Fall of the Spider: Key Members of Prolific Hacktivist Group Plead Guilty to Critical Infrastructure and Healthcare Cyberattacks

Executive Overview

In a dramatic turning point for global cyber law enforcement, two core members of the notorious cybercrime syndicate known as Scattered Spider entered guilty pleas in a London courtroom this week. The surrenders occurred on the very first day of what was projected to be a protracted six-week criminal trial, signaling a definitive collapse in the defense of two young men whose digital rampages severely disrupted national infrastructure, corporate giants, and healthcare networks across two continents.

Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall, admitted to criminal charges stemming from a high-profile August 2024 cyberattack against Transport for London (TfL)—the public body responsible for overseeing the Greater London area’s vast transit network. Both defendants formally pleaded guilty to conspiring to commit unauthorized acts against TfL computer systems and, crucially, causing a risk of serious damage to human welfare—a charge reflecting the dangerous real-world ramifications of modern critical infrastructure intrusions.

+-----------------------------------------------------------------------------------+
|                        SCATTERED SPIDER: KEY PLAYERS & STATUS                     |
+------------------------+-------------------+--------------------------------------+
| Individual             | Age / Location    | Legal Status / Disposition           |
+------------------------+-------------------+--------------------------------------+
| Thalha Jubair          | 20 (East London)  | Pleaded guilty (UK); Extradition     |
|                        |                   | facing unsealed US Indictment        |
| Owen Flowers           | 18 (Walsall, UK)  | Pleaded guilty (UK); Admitted to     |
|                        |                   | US Healthcare Hacks                  |
| Tyler Buchanan         | 24 (UK)           | Pleaded guilty (US Wire Fraud/ID     |
|                        |                   | Theft); Sentencing Oct 2             |
| Noah Michael Urban     | 20 (Florida, US)  | Sentenced to 10 years federal prison |
|                        |                   | + $13M Restitution (Aug 2025)        |
| Ahmed H. E. Elbadawy   | 24 (Texas, US)    | Indicted; Awaiting Trial             |
| Evans Onyeaka Osiebo   | 21 (Texas, US)    | Indicted; Awaiting Trial             |
| Joel Martin Evans      | 26 (N. Carolina)  | Indicted; Awaiting Trial             |
+------------------------+-------------------+--------------------------------------+

The judicial proceedings in the United Kingdom revealed the far-reaching extent of the duo’s illicit operations. Beyond the TfL attack, Flowers independently admitted to participating in a hack targeting major U.S.-based healthcare providers SSM Health Care Corporation and Sutter Health in September 2024. Meanwhile, Jubair faces an unsealed federal indictment in the United States, where prosecutors allege his involvement in over a hundred network intrusions that extracted more than $115 million in extortion payouts.

The guilty pleas represent one of the most significant victories to date for joint U.S.-UK law enforcement operations targeting Scattered Spider—a fluid, highly effective cybercrime collective infamous for blending sophisticated social engineering, SIM-swapping, and aggressive extortion tactics.


Detailed Chronology of a Global Cybercrime Campaign

The judicial admissions made by Jubair and Flowers are the culmination of a multi-year spree that escalated from teenage SIM-swapping forums to enterprise-level extortion schemes affecting millions of citizens worldwide.

2022: The SMS Phishing Spree and Early Telecom Exploitation

The roots of the syndicate’s operations lie in aggressive social engineering. During the summer of 2022, members of Scattered Spider executed a massive, targeted SMS phishing campaign against corporate employees. Utilizing stolen single sign-on (SSO) credentials, the group breached internal networks at more than 130 organizations, including tech and service behemoths such as LastPass, DoorDash, Mailchimp, Plex, and Signal.

During this phase, Jubair was deeply involved in operating online infrastructure dedicated to telecom exploitation. Operating under hacker aliases such as "Rocket Ace" and "Everlynn", a then-15-year-old Jubair orchestrated unauthorized access to internal customer service tools at major U.S. and UK wireless carriers. This access allowed his group to offer illicit SIM-swapping services, effectively hijacking victims’ phone numbers to intercept one-time passcodes and siphon digital assets.

