Executive Overview
In a massive development for international cybersecurity enforcement, two prominent young British members of the notorious cybercrime syndicate Scattered Spider pleaded guilty in a United Kingdom court to criminal charges stemming from a devastating August 2024 cyberattack. The attack crippled Transport for London (TfL), the municipal body governing the Greater London area’s public transport infrastructure.
The dramatic admissions of guilt—entered on what was scheduled to be the first day of a grueling six-week trial—expose the inner workings of one of the world’s most aggressive and elusive digital extortion rings. Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, stood before a UK court and admitted to conspiring to launch unauthorized cyberattacks against TfL computer networks, explicitly creating a risk of serious damage to human welfare.
For years, Scattered Spider has operated with seeming impunity, transitioning from SIM-swapping and low-level social engineering into sophisticated ransomware deployments that have paralyzed multinational corporations, iconic retail giants, critical healthcare providers, and vital urban infrastructure on both sides of the Atlantic. The guilty pleas of Jubair and Flowers mark a watershed moment in the global fight against the syndicate, providing a rare window into the tactics, infrastructure, and cross-border scope of a collective that has cost victims hundreds of millions of dollars.
Detailed Chronology of the TfL Attack and Global Operations
The Transport for London Crippling (August 2024)
The operation against Transport for London in August 2024 sent shockwaves through the UK capital. TfL controls the Underground, buses, river services, and major roadways that millions of commuters rely on daily. When Scattered Spider struck, the digital intrusion severely disrupted internal networks, forcing the agency to take critical customer-facing systems offline and manually manage operations to prevent catastrophic safety failures.
Prosecutors emphasized that the threat posed by Jubair and Flowers extended far beyond mere financial extortion or data theft; by targeting critical urban transit infrastructure, the cybercriminals created a clear and present danger to human welfare and public safety.
Expanding the Attack Surface: Healthcare and Retail Strikes
While the TfL hack brought the duo under intense domestic scrutiny, court documents and investigative reports reveal a far broader trail of destruction. According to BBC reports, Owen Flowers additionally admitted to participating in a separate conspiracy aimed at hacking major U.S.-based healthcare providers—specifically SSM Health Care Corporation and Sutter Health—in September 2024.
These admissions align with a pattern of escalation by Scattered Spider. In July 2025, security investigations linked both Flowers and Jubair to high-profile ransomware attacks targeting British retail institutions, including Marks & Spencer, Harrods, and the Co-op Group.
Intriguingly, intelligence and media sources familiar with the investigations revealed that Flowers was the anonymous insider who granted media interviews following Scattered Spider’s high-profile September 2023 ransomware blitz against Las Vegas casino operators MGM Resorts and Caesars Entertainment. Those casino attacks caused hundreds of millions of dollars in losses and demonstrated the group’s uncanny ability to bypass multi-factor authentication (MFA) through human manipulation.
Supporting Context & Metrics: The Mechanics of Scattered Spider
"Star Chat" and the Industrialization of SIM-Swapping
To understand how teenagers and young adults managed to bring global enterprises to their knees, one must examine the foundational infrastructure they built. According to U.S. and UK prosecutors, Thalha Jubair co-ran a high-volume Telegram channel known as Star Chat (or Star Fraud Chat).
This channel served as the command-and-control hub for a sophisticated SIM-swapping ring. The group utilized voice- and SMS-based phishing campaigns targeting employees at major telecommunications providers in the United States and the United Kingdom. Once internal corporate tools were compromised, the threat actors could seamlessly intercept a target’s phone number, re-route calls, and hijack one-time verification codes essential for multi-factor authentication.
Receipts recovered by investigators and highlighted by security analysts show successful SIM-swaps targeting major carriers like T-Mobile. U.S. prosecutors noted that Jubair operated under the hacker handle "Rocket Ace."

