In a landmark moment for international cybersecurity enforcement, two young British nationals—Thalha Jubair, 20, and Owen Flowers, 18—have pleaded guilty in a United Kingdom court to charges stemming from a devastating August 2024 cyberattack that paralyzed Transport for London (TfL). The pleas, entered on the first day of what was scheduled to be a six-week trial, mark a significant victory in the ongoing battle against "Scattered Spider," a prolific and elusive cybercrime collective that has wreaked havoc on global infrastructure, major retailers, and the healthcare sector.

The conviction of Jubair and Flowers is not merely the end of a local criminal case; it represents the unraveling of a sophisticated, borderless network of digital extortionists who have cost organizations and individuals hundreds of millions of dollars.

The August 2024 TfL Crisis

The attack on Transport for London serves as the centerpiece of the UK prosecution. In August 2024, the public transport network—the lifeblood of the Greater London area—suffered a catastrophic digital breach. The disruption, orchestrated by Scattered Spider, crippled internal systems, compromised sensitive data, and left millions of commuters in a state of uncertainty.

Jubair and Flowers admitted to conspiring to perform unauthorized acts against TfL’s computer systems, specifically acknowledging that their actions posed a risk of "serious damage to human welfare." For a city as reliant on its transit network as London, the attack was a sobering reminder of the vulnerability of critical infrastructure to the tactics of modern cyber-mercenaries.

A Chronology of Digital Chaos

The criminal careers of Jubair and Flowers, though brief, have left a deep scar on the global digital landscape. Their activities reflect a rapid escalation from teenage mischief to high-stakes, multi-million-dollar cybercrime.

The Genesis: SIM-Swapping and Phishing (2022)

Long before the TfL attack, the seeds of the Scattered Spider operation were sown through a campaign of widespread social engineering. Prosecutors allege that as early as 2022, the group engaged in a massive SMS phishing spree—often referred to as "smishing"—that targeted the employees of hundreds of major organizations.

By stealing single sign-on credentials from employees at companies like LastPass, DoorDash, Mailchimp, Plex, and Signal, the group gained a foothold in corporate environments across the globe. During this period, Jubair was allegedly involved in running a Telegram channel dubbed "Star Chat." This digital hub facilitated a specialized SIM-swapping service, allowing members to intercept phone calls and text messages—including the one-time codes required for multi-factor authentication—effectively bypassing the security layers of their victims.

The "Everlynn" Era

One of the most chilling aspects of the investigation involves Jubair’s early history. According to reports from KrebsOnSecurity, by age 15, Jubair was already operating under the handle "Everlynn." This alias was used to sell fraudulent "emergency data requests" (EDRs). By compromising police and government email accounts, the attackers could send official-looking demands to major tech companies, insisting that sensitive user data—such as IP addresses and account details—be turned over immediately under the guise of an urgent, life-or-death situation. This exploitation of the legal process demonstrated a chilling level of sophistication and a willingness to manipulate public trust in law enforcement.

The High-Profile Ransomware Spree (2023–2025)

By 2023, the group’s focus had shifted toward massive ransomware operations. The group gained international notoriety for the September 2023 attacks on MGM Resorts and Caesars Entertainment, which effectively shut down operations at major Las Vegas casinos. Sources familiar with the investigation have identified Owen Flowers as the individual who acted as the group’s media liaison, granting anonymous interviews in the aftermath of the attacks to taunt authorities and amplify the group’s reach.

The violence of their digital tactics continued into 2025, with attacks hitting British institutions including Marks & Spencer, Harrods, and the Co-op Group.

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Supporting Data: The Cost of the Scattered Spider Reign

The financial implications of Scattered Spider’s activities are staggering. A September 2025 indictment unsealed in New Jersey alleged that Jubair and his associates were responsible for at least 120 network intrusions across 47 different U.S. entities.

  • Ransom Totals: Conservative estimates place the ransom payments extorted by the group at no less than $115 million.
  • Cryptocurrency Theft: Following a 2022 phishing campaign, it is estimated that the group, including members like Tyler "Tylerb" Buchanan, successfully stole at least $8 million in cryptocurrency from victims across the United States.
  • Global Reach: The victims range from retail giants and transit authorities to critical healthcare providers, including U.S.-based SSM Health Care Corporation and Sutter Health.

Official Responses and International Cooperation

The dismantling of the Scattered Spider network is the result of unprecedented coordination between the UK’s National Crime Agency (NCA) and the U.S. Department of Justice (DOJ).

In April 2026, 24-year-old Tyler Buchanan pleaded guilty in the U.S. to wire fraud conspiracy and aggravated identity theft. His sentencing, slated for October, follows the August 2025 imprisonment of another prominent member, Noah Michael Urban, who received a 10-year federal prison sentence and an order to pay $13 million in restitution.

Despite these successes, the investigation remains active. The U.S. government continues to pursue other indicted members of the group, including:

  • Ahmed Hossam Eldin Elbadawy (a.k.a. "AD"): 24, of College Station, Texas.
  • Evans Onyeaka Osiebo: 21, of Dallas, Texas.
  • Joel Martin Evans (a.k.a. "joeleoli"): 26, of Jacksonville, North Carolina.

The international nature of these arrests serves as a warning to cybercriminals who believe their location offers protection from the law. The close collaboration between the FBI, the DOJ, and the UK’s NCA has bridged the jurisdictional gaps that hackers have traditionally exploited.

Implications for Global Cybersecurity

The guilty pleas of Jubair and Flowers serve as a turning point in the industry’s approach to "Gen-Z" cybercriminals. The case underscores several critical realities:

1. The Vulnerability of Human-Centric Security

Scattered Spider’s success was not built on breaking encryption or finding complex zero-day exploits, but on the exploitation of human psychology. Through SIM-swapping, SMS phishing, and the manipulation of legal processes, the group proved that the weakest link in any organization’s security posture is its people.

2. The Professionalization of "Script Kiddies"

The transition from petty, ego-driven hacking to sophisticated, high-revenue ransomware operations shows how quickly modern digital natives can scale their illicit activities. The "Star Chat" Telegram channel functioned as a business incubator, providing the tools and infrastructure for aspiring criminals to turn social engineering into a profitable, scalable service.

3. The Future of Prosecution

The use of forensic digital evidence, combined with international intelligence sharing, is changing the landscape for cyber-prosecutors. By documenting the lifecycle of these attackers—from their early days as teenage "Everlynn" aliases to their roles in global ransomware syndicates—law enforcement is creating a blueprint for the long-term prosecution of decentralized cybercrime groups.

Conclusion

As Thalha Jubair and Owen Flowers await their sentencing on July 15, 2026, the global cybersecurity community watches closely. Their conviction is a stark reminder that while the digital world offers opportunities for anonymity and global reach, it also provides a transparent trail for those who know how to follow it. For the victims—from the transit riders in London to the casino patrons in Las Vegas and the patients in U.S. hospitals—the outcome is a measure of justice in an increasingly volatile digital age. The Scattered Spider web may be fraying, but the case continues, serving as a reminder that the cost of cybercrime is ultimately paid by the public.