Key Operatives of Prolific "Scattered Spider" Cybercrime Group Plead Guilty Following Landmark Investigation

Executive Overview

In a dramatic development on the opening day of what was scheduled to be a six-week criminal trial in the United Kingdom, two core members of the notorious cybercrime syndicate known as Scattered Spider entered guilty pleas to serious computer misuse and conspiracy charges. The courtroom admissions mark a decisive legal breakthrough against one of the most destructive and financially predatory hacking networks operating internationally.

The defendants—Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall—admitted to conspiring to launch a crippling August 2024 cyberattack against Transport for London (TfL), the public authority overseeing the vast transport network across Greater London. Beyond severe operational disruptions, the charges against both men explicitly include causing a risk of serious damage to human welfare due to the core infrastructure targeted during the breach.

+-----------------------------------------------------------------------------------+
|                        SCATTERED SPIDER LEGAL PROCEEDINGS                         |
+------------------------------------+----------------------------------------------+
| Defendant                          | Admitted Charges / Status                    |
+------------------------------------+----------------------------------------------+
| Thalha Jubair (20, East London)    | • TfL Cyberattack & Human Welfare Risk       |
|                                    | • Facing US Extradition ($115M Extortion)    |
| Owen Flowers (18, Walsall)         | • TfL Cyberattack & Human Welfare Risk       |
|                                    | • SSM Health & Sutter Health Intrusions      |
| Tyler Buchanan (24, UK)            | • Wire Fraud & Aggravated Identity Theft     |
| Noah Michael Urban (20, Florida)   | • Sentenced: 10 Years Prison + $13M Rest.    |
+------------------------------------+----------------------------------------------+

In addition to the Transport for London compromise, Flowers separately admitted to conspiring to breach the computer networks of two major United States healthcare providers: SSM Health Care Corporation and Sutter Health. Meanwhile, Jubair faces an unsealed federal indictment in the United States, where prosecutors allege his involvement in scores of corporate network breaches yielding well over $100 million in ransom payments.

The guilty pleas underscore the extensive reach of Scattered Spider, a loosely organized yet highly sophisticated collective known for combining advanced social engineering, SIM-swapping, credential theft, and ransomware deployment. The network’s activities have systematically disrupted critical municipal services, public healthcare systems, hospitality conglomerates, and high-street retail giants across multiple continents.


Detailed Chronology

The criminal trajectory of Scattered Spider and its key operatives spans years of aggressive cyber intrusions, evolving from targeted credential theft to massive extortion schemes and critical infrastructure attacks.

               SCATTERED SPIDER OPERATIONAL TIMELINE

  May 2022           Summer 2022          Sept 2023        Aug-Sept 2024
    |                    |                    |                  |
    v                    v                    v                  v
  Intrusion          Mass SMS              Las Vegas           TfL & US
  Campaign           Phishing              Casino              Healthcare
  Begins             Spree (>130 orgs)     Ransomware          Breaches

    ===================================================================

  July 2025          Aug-Sept 2025        April 2026        Present
    |                    |                    |                  |
    v                    v                    v                  v
  UK Retail          Urban Sentenced;     Buchanan           UK Guilty
  Arrests            Jubair Indicted      Guilty Plea        Pleas Entered
  (Flowers/Jubair)   ($115M Ransoms)                         (Sentencing July)
  • May 2022: The beginning of a multi-year intrusion campaign detailed by U.S. federal prosecutors. Between May 2022 and September 2025, Scattered Spider operatives targeted dozens of corporate networks, resulting in widespread data theft and massive extortion demands.
  • Summer 2022: Operatives including Jubair and 24-year-old British national Tyler "Tylerb" Buchanan executed a broad SMS-based phishing campaign targeting single sign-on (SSO) credentials. The campaign breached over 130 organizations—including tech and communication platforms such as LastPass, DoorDash, Mailchimp, Plex, and Signal—and netted at least $8 million in stolen cryptocurrency.
  • September 2023: Scattered Spider launched high-profile ransomware attacks against major Las Vegas casino and hospitality operators, including MGM Resorts and Caesars Entertainment. During the immediate aftermath, Flowers acted as an anonymous spokesperson, giving media interviews detailing the group’s actions.
  • August 2024: The group executed a major cyberattack against Transport for London (TfL), compromising internal computer systems, threatening public transport operational stability, and creating significant risks to human welfare.
  • September 2024: Flowers participated in unlawful network intrusions targeting U.S. healthcare systems, specifically SSM Health Care Corporation and Sutter Health.
  • July 2025: Following investigations into cyberattacks against prominent U.K. businesses—including high-street retail giants Marks & Spencer, Harrods, and Co-op Group—British authorities arrested Flowers and Jubair.
  • August 2025: U.S. federal courts sentenced 20-year-old Florida resident Noah Michael Urban, a key U.S.-based Scattered Spider associate, to 10 years in federal prison and ordered $13 million in restitution following his guilty plea to wire fraud and conspiracy.
  • September 2025: Federal prosecutors in New Jersey unsealed a comprehensive criminal indictment against Jubair and his co-conspirators, charging them with computer fraud, wire fraud, and money laundering across 120 network intrusions.
  • April 2026: Tyler Buchanan pleaded guilty in U.S. federal court to wire fraud conspiracy and aggravated identity theft stemming from his role in the 2022 credential-harvesting campaign.
  • Present: Jubair and Flowers entered guilty pleas on day one of their U.K. trial, with official sentencing set for July 15, 2026, in London.

