Key Scattered Spider Hackers Plead Guilty in UK Over Transport for London Cyberattack and Global Extortion Spree

Executive Overview

In a dramatic turn of events on the opening day of a scheduled six-week trial in London, two central operatives of the infamous cybercrime syndicate known as Scattered Spider entered guilty pleas to criminal charges arising from a devastating August 2024 cyberattack against Transport for London (TfL). The cyber incident severely disrupted public transit operations across Greater London, compromising critical internal systems and putting public infrastructure at risk.

The defendants—Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall—admitted to conspiring to commit unauthorized acts against TfL computer systems that brought about a risk of serious damage to human welfare. Beyond the UK transportation attack, the guilty pleas shed light on a global enterprise of high-stakes extortion, corporate espionage, and SIM-swapping operations that targeted critical healthcare providers, major retailers, casino giants, and telecommunication carriers across the United Kingdom and the United States.

+-----------------------------------------------------------------------------------+
|                        SCATTERED SPIDER LEGAL PROCEEDINGS                         |
+---------------------+-------------------------------+-----------------------------+
| Defendant           | Primary Allegations / Roles   | Current Status / Outcome    |
+---------------------+-------------------------------+-----------------------------+
| Thalha Jubair (20)  | TfL attack, Star Chat admin,  | Guilty plea in UK;          |
|                     | SMS/Voice Phishing, EDR abuse | US Indictment ($115M ransom)|
+---------------------+-------------------------------+-----------------------------+
| Owen Flowers (18)   | TfL attack, US Healthcare     | Guilty plea in UK;          |
|                     | breaches, MGM media contact   | UK sentencing July 15, 2026 |
+---------------------+-------------------------------+-----------------------------+
| Tyler Buchanan (24) | 2022 SMS phishing spree,      | Guilty plea in US;          |
|                     | $8M crypto theft              | Sentencing Oct 2, 2026      |
+---------------------+-------------------------------+-----------------------------+
| Noah M. Urban (20)  | SIM-swapping, wire fraud      | Sentenced Aug 2025          |
|                     |                               | (10 years prison, $13M rest)|
+---------------------+-------------------------------+-----------------------------+

Scattered Spider—variously designated by threat intelligence researchers as UNC3944, Scatter Swine, or Starfraud—is recognized for its unique blend of aggressive social engineering, helpdesk vishing (voice phishing), SIM-swapping, and partnerships with established Ransomware-as-a-Service (RaaS) syndicates. The group’s members, primarily young, English-speaking individuals operating out of Western countries, have extracted tens of millions of dollars in ransom payments while repeatedly exposing systemic vulnerabilities in modern corporate authentication frameworks.


Detailed Chronology of Attacks and Law Enforcement Action

The 2022 Mass Phishing Campaign & Identity Theft Spree

The core infrastructure of Scattered Spider’s operational methodology was forged during a relentless mass SMS phishing spree in the summer of 2022. Operating alongside fellow British national Tyler "Tylerb" Buchanan, Jubair and other members launched sophisticated social engineering campaigns targeting single sign-on (SSO) credentials of corporate employees.

By crafting malicious authentication portals that mirrored legitimate corporate login pages, the network compromised more than 130 high-profile organizations. Affected entities included digital identity and service management brands such as LastPass, DoorDash, Mailchimp, Plex, and Signal. The harvested credentials allowed the group to infiltrate internal networks and exfiltrate sensitive data, ultimately yielding over $8 million in stolen cryptocurrency from targeted corporate victims across North America.

The September 2023 Las Vegas Casino Heists

By late 2023, Scattered Spider escalated its targets to include major hospitality and entertainment conglomerates. In September 2023, the group mounted cyberattacks against MGM Resorts International and Caesars Entertainment in Las Vegas.

The attacks, which crippled hotel reservation systems, digital room keys, slot machines, and floor operations for days, demonstrated the group’s ability to cause mass operational chaos. Investigative sources revealed that Owen Flowers acted as the group’s anonymous spokesperson during this period, granting interviews to tech journalists and security researchers. Flowers utilized public relations maneuvering as a psychological tactic to exert pressure on corporate executive boards during ransom negotiations. While Caesars reportedly paid an estimated $15 million ransom to restore service stability, MGM resisted, resulting in tens of millions of dollars in operational downtime and cleanup costs.

The August 2024 Transport for London Incident

In August 2024, the syndicate shifted focus to critical UK civic infrastructure, breaching the network of Transport for London. TfL oversees London’s Underground ("The Tube"), bus networks, overground trains, and congestion charging systems.

The intrusion jeopardized internal operational data, employee information, and customer identity verification databases, forcing transit authorities to severely restrict internal computer networks and temporarily suspend online services. The severity of the disruption prompted the UK National Crime Agency (NCA) and Counter Terrorism Policing to classify the event as a threat causing risk of serious damage to human welfare. Both Jubair and Flowers ultimately admitted their direct roles in executing the breach.

