Executive Overview
In a landmark development for international cybersecurity and law enforcement, two key operatives of the notorious, highly prolific cybercrime collective known as Scattered Spider pleaded guilty in a United Kingdom courtroom this week. The admissions of guilt came on the very first day of what was projected to be a grueling six-week trial, bringing a swift and definitive legal reckoning to a pair of young hackers whose digital footprints span multiple continents, high-profile corporate intrusions, and critical infrastructure attacks.
The defendants—Thalha Jubair, 20, of East London, and Owen Flowers, an 18-year-old from Walsall—admitted to serious criminal charges stemming from a devastating August 2024 cyberattack that paralyzed Transport for London (TfL), the municipal body governing the Greater London area’s expansive public transit network. Beyond the crippling of London’s transit infrastructure, the duo’s guilty pleas illuminate a sprawling web of global cybercrime, including high-impact ransomware campaigns against elite British retailers, devastating intrusions into American healthcare giants, large-scale SIM-swapping operations, and multi-million-dollar cryptocurrency thefts.
The case underscores the evolving nature of modern cybercrime syndicates. Unlike traditional, state-sponsored Advanced Persistent Threat (APT) groups, Scattered Spider is largely comprised of digital natives—often young adults and teenagers—who weaponize social engineering, advanced phishing techniques, and relentless determination to breach enterprise networks. With their upcoming sentencing scheduled for July 15, 2026, Flowers and Jubair face the culmination of an intensive, multi-jurisdictional dragnet involving British law enforcement agencies, the U.S. Department of Justice (DOJ), and international investigative journalism.
Detailed Chronology: From Digital Infractions to Global Extortion
The path that led Flowers and Jubair to a UK dock is a sprawling narrative of escalating digital criminality, characterized by a transition from petty cyber-harassment and credential harvesting to industrial-scale corporate extortion.
The London Transport Disruption (August 2024)
The immediate catalyst for the UK prosecution was the August 2024 cyberattack targeting Transport for London. TfL serves as the circulatory system of the UK capital, managing the Underground, buses, London Overground, and critical transit infrastructure. The attack threw the system into disarray, forcing operators to scramble to secure networks, protect sensitive customer data, and prevent systemic failures that posed a direct risk to public welfare.
In court, Jubair and Flowers formally admitted to conspiring to commit unauthorized acts against TfL computer systems. Crucially, they also pleaded guilty to causing a risk of serious damage to human welfare—a severe legal threshold reflecting the potential downstream consequences of disabling critical municipal infrastructure.
The US Healthcare Intrusions (September 2024)
While the TfL hack brought the threat home to British soil, Flowers’ criminal enterprise extended rapidly across the Atlantic. According to reports from the BBC and investigative filings, Flowers separately admitted to participating in a high-stakes conspiracy to infiltrate major U.S.-based healthcare providers, specifically targeting SSM Health Care Corporation and Sutter Health in September 2024. These healthcare intrusions raised immediate alarms among federal regulators, given the life-or-death nature of medical operations and the vulnerability of electronic health record systems to ransomware disruptions.
British Retail and Casino Extortions (2023–2025)
Investigators have long tracked the fluid membership of Scattered Spider as they pivoted between targets of opportunity. In July 2025, further details emerged following arrests coordinated by the UK National Crime Agency (NCA). Flowers and Jubair were linked directly to aggressive ransomware campaigns targeting iconic British brands, including high-end department stores Marks & Spencer and Harrods, as well as the prominent British food retailer Co-op Group.
Furthermore, sources familiar with the global investigation revealed that Owen Flowers was the elusive Scattered Spider insider who orchestrated a bizarre public relations gambit: anonymously granting interviews to mainstream media outlets in the chaotic aftermath of the September 2023 ransomware attacks that crippled Las Vegas casino giants MGM Resorts and Caesars Entertainment. This audacity—taunting investigators while corporate networks bled data—became a hallmark of the collective’s psychological warfare tactics.
Supporting Context & Metrics: The Mechanics of Scattered Spider
To fully understand the gravity of the guilty pleas, one must examine the operational infrastructure that propelled Jubair and Flowers to the upper echelons of the cybercrime underworld.
Star Chat and the SIM-Swapping Industrial Complex
U.S. and British prosecutors detailed how Thalha Jubair co-administered a bustling, highly organized Telegram channel known as Star Chat (or Star Fraud Chat). This platform served as the nerve center for a specialized SIM-swapping syndicate.

