In a landmark development for international cybersecurity enforcement, two young British nationals have pleaded guilty to charges stemming from a devastating August 2024 cyberattack that paralyzed Transport for London (TfL), the backbone of the United Kingdom’s capital transit network. The defendants, Thalha Jubair, 20, and Owen Flowers, 18, were identified as pivotal operatives within "Scattered Spider," a notorious, loosely organized, yet highly effective cybercrime collective that has wreaked havoc on corporate and public sector entities across the globe.
Their guilty pleas, entered on the first day of what was projected to be a grueling six-week trial, mark a significant turning point in the years-long effort by law enforcement agencies—including the UK’s National Crime Agency (NCA) and the U.S. Department of Justice (DOJ)—to dismantle a syndicate responsible for hundreds of millions of dollars in losses.
The Anatomy of the TfL Siege and Beyond
The August 2024 assault on Transport for London was more than a technical glitch; it was a demonstration of the capabilities that have made Scattered Spider a household name in the cybersecurity threat intelligence community. By infiltrating the computer systems responsible for the public transport network in the Greater London area, the pair caused widespread disruption, ultimately leading to their arrest and subsequent admission of guilt for "conspiring to commit unauthorized acts" and "causing risk of serious damage to human welfare."
However, the scope of their criminal activity extended far beyond the London transit system. Owen Flowers, specifically, admitted to participating in a separate, equally malicious conspiracy to breach U.S.-based healthcare providers, including SSM Health Care Corporation and Sutter Health, in September 2024. These actions underscore the group’s "platform-agnostic" approach to cybercrime, where they pivot between public infrastructure, retail giants, and critical healthcare databases with equal disregard for the human impact.
A Chronology of Digital Chaos: From Phishing to Ransom
To understand the rise of Jubair and Flowers, one must look at the evolution of the Scattered Spider ecosystem—a collective that moved from petty cyber-vandalism to high-stakes industrial extortion.
The 2022 Foundation: Mass SMS Phishing
The roots of the group’s influence can be traced back to the summer of 2022, when a massive SMS phishing campaign—often referred to as "smishing"—targeted employees across hundreds of major companies. By harvesting single sign-on credentials, the group successfully breached organizations including LastPass, DoorDash, Mailchimp, Plex, and Signal. Prosecutors allege that Jubair was instrumental in these early campaigns, providing the technical infrastructure that allowed the group to scale its operations.
The MGM/Caesars Inflection Point
In September 2023, Scattered Spider captured international headlines by targeting the giants of the Las Vegas hospitality sector: MGM Resorts and Caesars Entertainment. Sources familiar with the investigation have identified Owen Flowers as the primary member of the group who engaged with media outlets following the attacks, effectively acting as the group’s publicist in the wake of the chaos. This period marked a transition for the group from simple data theft to full-scale ransomware extortion.
The Retail Rampage (2024-2025)
The group continued to target major British retail institutions, including Marks & Spencer, Harrods, and the Co-op Group. These attacks were characterized by the use of sophisticated social engineering techniques, which allowed the hackers to bypass multi-factor authentication (MFA) protocols that many companies believed were impenetrable.
Supporting Data: The Business Model of Cybercrime
The financial footprint left by Scattered Spider is staggering. According to a September 2025 indictment unsealed in New Jersey, the group’s activities between May 2022 and September 2025 involved at least 120 distinct network intrusions across 47 U.S. entities. The DOJ estimates that victims have collectively paid at least $115 million in ransom payments to the group.
The "Star Chat" Telegram Engine
Central to these operations was "Star Chat," a Telegram channel managed by Jubair. This hub served as a marketplace and command center for a specialized SIM-swapping service. By using voice and SMS-based phishing, the group could intercept one-time passcodes (OTPs) meant for multi-factor authentication. Once a target’s phone number was redirected to a device under the attackers’ control, the security gates of even the most well-defended corporate networks would swing open.
The "Everlynn" Persona
Jubair’s digital history is as prolific as it is alarming. Records indicate that as early as age 15, he operated under the handle "Everlynn." During this period, he was known for selling fraudulent "emergency data requests" (EDRs). By compromising law enforcement email accounts, he would send fake, urgent requests to major tech companies, demanding sensitive subscriber data under the guise of life-or-death investigations. This tactic effectively weaponized the legal system’s own emergency procedures against the tech giants themselves.

Official Responses and the Global Legal Dragnet
The legal pursuit of Scattered Spider has required an unprecedented level of cooperation between the UK’s National Crime Agency and the U.S. Department of Justice. The strategy has shifted from treating these as isolated incidents to dismantling the group as a criminal enterprise.
In April 2026, Tyler "Tylerb" Buchanan, a 24-year-old British national, pleaded guilty in U.S. court to wire fraud conspiracy and aggravated identity theft. His cooperation and admission of guilt provided investigators with a roadmap of the group’s internal hierarchy. Similarly, in August 2025, 20-year-old Florida resident Noah Michael Urban was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution.
Despite these victories, the U.S. Department of Justice continues to hunt for other key members. Three defendants remain indicted alongside Buchanan:
- Ahmed Hossam Eldin Elbadawy ("AD"), 24, of College Station, Texas.
- Evans Onyeaka Osiebo, 21, of Dallas, Texas.
- Joel Martin Evans ("joeleoli"), 26, of Jacksonville, North Carolina.
The international nature of the group, which recruits young, tech-savvy individuals from across the globe, presents a significant challenge for traditional law enforcement. However, the consistent unsealing of indictments and successful extradition efforts suggest that the "anonymous" nature of their digital personas is no longer a shield against the reach of the law.
The Wider Implications: A Paradigm Shift in Cyber Defense
The case of Jubair and Flowers is more than just a headline; it serves as a wake-up call for the global cybersecurity landscape.
1. The Death of MFA as a Silver Bullet
The success of Scattered Spider’s SIM-swapping and SMS phishing campaigns has forced a massive industry-wide re-evaluation of multi-factor authentication. Traditional SMS-based OTPs are now widely recognized as "corporate liabilities." Security experts are increasingly pushing for the adoption of FIDO2-compliant physical security keys, which are resistant to the remote interception tactics that defined the Scattered Spider methodology.
2. The Rise of "Youth-Led" Cyber-Insurgency
The average age of the defendants involved in this group—most of whom were teenagers or in their early 20s at the time of their crimes—demonstrates a troubling shift. The "barrier to entry" for cybercrime has collapsed. With Telegram-based command centers and pre-packaged phishing kits, young offenders can execute attacks that were once the sole purview of state-sponsored actors.
3. Critical Infrastructure as a Primary Target
By targeting Transport for London, Scattered Spider signaled that critical public infrastructure is no longer "off-limits" for criminal syndicates. The psychological and logistical damage caused by crippling a transit network is significantly higher than that of a standard data breach, potentially prompting governments to treat cyberattacks on transit and healthcare with the same severity as physical acts of terrorism.
Conclusion
As Thalha Jubair and Owen Flowers await their sentencing on July 15, 2026, the tech community looks on with a mix of relief and caution. While the dismantling of the "Star Chat" network and the successful prosecution of these key individuals strike a blow to Scattered Spider’s operational capacity, the structural vulnerabilities they exploited remain.
The era of Scattered Spider has forced a realization that the digital world is inextricably linked to physical safety. From the trains of London to the hospitals of the American Midwest, the digital siege has been documented, contested, and—in this instance—brought to a halt. However, the persistence of the group’s remaining fugitives serves as a reminder that in the shadow of the internet, the next generation of threat actors is always learning, evolving, and waiting for the next vulnerability to emerge.