Supporting Context & Metrics

The Infrastructure and Ransomware Threat

The August 2024 incident targeting Transport for London highlighted Scattered Spider’s willingness to escalate tactics from financial extortion to disrupting critical public infrastructure. Transport for London oversees a complex network of underground, bus, and light rail systems servicing millions of commuters daily. Compromising these networks threatened digital operations and presented serious human welfare risks, a factor formally recognized in the defendants’ guilty pleas.

Mechanics of "Star Chat" and Telecommunications Exploitation

A core component of Scattered Spider’s infrastructure relied on compromised telecommunications access, largely facilitated by Jubair under the online alias "Rocket Ace." According to U.S. law enforcement filings, Jubair co-operated a busy Telegram channel named Star Chat (also known as Star Fraud Chat).

┌────────────────────────────────────────────────────────────────────────┐
│                        "STAR CHAT" ATTACK VECTOR                       │
├────────────────────────────────────────────────────────────────────────┤
│ 1. Voice & SMS Phishing                                                │
│    └─► Target: Telecom Employees (U.S. & U.K. Wireless Carriers)       │
│                                                                        │
│ 2. Credential Harvesting                                               │
│    └─► Compromise internal carrier tools & customer management systems  │
│                                                                        │
│ 3. Unauthorized SIM-Swapping Service                                   │
│    └─► Redirect victim phone numbers to attacker-controlled devices    │
│                                                                        │
│ 4. Authentication Interception                                         │
│    └─► Capture SMS/Voice Multi-Factor Authentication (MFA) codes       │
│                                                                        │
│ 5. Enterprise & Individual Compromise                                  │
│    └─► Breach corporate SSO networks & drain cryptocurrency wallets    │
└────────────────────────────────────────────────────────────────────────┘

Star Chat operated as a centralized hub for executing SIM-swapping attacks:

  1. Operatives utilized voice phishing (vishing) and SMS phishing (smishing) to trick employees at major telecommunications providers in the U.S. and U.K. into surrendering internal administrative credentials.
  2. Once internal telecom tools were compromised, the group offered illicit services to redirect target phone numbers to devices under their control.
  3. By intercepting incoming calls and text messages, attackers bypassed multi-factor authentication (MFA) protocols, granting them unauthorized access to corporate networks, bank accounts, and cryptocurrency wallets.

Abuse of Emergency Data Requests (EDR)

Investigative findings reveal that Jubair’s cybercrime activities began years prior to the TfL attack. At age 15, operating under the alias Everlynn, Jubair engaged in the illicit sale of fraudulent Emergency Data Requests (EDRs).

By using compromised police and government email accounts, he submitted fake emergency requests to major technology companies. These notices falsely claimed that immediate disclosure of subscriber metadata—including real names, IP addresses, and email accounts—was required to prevent imminent death or serious physical harm, bypassing standard judicial authorization and subpoena processes.

Financial and Operational Impact

The financial toll exacted by Scattered Spider ranks among the highest reported for a single cybercrime collective:

Scattered Spider Hackers Plead Guilty on Day 1 of Trial
  • $115 Million+ in Ransoms Paid: The U.S. federal indictment in New Jersey attributes over 120 computer network intrusions across 47 U.S. entities to Jubair and his co-conspirators, resulting in at least $115 million paid by victims attempting to recover encrypted or exfiltrated data.
  • $8 Million in Cryptocurrency Theft: Through the summer 2022 SMS phishing campaign alone, co-conspirators including Buchanan and Jubair harvested single sign-on credentials that facilitated the direct theft of more than $8 million in cryptocurrency from individual and institutional victims.
  • Mass Target Portfolio: The group’s documented target list spans critical sectors, encompassing transport authorities (TfL), global hospitality leaders (MGM Resorts, Caesars Entertainment), major U.K. commercial retailers (Marks & Spencer, Harrods, Co-op Group), corporate software and service vendors (LastPass, DoorDash, Mailchimp, Plex, Signal), and major healthcare systems (SSM Health Care Corporation, Sutter Health).