The 2022 SMS Phishing Spree
Jubair’s criminal resume extends deep into the historical archives of modern cybercrime. Prosecutors in New Jersey tied Jubair to a massive, weeks-long SMS phishing campaign during the summer of 2022. Operating at scale, the campaign harvested single sign-on credentials from employees across hundreds of companies, leading to successful corporate intrusions and data exfiltration at more than 130 organizations.
The casualties of this sweeping campaign read like a "who’s who" of modern technology and communication platforms:
- LastPass
- DoorDash
- Mailchimp
- Plex
- Signal
The "Everlynn" Persona and Fake Emergency Data Requests
Cybersecurity reporting has further illuminated the technical versatility of these young threat actors. Research from KrebsOnSecurity revealed that years prior, under the online alter ego "Everlynn," a 15-year-old Jubair was actively selling fraudulent "Emergency Data Requests" (EDRs).
Using compromised police and government email accounts, these fraudulent requests were sent to major tech conglomerates. The messages falsely claimed that life-and-death emergencies required immediate disclosure of user data—such as usernames, IP addresses, and email logs—thereby bypassing standard, time-consuming legal channels like court orders.
Official Statements and International Legal Pressure
The takedown of Flowers and Jubair is the product of intense, multi-agency collaboration between the UK National Crime Agency (NCA), the U.S. Department of Justice (DOJ), and the Federal Bureau of Investigation (FBI).
In September 2025, federal prosecutors in New Jersey unsealed a sweeping indictment against Jubair and fellow Scattered Spider members. The indictment detailed a staggering campaign:
- 120 computer network intrusions
- 47 targeted U.S. entities between May 2022 and September 2025
- At least $115 million in ransom payments extorted from victims
The Department of Justice and British authorities have made dismantling Scattered Spider a top national security priority, recognizing that the decentralized, English-speaking syndicate poses a unique threat to Western critical infrastructure.
The Expanding Web of Prosecutions
The guilty pleas of Jubair and Flowers do not exist in a vacuum; they represent falling dominoes in a coordinated international crackdown on the syndicate:
- Tyler "Tylerb" Buchanan: In April 2026, 24-year-old British national Tyler Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft. Federal authorities revealed that Buchanan, alongside Jubair and others, utilized credentials stolen during the 2022 SMS phishing spree to siphon at least $8 million in cryptocurrency from victims across the U.S. Buchanan’s sentencing is scheduled for October 2, 2026.
- Noah Michael Urban: In August 2025, 20-year-old Florida resident and SIM-swapper Noah Michael Urban was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy charges related to his role in Scattered Spider.
- Pending Indictments: The DOJ continues to aggressively pursue other indicted members of the collective, including Ahmed Hossam Eldin Elbadawy ("AD"), 24, of Texas; Evans Onyeaka Osiebo, 21, of Texas; and Joel Martin Evans ("joeleoli"), 26, of North Carolina.
Future Outlook
The guilty pleas of Thalha Jubair and Owen Flowers represent a critical turning point in the containment of Scattered Spider. For years, the cybercrime ecosystem operated under the assumption that youthful digital native rings could exploit the seams of international law enforcement, hiding behind encrypted messaging apps, pseudonymous online handles, and complex cryptocurrency mixing services.
However, the relentless cross-border cooperation between the UK’s National Crime Agency and American federal prosecutors has proven that physical arrests, extradition threats, and meticulous digital forensics can successfully puncture the veil of anonymity.
As Flowers and Jubair await their formal sentencing hearing—slated for July 15, 2026, in a London court—the cybersecurity industry watches closely. While these guilty pleas neutralize two of the group’s most technically agile operatives, the broader Scattered Spider network continues to evolve. Security leaders emphasize that organizations must remain vigilant, hardening not only their technical perimeter defenses—particularly against MFA fatigue, sophisticated SIM-swapping, and social engineering vectors—but also ensuring robust internal training to withstand the relentless human-centric assaults characteristic of modern cybercrime syndicates.