Healthcare & Retail Campaigns (2024–2025)

Following the TfL incident, Flowers expanded his solo and collaborative intrusion efforts. In September 2024, Flowers breached two major U.S.-based healthcare networks: SSM Health Care Corporation and Sutter Health. The intrusions into critical healthcare providers created immediate concerns regarding patient data privacy and operational continuity.

Simultaneously, law enforcement tracked the syndicate’s campaign against prominent UK corporate entities. By mid-2025, investigations tied Flowers and Jubair to high-profile ransomware and extortion attacks against premium retail brands, including Marks & Spencer, Harrods, and major supermarket network Co-op Group.

                                SCATTERED SPIDER ATTACK TIMELINE

  Summer 2022          Sept 2023             Aug 2024            Sept 2024             July 2025
  ------------         ---------             --------            ---------             ---------
  SMS Phishing Spree   MGM & Caesars         Transport for       US Healthcare         UK Law Enforcement
  130+ Orgs Targeted   Resorts Breached      London Attack       Breaches (SSM/Sutter) Arrests Flowers & Jubair
  ($8M+ Crypto Stolen) (Extortion & Chaos)   (Transit Crippled)  (Flowers Solo Plea)   (Retail Attack Claims)

Technical Mechanics, TTPs, and Operational Infrastructure

Voice Phishing, Helpdesk Exploitation, and "Star Chat"

Scattered Spider’s tactical success relied heavily on social engineering rather than zero-day software exploits. The group systematically exploited the weakest link in corporate security perimeters: human helpdesk personnel.

Threat actors within the group regularly impersonated target company employees, contacting corporate IT helpdesks to request Multi-Factor Authentication (MFA) resets or new device enrollments. Utilizing personal details gathered via data brokers, public records, and previous breaches, the attackers bypassed security questions with convincing fluency in English.

+------------------------------------------------------------------------------------+
|                         SIM-SWAPPING VIA "STAR CHAT" TTPs                          |
+------------------------------------------------------------------------------------+
|                                                                                    |
|  [ Target Employee ] --(Vishing/SMS Phishing)--> [ Impersonated Telecom Portal ]   |
|                                                                  |                 |
|                                                                  v                 |
|  [ Intercepted MFA / SMS ] <--(Redirect Number)-- [ Compromised Carrier Internal ] |
|                                                    [ Admin Tools (T-Mobile, etc.)] |
|                                                                  |                 |
|                                                                  v                 |
|  [ Account Takeover / SSO Breach ] <------------ [ Star Chat SIM-Swap Service ]    |
|                                                                                    |
+------------------------------------------------------------------------------------+

To support these efforts, Jubair co-managed a lucrative Telegram platform known as Star Chat (also operating as Star Fraud Chat). The platform functioned as a service marketplace for SIM-swapping operations. Members of Star Chat compromised the internal administration tools of major U.S. and UK wireless service providers—such as T-Mobile—by credential-phishing telecommunications workers.

Once inside a carrier’s internal network, Star Chat administrators offered paid services to fraudulently port target telephone numbers to attacker-controlled SIM cards. This capability enabled the group to intercept incoming phone calls, SMS text messages, and one-time passcodes (OTPs), neutralizing SMS-based multi-factor authentication defenses across financial, corporate, and cloud platforms.

Fraudulent Emergency Data Requests (EDRs)

Jubair’s technical history in cybercrime began long before his involvement with Scattered Spider’s high-profile corporate ransomware incidents. Law enforcement documentation reveals that at age 15, Jubair operated under the online persona "Everlynn."

Scattered Spider Hackers Plead Guilty on Day 1 of Trial – Krebs on Security

As Everlynn, Jubair engaged in the monetization of compromised government and law enforcement email accounts. Using legitimate police email domains acquired through compromised law enforcement credentials, he submitted fraudulent Emergency Data Requests (EDRs) to major technology companies and social media platforms.

By abusing the emergency protocol—which requires service providers to immediately supply subscriber information, IP address logs, location data, and communication records without waiting for a formal court order or search warrant—Jubair harvested sensitive target dossiers and sold the illegally acquired subscriber information to malicious actors across the cybercrime underground.


Supporting Context, Metrics, and Co-Conspirators

Global Financial Toll and US Indictments

The financial impact of Scattered Spider’s operations is extensive. According to a landmark indictment unsealed in the U.S. District Court for the District of New Jersey in September 2025, Jubair and his co-conspirators were charged in connection with:

  • 120+ Computer Network Intrusions executed across the global corporate sector.
  • 47 U.S. Corporate Entities directly breached between May 2022 and September 2025.
  • $115 Million+ accumulated in confirmed victim ransom payments.

The U.S. indictment charges Jubair with conspiracy to commit computer fraud, wire fraud, and money laundering.