Official Statements and Legal Posture

The legal proceedings across the U.K. and the U.S. highlight an extensive multi-agency effort targeting Scattered Spider’s leadership structure.

U.K. Prosecutions

Reporting by the BBC confirmed that Flowers and Jubair formally admitted to conspiring to execute unauthorized acts against Transport for London systems. Prosecutors emphasized that the severity of the charges reflects not only digital damages, but also the real-world operational risks posed to the general public.

Flowers’ separate admission regarding the September 2024 breaches of SSM Health Care Corporation and Sutter Health establishes his direct involvement in cross-border intrusions targeting essential health services.

U.S. Department of Justice Actions

The United States Department of Justice (DOJ) has pursued extensive charges against the network’s key members. The New Jersey indictment against Jubair details charges of computer fraud, wire fraud, and money laundering.

+-----------------------------------------------------------------------------------+
|                     U.S. DEPARTMENT OF JUSTICE DEFENDANTS                         |
+------------------------------------+----------------------------------------------+
| Defendant                          | Background / Charges                         |
+------------------------------------+----------------------------------------------+
| Thalha Jubair                      | Unsealed NJ Indictment: Wire/Computer Fraud  |
| Tyler "Tylerb" Buchanan            | Guilty Plea: Wire Fraud & Identity Theft     |
| Noah Michael Urban                 | Convicted: 10 Years Prison, $13M Restitution |
| Ahmed Hossam Eldin Elbadawy ("AD") | 24, College Station, TX — Active Indictment   |
| Evans Onyeaka Osiebo               | 21, Dallas, TX — Active Indictment           |
| Joel Martin Evans ("joeleoli")     | 26, Jacksonville, NC — Active Indictment     |
+------------------------------------+----------------------------------------------+

Official filings from the DOJ highlight several other core defendants:

  • Tyler Buchanan: Pleaded guilty in April 2026 to wire fraud conspiracy and aggravated identity theft. His sentencing is scheduled for October 2.
  • Noah Michael Urban: Currently serving a 10-year federal prison sentence following his August 2025 conviction.
  • Active U.S. Defendants: Three additional defendants indicted alongside Buchanan remain under federal indictment:
    • Ahmed Hossam Eldin Elbadawy ("AD"), 24, of College Station, Texas.
    • Evans Onyeaka Osiebo, 21, of Dallas, Texas.
    • Joel Martin Evans ("joeleoli"), 26, of Jacksonville, North Carolina.

Future Outlook

The guilty pleas entered by Jubair and Flowers in London represent a major victory for international cyber law enforcement. However, significant legal processes remain underway in both the United Kingdom and the United States.

                      UPCOMING LEGAL MILESTONES

           July 15, 2026                  October 2, 2026
                 |                              |
                 v                              v
        U.K. Sentencing Hearing       U.S. Sentencing Hearing
        (Flowers & Jubair)            (Tyler Buchanan)
        London Court                  U.S. Federal Court

Flowers and Jubair are scheduled to appear in a London court on July 15, 2026, where they will receive their sentences for the TfL attack, the human welfare endangerment charges, and associated healthcare network breaches.

Following his U.K. sentencing, Jubair faces potential extradition proceedings to the United States to address his unsealed New Jersey indictment. If extradited, he will face federal prosecution for his alleged role in 120 network intrusions, multi-million dollar extortion schemes, and systemic SIM-swapping operations.

In the United States, attention turns to the October 2 sentencing of Tyler Buchanan, as well as ongoing prosecution efforts against remaining indicted co-defendants Elbadawy, Osiebo, and Evans.

The dismantling of Scattered Spider’s leadership demonstrates an increasingly coordinated global approach by law enforcement agencies, leveraging cross-border intelligence sharing to disrupt complex cybercrime networks, neutralize infrastructure threats, and hold young threat actors accountable for large-scale digital extortion.

Leave a Reply

Your email address will not be published. Required fields are marked *