The modus operandi of the group relied heavily on voice- and SMS-based phishing attacks targeting frontline employees at major telecommunications and wireless providers in the United States and the United Kingdom. Once internal corporate tools were compromised through social engineering, the hackers wielded administrative access to execute SIM swaps. This illicit service allowed buyers to intercept a targeted individual’s phone number, routing calls and text messages—including critical multi-factor authentication (MFA) one-time passcodes—directly to devices controlled by the criminals. Receipts recovered by investigators showcased automated billing and execution of SIM swaps against major carriers like T-Mobile, where Jubair operated under hacker monikers such as "Rocket Ace."
The 2022 Mass SMS Phishing Campaign
Jubair’s footprint extends back to the summer of 2022, when he allegedly participated in a devastating mass SMS phishing blitz that targeted single sign-on (SSO) credentials across hundreds of corporations. This weeks-long campaign successfully breached more than 130 high-profile organizations, resulting in catastrophic data thefts and corporate intrusions at tech companies including:
- LastPass
- DoorDash
- Mailchimp
- Plex
- Signal
The "Everlynn" Persona and Fake Emergency Data Requests
Investigative reporting by KrebsOnSecurity previously uncovered that Jubair’s digital evolution began early. Operating under the alias “Everlynn” when he was just 15 years old, Jubair sold fraudulent “emergency data requests” (EDRs). By compromising legitimate police and government email accounts, the teenager issued legalistic-sounding demands to major technology platforms, coercing them into handing over sensitive subscriber data—such as usernames, IP addresses, and email logs—under the false pretense of imminent life-or-death emergencies that bypassed standard court-ordered warrants.
International Enforcement and Global Indictments
The dismantling of Scattered Spider is a masterclass in cross-border law enforcement cooperation, bridging the UK National Crime Agency, the U.S. Federal Bureau of Investigation (FBI), and the U.S. Department of Justice.
The New Jersey Indictment and US Warrants
In September 2025, federal prosecutors in New Jersey unsealed a sweeping indictment targeting Jubair and fellow Scattered Spider operatives. The legal documents detailed a staggering scope of criminal activity:
- 120 computer network intrusions across 47 distinct U.S. entities between May 2022 and September 2025.
- At least $115 million in ransom payments extorted from corporate victims.
- Charges encompassing computer fraud, wire fraud, and complex international money laundering schemes.
While Jubair and Flowers face justice in British courts, U.S. authorities continue to pursue extradition and parallel prosecutions for crimes committed on American soil.
The Domino Effect: Guilty Pleas and Sentences Across the Globe
The legal walls have been closing in on Scattered Spider for months, punctuated by a series of high-profile guilty pleas and harsh sentences:
- Tyler “Tylerb” Buchanan: In April 2026, 24-year-old British national and core Scattered Spider member Tyler Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft. Prosecutors established that Buchanan, alongside Jubair and others, leveraged credentials harvested during the 2022 SMS phishing spree to loot at least $8 million in cryptocurrency from victims across the United States. Buchanan’s sentencing is currently slated for October 2.
- Noah Michael Urban: In August 2025, 20-year-old Florida native and prominent Scattered Spider SIM-swapper Noah Michael Urban was handed a robust 10-year federal prison sentence and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy charges.
- Outstanding Indictments: The U.S. DOJ maintains active federal cases against several remaining co-conspirators indicted alongside Buchanan, including:
- Ahmed Hossam Eldin Elbadawy (“AD,” 24) of College Station, Texas.
- Evans Onyeaka Osiebo (21) of Dallas, Texas.
- Joel Martin Evans (“joeleoli,” 26) of Jacksonville, North Carolina.
Future Outlook: The Shifting Landscape of Cybercrime
The guilty pleas of Owen Flowers and Thalha Jubair mark a watershed moment, but they also highlight persistent vulnerabilities in the global digital ecosystem.
For critical infrastructure operators, the Transport for London breach served as a wake-up call regarding the physical and economic fallout of digital compromises. As municipalities increasingly digitize their public transit, water, and energy grids, they remain primary targets for financially motivated extortion groups.
Furthermore, the youth of the defendants—both teenagers and early-twenty-somethings at the time of their offenses—signals a troubling generational shift in cybercrime. Traditional organized crime syndicates have given way to decentralized, Telegram-native collectives where technical prowess is traded freely, and social engineering is refined into an art form.
As Flowers and Jubair await their formal sentencing before a London court on July 15, 2026, the message from international law enforcement is unambiguous: geographic borders, encrypted messaging applications, and juvenile status will no longer shield cybercriminals from accountability. However, as long as corporate supply chains rely on vulnerable authentication mechanisms and third-party credential management, groups like Scattered Spider—and the generation of hackers they inspired—will continue to test the resilience of the modern digital economy.