Two key figures in one of the most disruptive cybercrime groups of recent years admitted their roles in attacks on Transport for London, UK retailers, and US healthcare providers.
Summary
- Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty on the first day of their UK trial to charges related to the August 2024 Transport for London cyberattack.
- Flowers separately admitted involvement in hacking US healthcare providers SSM Health Care Corporation and Sutter Health in September 2024.
- US prosecutors allege Jubair helped coordinate 120 network intrusions against 47 US entities, with victims paying at least $115 million in ransom.
- Jubair co-ran a Telegram-based SIM-swapping operation called Star Chat, which sold access to redirected phone numbers to intercept calls and MFA codes.
- Scattered Spider prosecutions are continuing globally, with three additional US defendants still facing charges and sentencing dates set for others.
Guilty Pleas End Trial Before It Begins
What was expected to be a six-week criminal trial in the United Kingdom concluded before it could start. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall each pleaded guilty on the first day of proceedings to conspiring to commit unauthorised acts against Transport for London computer systems and causing risk of serious damage to human welfare. The August 2024 attack on Transport for London disrupted the public transport network across Greater London. Both men are scheduled to be sentenced in a London court on 15 July 2026.
A Pattern of Escalating Intrusions
The charges extend well beyond the TfL incident. Flowers admitted involvement in the September 2024 compromise of US healthcare providers SSM Health Care Corporation and Sutter Health. Multiple sources familiar with the investigation have also identified Flowers as the Scattered Spider member who gave anonymous media interviews in the wake of the group’s September 2023 ransomware attacks against MGM Resorts and Caesars Entertainment in Las Vegas. Jubair and Flowers were arrested in the UK in July 2025 in connection with ransomware attacks on UK retailers Marks & Spencer, Harrods, and the Co-op Group.
The US Indictment: Scale and Financial Impact
In September 2025, prosecutors in New Jersey unsealed an indictment naming Jubair and other Scattered Spider members in connection with 120 network intrusions against 47 US entities between May 2022 and September 2025. Victims paid at least $115 million in ransom payments across those incidents, according to prosecutors. Jubair is also wanted by US law enforcement. The indictment alleges computer fraud, wire fraud, and money laundering.
SIM Swapping as an Operational Foundation
A significant part of the group’s capability rested on a Telegram channel called Star Chat, which Jubair co-ran. The channel hosted a SIM-swapping service that used voice and SMS-based phishing to steal credentials from employees at major wireless carriers in the US and UK. Operators would then redirect a target’s phone number to an attacker-controlled device, allowing interception of calls, SMS messages, and one-time MFA codes. Receipts cited in reporting show the service was used against T-Mobile customers after the group obtained access to internal T-Mobile employee tools.
The 2022 SMS Phishing Campaign
US prosecutors also allege Jubair participated in a mass SMS phishing campaign during the summer of 2022 that harvested single sign-on credentials from employees at hundreds of organisations. That campaign resulted in intrusions and data theft at more than 130 organisations, including LastPass, DoorDash, Mailchimp, Plex, and Signal. Fellow Scattered Spider member Tyler Buchanan pleaded guilty in April 2026 to wire fraud conspiracy and aggravated identity theft for his role in the same campaign. Prosecutors say Buchanan, Jubair, and others used harvested credentials to steal at least $8 million in cryptocurrency from US victims. Buchanan’s sentencing is scheduled for 2 October.
Broader Group Accountability
In August 2025, Noah Michael Urban, 20, a Florida-based Scattered Spider member, was sentenced to ten years in federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy. Three additional defendants indicted alongside Buchanan — Ahmed Hossam Eldin Elbadawy of Texas, Evans Onyeaka Osiebo of Dallas, and Joel Martin Evans of North Carolina — still face charges. What is notable across this group is the youth of the individuals involved: several were teenagers when the offences began, and one was allegedly selling fraudulent emergency data requests to extract subscriber information from tech companies at age 15.
Why it matters
Scattered Spider is not a nation-state actor or a sophisticated criminal enterprise operating in the shadows — it is a loosely affiliated group of young English-speaking individuals who caused $115 million in ransomware losses, disrupted critical public transport infrastructure, compromised healthcare systems, and breached more than 130 organisations largely through social engineering, SIM swapping, and SMS phishing. For CISOs, this case is a pointed reminder that the threat vector is often the human layer: carrier employees, helpdesk staff, and SSO credential holders. The group’s operational playbook — intercept MFA codes, harvest SSO credentials, move laterally — is well-documented and replicable. The ongoing US prosecutions suggest law enforcement attention to this cluster remains active, but deterrence alone is not a control.
What to do now
- Review whether your organisation’s MFA implementation relies on SMS or voice-based one-time codes, which are vulnerable to SIM-swapping interception, and assess migration to hardware tokens or phishing-resistant authentication.
- Assess helpdesk and carrier account management processes for susceptibility to voice phishing and social engineering, particularly procedures that allow phone number changes or account recovery without robust identity verification.
- Ensure SSO and single sign-on credential compromise scenarios are included in your incident response and threat modelling exercises, given this group’s documented success in harvesting and leveraging those credentials at scale.
- Review your organisation’s exposure to emergency data request fraud — verify that your process for responding to law enforcement data requests includes validation of the requesting agency’s identity and the legitimacy of the request channel.
- Check whether any of your organisation’s third-party providers — particularly in communications, identity, or logistics — were among the 130-plus organisations affected by the 2022 SMS phishing campaign, and assess residual supply chain risk.