In total, early crypto-heists tied to this specific credential-harvesting push yielded at least $8 million in stolen cryptocurrency.

   +-----------------------+     +-----------------------+     +-----------------------+
   |   SMS Phishing Spree  | --> | Telecom Credential    | --> | SIM-Swapping Service  |
   | (LastPass, DoorDash,  |     | Compromise            |     | ("Star Fraud Chat" /  |
   | Signal, 130+ Entities)|     | (Employee Tool Access)|     | Intercepting 2FA)     |
   +-----------------------+     +-----------------------+     +-----------------------+
                                                                           |
                                                                           v
   +-----------------------+     +-----------------------+     +-----------------------+
   | Mass Ransom Extortion | <-- | Critical Infrastructure| <-- | High-Profile Enterprise|
   | ($115M Total Extorted |     | Attacks (TfL, Sutter  |     | Hacks (MGM, Caesars,  |
   | Across 47 US Victims) |     | Health, SSM Health)   |     | Harrods, M&S, Co-op)  |
   +-----------------------+     +-----------------------+     +-----------------------+

2023: High-Profile Enterprise Extortion and Media Manipulation

By late 2023, Scattered Spider transitioned from identity theft and cryptocurrency drains to devastating ransomware and double-extortion attacks against major commercial entities:

  • Las Vegas Casino Breaches (September 2023): The syndicate breached internal networks belonging to MGM Resorts and Caesars Entertainment, causing widespread operational chaos across hotel keycard systems, slot machines, and internal databases. Multiple sources confirm that Owen Flowers acted as the group’s anonymous media representative during this window, granting taunting interviews to cybersecurity reporters while corporate IT teams fought to contain the damage.
  • UK Retail Blitz: The group turned its sights toward top UK businesses, orchestrating disruptive cyberattacks against major retailers Marks & Spencer, Harrods, and Co-op Group.

2024: Critical Infrastructure Sabotage and Healthcare Targets

The syndicate’s target selection escalated dramatically in 2024, moving from corporate retail and hospitality into public safety and health sector operations:

  • Transport for London (August 2024): The duo compromised TfL’s core IT environment. The attack severely impacted internal operations, public-facing digital services, and identity management infrastructure. Because TfL coordinates London’s public transport services—including the Underground, bus networks, and traffic routing—law enforcement classified the intrusion as a direct threat to human welfare.
  • U.S. Healthcare Systems (September 2024): Owen Flowers participated in successful network breaches of SSM Health Care Corporation and Sutter Health, compromising sensitive hospital infrastructure and patient environments.

2025–2026: Arrests, Indictments, and Law Enforcement Takedowns

The syndicate’s rapid expansion triggered an aggressive response from global law enforcement agencies:

  • July 2025: UK law enforcement arrested Flowers and Jubair following extensive investigations into the UK retail hacks.
  • August 2025: Florida-based Scattered Spider operative Noah Michael Urban was sentenced in U.S. federal court to 10 years in prison and ordered to pay $13 million in restitution after pleading guilty to wire fraud and conspiracy.
  • September 2025: The U.S. Attorney’s Office for the District of New Jersey unsealed a comprehensive indictment against Thalha Jubair and several co-conspirators, charging them with computer fraud, wire fraud, and money laundering tied to 120 breaches.
  • April 2026: British national Tyler "Tylerb" Buchanan (24) pleaded guilty in the U.S. to wire fraud conspiracy and aggravated identity theft stemming from the 2022 phishing campaign.
  • June 2026: Jubair and Flowers officially entered guilty pleas on the opening day of their London trial.

Technical Anatomy: Attack Vectors and Tradecraft

Scattered Spider’s operational success relied heavily on high-end social engineering, telecom identity exploitation, and direct pressure tactics rather than novel malware zero-days.