Sentences and Legal Status of Key Operatives

The global law enforcement campaign against Scattered Spider has led to a series of coordinated arrests and convictions across multiple legal jurisdictions.

+-------------------------------------------------------------------------------------+
|                     SCATTERED SPIDER NETWORK - LEGAL STATUS                         |
+------------------------------+--------------------+---------------------------------+
| Defendant                    | Jurisdiction       | Current Status & Sentences      |
+------------------------------+--------------------+---------------------------------+
| Thalha Jubair ("Rocket Ace") | UK / United States | Pleaded Guilty UK;              |
|                              |                    | US Indictment Pending           |
| Owen Flowers                 | UK                 | Pleaded Guilty UK;              |
|                              |                    | Sentencing set July 15, 2026    |
| Tyler Buchanan ("Tylerb")    | United States      | Pleaded Guilty;                 |
|                              |                    | Sentencing set October 2, 2026  |
| Noah Michael Urban           | United States      | Convicted/Sentenced Aug 2025;   |
|                              |                    | 10 Years Prison, $13M Rest.     |
| Ahmed Hossam Eldin Elbadawy  | United States      | Indicted; Awaiting Trial        |
| Evans Onyeaka Osiebo         | United States      | Indicted; Awaiting Trial        |
| Joel Martin Evans            | United States      | Indicted; Awaiting Trial        |
+------------------------------+--------------------+---------------------------------+

In August 2025, Noah Michael Urban, a 20-year-old Scattered Spider member based in Florida, was sentenced in U.S. federal court to 10 years in prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy charges.

In April 2026, Tyler Buchanan, 24, entered a guilty plea in U.S. federal court to conspiracy to commit wire fraud and aggravated identity theft stemming from the 2022 mass SMS phishing campaign. Buchanan is scheduled for formal sentencing on October 2, 2026.

Meanwhile, three additional U.S. defendants indicted alongside Buchanan remain under federal prosecution:

  1. Ahmed Hossam Eldin Elbadawy (24, known online as "AD") of College Station, Texas.
  2. Evans Onyeaka Osiebo (21) of Dallas, Texas.
  3. Joel Martin Evans (26, known online as "joeleoli") of Jacksonville, North Carolina.

Official Statements and Industry Impact

Following the guilty pleas in London, law enforcement leadership highlighted the international cooperation involved in dismantling the group’s operational leadership.

A representative from the UK National Crime Agency (NCA) noted:

"These guilty pleas mark a decisive step in disrupting a cybercrime group that caused widespread disruption to vital public services and commercial enterprises. The actions of these individuals were not victimless pranks; they caused severe financial harm and risked critical public infrastructure. Our close work with the FBI and international partners demonstrates that cybercriminals cannot hide behind digital pseudonyms or geographic borders."

The U.S. Department of Justice emphasized the ongoing nature of international extraditions and prosecutions aimed at Scattered Spider affiliates, reiterating that individuals operating within Western countries will face justice in every jurisdiction where their crimes inflicted damage.

Chief Information Security Officers (CISOs) and cybersecurity firms have analyzed the group’s tactics to update defensive strategies. Scattered Spider’s success exposed fundamental vulnerabilities in identity lifecycle management:

  • Deprecation of SMS-Based MFA: The group’s usage of SIM-swapping highlighted the insecurity of SMS text messages for identity verification, driving enterprise adoption toward hardware security keys (FIDO2/WebAuthn) and phishing-resistant MFA solutions.
  • Helpdesk Protocol Restructuring: Organizations have had to re-engineer IT helpdesk workflows, introducing strict out-of-band verification steps to prevent threat actors from utilizing vishing to reset credentials.
  • Emergency Data Request Authentication: Tech platforms have implemented stricter multi-stage verification procedures for law enforcement data requests to block fake EDR schemes.

Future Outlook

Thalha Jubair and Owen Flowers remain in UK custody awaiting their formal joint sentencing hearing, which is scheduled for July 15, 2026, at Southwark Crown Court in London. Both face substantial prison terms under the UK Computer Misuse Act given the severity of the infrastructure disruption and public welfare risk associated with the Transport for London cyberattack.

Following the conclusion of UK judicial proceedings and the service of any imposed custodial sentences, Jubair faces potential extradition to the United States to address the federal indictment unsealed against him in New Jersey.

The unraveling of Scattered Spider’s leadership represents a major victory for international law enforcement agencies, including the NCA, FBI, and U.S. Department of Justice. However, cybersecurity analysts caution that the tactics popularized by the syndicate—specifically the monetization of IT helpdesk vishing, automated SIM-swapping, and the integration of native English speakers into Eastern European Ransomware-as-a-Service operations—remain a threat model actively emulated by emerging cybercrime groups globally.

Leave a Reply

Your email address will not be published. Required fields are marked *