer acts that cause, or create a significant risk of, serious damage. The pair pleaded guilty on the basis of recklessness rather than intent. The only prior Section 3ZA conviction involved a former GCHQ intern jailed for six years following a national security investigation; the NCA was explicit that the two cases share no parallels.
How the attack was carried out
Flowers and Jubair purchased partial TfL employee credentials from criminal forums and used them to initiate 2FA resets on staff accounts across multiple attempts. They then impersonated an employee and socially engineered a TfL helpdesk worker into resetting a password — a textbook vishing play consistent with Scattered Spider’s known tradecraft. The pair gained access to TfL’s network on 31 August 2024 and held that access until 3 September, during which time they worked to elevate privileges and reach internal databases. The full scope of the data exposure — approximately seven million users — only became clear earlier this year.
Operational and financial impact
While train and bus services continued running, the attack disrupted customer-facing systems significantly. Account logins, customer portals, and third-party apps reliant on TfL data all suffered degraded availability. TfL could not issue photo travel cards until 4 December 2024. A number of ticket machines malfunctioned, and contactless card users were unable to view journey histories online. All approximately 28,000 TfL employees — a substantial proportion of whom worked remotely — were required to attend offices in person for password resets. Total remediation costs reached £29 million.
The forensic trail that sealed the case
Flowers’ arrest on 6 September 2024 at his Walsall home proved decisive. Officers seized laptops, tower computers, and USB storage devices. Analysis of one Acer laptop revealed that Flowers had accessed the remote infrastructure and virtual machines used in the attack. More significantly, he had recorded videos and screenshots of the attack in progress — the pair reportedly livestreamed the 16-hour operation online. Investigators traced cryptocurrency payments for the attack infrastructure back to an account on Flowers’ machine, the same account he used to order food deliveries to his home address. The laptop also held spreadsheets of partial TfL employee credentials and artefacts linking activity to Jubair, including a shared alias tied to flight bookings, hotel reservations, and food orders traceable to the 20-year-old. A cloud storage account containing TfL data was found accessible to both.
Prior history and missed intervention
Jubair’s criminal history is extensive: 22 prior convictions in the UK, including 13 for fraud and one for blackmail, with offending beginning at age 14. He was previously convicted in 2023 for involvement with the Lapsus$ group — which targeted BT/EE and Nvidia, among others — and received an 18-month youth rehabilitation order, including a VPN ban, before quickly reoffending. He also faces unsealed US charges covering alleged compromise of 120 networks belonging to 47 entities, with more than $115 million in ransom payments attributed to that activity. Flowers, for his part, was visited by police in October 2023 and handed a cease-and-desist, offered training on CMA offences, and declined to engage. He continued offending at increasing severity through to the TfL attack.
The legislative gap
NCA Deputy Director Paul Foster highlighted that existing legal tools — including serious crime prevention orders — cannot be applied to offenders under 18, and that some CMA offences fall below the threshold required for such orders. He argued that the proposed Cyber Crime Risk Orders, flagged in the most recent King’s Speech, would have provided a proportionate mechanism to impose conditions on Flowers sooner, with breach carrying criminal sanctions regardless of whether an underlying investigation has concluded. Foster indicated that such orders could have enabled earlier action based on intelligence from US and Australian partners.
Why it matters
This case is a concrete illustration of how a credential purchase on a criminal forum, combined with a single successful helpdesk social engineering call, can result in seven million customers’ data being exposed, £29 million in remediation costs, and months of operational disruption to critical infrastructure. For CISOs, the attack method was not exotic — it was credential theft plus vishing plus privilege escalation — which means the controls to frustrate it are known and available. The NCA’s explicit acknowledgement that early engagement with law enforcement was material to achieving conviction is also a direct signal: organisations that hold back from reporting incidents may reduce their own chances of seeing perpetrators prosecuted.
What to do now
- Review helpdesk identity verification procedures: ensure that password resets and 2FA changes cannot be completed based solely on a caller claiming to be an employee — require out-of-band verification against a second, independently held identity attribute.
- Treat partial credential exposure as a full compromise signal: the attackers started with credentials purchased from forums; monitor for your organisation’s credentials appearing in criminal marketplaces and act on those alerts promptly.
- Establish and rehearse early engagement protocols with law enforcement: the NCA noted that TfL’s early reporting was a direct factor in making prosecution possible.
- Audit remote-worker access controls: the requirement to recall 28,000 staff for in-person password resets reflects gaps in out-of-band identity assurance for a largely remote workforce — address those before an incident occurs.
- Assume longer dwell time than initial forensics suggest: TfL’s initial estimate of around 5,000 affected records was revised to approximately seven million months later; plan incident scope assessments with appropriate conservatism.