+-----------------------------------------------------------------------------------+
|                        SCATTERED SPIDER OPERATIONAL TOOLKIT                       |
+------------------------+----------------------------------------------------------+
| Attack Vector          | Mechanism / Technique Employed                           |
+------------------------+----------------------------------------------------------+
| Voice & SMS Phishing   | Direct caller impersonation of IT Helpdesks ("Vishing"); |
|                        | Mass SMS landing pages targeting employee SSO logins.    |
+------------------------+----------------------------------------------------------+
| SIM Swapping           | Compromising internal telecom employee tools to redirect |
|                        | victim phone numbers and bypass SMS-based 2FA.           |
+------------------------+----------------------------------------------------------+
| Abuse of EDR Systems   | Utilizing compromised official government/police email   |
| (Emergency Data Reqs)  | addresses to demand immediate user data from Big Tech.   |
+------------------------+----------------------------------------------------------+
| Ransom Extortion &     | Deploying locker strains, exfiltrating sensitive data,   |
| Public Relations       | and engaging directly with media to apply pressure.      |
+------------------------+----------------------------------------------------------+

1. Voice Phishing (Vishing) and MFA Fatigue

The group excelled at bypassing multi-factor authentication (MFA). Operatives frequently called corporate helpdesks, impersonating non-technical staff members to request credential resets. Alternatively, they launched sustained "MFA Fatigue" attacks—flooding an employee’s mobile device with push authorization requests late at night until the employee accepted out of frustration or confusion.

2. The "Star Chat" SIM-Swapping Ecosystem

Prosecutorial filings detail Jubair’s role as a co-administrator of Star Chat (also operating as Star Fraud Chat), a highly popular Telegram channel catering to illicit SIM-swapping operations. The channel monetized access gained via voice-phishing campaigns targeting customer service representatives at U.S. and UK cellular providers.

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Once inside a carrier’s customer service portal, channel operators sold active SIM-swaps on demand. By re-routing a target’s mobile phone number to an attacker-controlled SIM card, the syndicate effortlessly intercepted incoming calls, SMS messages, and one-time passcodes, effectively taking over bank accounts, corporate emails, and cryptocurrency wallets.

3. Fraudulent Emergency Data Requests (EDRs)

Investigation reports reveal that during his early active period under the alias "Everlynn", Jubair specialized in abusing Emergency Data Requests (EDRs). The technique involves compromising legitimate, official police or emergency services email accounts.

Using these law enforcement credentials, attackers submit urgent requests to major tech platforms (e.g., Apple, Google, Meta), falsely asserting that a victim’s account details (IP logs, physical address, subscriber identity) are required immediately to prevent imminent loss of life or severe bodily harm. Tech platforms, bound by emergency compliance policies, frequently comply without requiring a legal subpoena or search warrant.


Supporting Context & Financial Metrics

The scale of financial damage caused by Scattered Spider positions the group among the most economically destructive cybercrime entities of the decade.

+-----------------------------------------------------------------------------------+
|                     FINANCIAL AND OPERATIONAL IMPACT METRICS                      |
+---------------------------------------+-------------------------------------------+
| Metric Description                    | Recorded Value / Extent                   |
+---------------------------------------+-------------------------------------------+
| Total Extortion Ransoms Extracted     | $115,000,000+ USD                         |
| Cryptocurrency Stolen (2022 Campaign) | $8,000,000+ USD                           |
| Individual Intrusion Incidents (US)   | 120+ Corporate & Health Networks          |
| Targeted U.S. Entities                | 47 Confirmed Entities                     |
| Mass Phishing Victims (2022)          | 130+ Global Companies                     |
| Court-Ordered Restitution (Urban)     | $13,000,000 USD                           |
+---------------------------------------+-------------------------------------------+

Beyond raw financial totals, the practical impact on public safety marked a critical threshold for prosecutorial strategy. The Transport for London breach led to systemic interruptions in ticketing systems, identity access management, and backend operations, forcing transport officials to restrict online services for weeks.

