All news
cybersecurityregulation

Teen Hackers Jailed Over £29M TfL Cyber-Attack

17 Jul 2026

Two men who carried out a cyber-attack on Transport for London (TfL) while still teenagers have been sentenced to five years and six months in prison — a case that exposes how young, loosely affiliated hackers are now capable of disrupting critical infrastructure at massive scale.

What happened

Owen Flowers and Thalha Jubair were sentenced this week for a 2024 attack on TfL that lasted 16 hours and knocked 148 technology systems offline. TfL says the breach cost it £29 million (roughly $47 million), and millions of customers had their data stolen. According to reports, the two had access sufficient to potentially shut down TfL's systems entirely — a detail that underscores how deep the intrusion went.

Messages attributed to Flowers reportedly joked about the hack "killing a 90-year-old on life support" and referenced "Scattered Spider is creating webs on the London Underground," tying the attack to the loosely organized cybercrime collective known as Scattered Spider.

Who's behind it

Jubair's history stretches back further than the TfL attack. He was first arrested at age 14 in February 2021, and by 2023 had received a Youth Rehabilitation Order for hacking alongside the Lapsus$ group, which previously targeted Nvidia and BT. He now carries 22 previous convictions for hacking, fraud, and harassment.

U.S. authorities have separately linked Jubair to attacks on 47 U.S.-based victims who allegedly paid out $115 million in ransoms to him and associates, and the FBI has accused him of involvement in attacks on more than 120 companies. Flowers was arrested in September 2024, and police seized roughly £1 million in cryptocurrency from him.

Scattered Spider itself has been connected to attacks well beyond TfL, including Marks & Spencer, the Co-op, MGM, WestJet, and Okta — spanning retail, gaming, airlines, and cybersecurity firms.

Paul Foster of the UK's National Crime Agency called Scattered Spider "the most significant cybercrime threat to the U.K. in recent years," and said the investigation into Flowers and Jubair "severely disrupted that threat and brought key offenders to justice." The NCA also flagged the broader rise of young hackers in the UK as one of the biggest threats to national cyber security.

Sources differ on some details: BBC reports the attack began on August 31 at a specific hour but doesn't specify the year, while TechCrunch describes it as occurring in "summer 2024." Age reporting also varies — BBC cites Flowers as 17 and Jubair as 18 at the time of the hack, while TechCrunch lists their current ages as 18 and 20. These may reflect different reference points (offense vs. sentencing) rather than a genuine discrepancy, but neither outlet clarifies this explicitly.

Why founders should care

This case is likely to matter to early-stage founders for a few reasons, even though it centers on a large public transit authority rather than a startup:

  • Scale of damage from a single breach. A 16-hour attack costing £29 million and disabling 148 systems suggests that even well-resourced organizations can suffer severe operational and financial fallout — a signal that startups, which typically have far less redundancy, may want to stress-test their own incident-response plans.
  • Threat actors are getting younger and more networked. Jubair's trajectory — from a 14-year-old arrest to alleged involvement in 120+ company attacks — indicates that traditional assumptions about who poses cyber risk may need updating. Founders should probably not assume sophisticated attacks only come from well-funded state or organized-crime actors.
  • Cross-sector exposure. Scattered Spider's victim list spans retail, gaming, airlines, and cybersecurity companies, which suggests the group's social-engineering and systems-access tactics are not industry-specific. Startups in seemingly unrelated sectors may face comparable exposure.
  • Enforcement wins may be temporary. While UK police say this prosecution has "severely disrupted" Scattered Spider's operations, it's unclear whether affiliated actors or the underlying techniques will persist. Founders should treat this as a possible short-term reprieve rather than a solved problem.

What's still unclear

Several details remain unresolved in current reporting: the exact year of the August 31 attack date, whether TfL has since implemented new security measures, the precise nature of the relationship between Flowers, Jubair, Scattered Spider, and Lapsus$, and the current status of U.S. charges or extradition proceedings against Jubair.

For founders, the takeaway isn't about TfL specifically — it's a reminder that cyber risk is increasingly driven by young, decentralized actors capable of causing outsized damage, and that incident-response readiness is worth prioritizing regardless of company size or sector.

Sources