Similarly, intrusions into SSM Health Care and Sutter Health raised immediate concerns regarding delayed medical treatments, compromised patient data integrity, and direct interference with health infrastructure, justifying the severe criminal classification of endangering human welfare.


Law Enforcement Coordination and Legal Precedents

The successful prosecution of Jubair, Flowers, and their co-conspirators underscores an unprecedented level of real-time intelligence sharing between the U.S. Department of Justice (DOJ), the Federal Bureau of Investigation (FBI), and the UK’s National Crime Agency (NCA).

Historically, Western law enforcement struggled to apprehend cybercrime operators hiding within non-extradition jurisdictions such as Russia or Iran. However, Scattered Spider primarily comprised native English-speaking youth residing within Western nations—specifically the U.S., UK, and Canada. This demographic profile allowed Western law enforcement agencies to deploy traditional domestic surveillance, physical search warrants, and rapid extraditions.

Extradition Mechanics and Pending Charges

While Jubair and Flowers face sentencing in London for their crimes on UK soil, Jubair’s legal troubles are far from resolved. The unsealed September 2025 indictment from the District of New Jersey positions him for potential extradition to the United States following the completion of his sentence in the UK.

Simultaneously, U.S. federal prosecutors continue to pursue remaining indicted co-defendants linked to the group:

  • Ahmed Hossam Eldin Elbadawy (24), a.k.a. "AD," of College Station, Texas;
  • Evans Onyeaka Osiebo (21), of Dallas, Texas;
  • Joel Martin Evans (26), a.k.a. "joeleoli," of Jacksonville, North Carolina.

These co-defendants face federal charges of computer fraud, wire fraud conspiracy, and identity theft, with trials pending in U.S. district courts.


Future Outlook & Industry Implications

The collapse of Scattered Spider’s core operational cell delivers key lessons for enterprise defense, public sector security, and international cyber law.

Key Dates on the Judicial Calendar

  • July 15, 2026: Owen Flowers and Thalha Jubair will appear before a London court to receive their sentences for the TfL attack, retail breaches, and healthcare intrusions.
  • October 2, 2026: Tyler Buchanan will be sentenced in U.S. federal court following his guilty plea to wire fraud conspiracy and identity theft.
+-----------------------------------------------------------------------------------+
|                           KEY UPCOMING JUDICIAL DATES                             |
+-------------------+---------------------------+-----------------------------------+
| Date              | Forum / Jurisdiction      | Event                             |
+-------------------+---------------------------+-----------------------------------+
| July 15, 2026     | London Crown Court (UK)   | Sentencing: Jubair & Flowers      |
| October 2, 2026   | U.S. Federal Court (US)   | Sentencing: Tyler Buchanan        |
| TBD (2026-2027)   | U.S. Federal Court (US)   | Trial: Elbadawy, Osiebo, Evans    |
| TBD Post-UK Sentence| U.S. Federal Court (US) | Extradition Proceedings: Jubair   |
+-------------------+---------------------------+-----------------------------------+

Strategic Takeaways for Corporate Security Defenders

  1. The Human Layer Remains the Primary Attack Surface: Scattered Spider demonstrated that identity management systems can be bypassed without complex technical exploits. Enterprise security strategies must prioritize strict identity verification protocols for internal IT helpdesk requests.
  2. Phase Out SMS-Based MFA: The group’s extensive reliance on SIM-swapping highlights the critical vulnerability of SMS-based two-factor authentication. Organizations must migrate to hardware security keys (FIDO2/WebAuthn) or app-based cryptographic authenticators.
  3. Rigorous Telecom and EDR Verification: Telecom providers and major tech platforms face growing pressure to tighten protocols around administrative employee tools and validate law enforcement emergency data requests through multi-stage authentication pipelines.

The guilty pleas of Jubair and Flowers close a major chapter in one of the most disruptive domestic cybercrime waves in recent memory, delivering a strong signal that youth, anonymity, and digital proxy networks offer no protection against coordinated international justice.

Leave a Reply

Your email address will not be published. Required fields are marked *