In a landmark victory for international cybercrime units, two prominent members of the notorious hacking collective known as Scattered Spider pleaded guilty in a United Kingdom court this week. The admissions of guilt, delivered on the opening day of a scheduled six-week trial, provide a rare glimpse into the operations of a group that has successfully extorted tens of millions of dollars from some of the world’s largest corporations. Thalha Jubair, 20, and Owen Flowers, 18, admitted to a series of high-profile cyberattacks, most notably the August 2024 disruption of Transport for London (TfL), the body responsible for the capital’s vast public transport infrastructure.

The proceedings in London highlight the growing threat posed by decentralized, highly skilled hacking groups composed largely of young adults in Western nations. While traditional ransomware syndicates often operate out of Eastern Europe, Scattered Spider—also tracked by security researchers as UNC3944 or Star Fraud—has distinguished itself through aggressive social engineering and a deep understanding of Western corporate IT structures.

The August 2024 Attack on Transport for London

The guilty pleas centered heavily on the cyberattack that crippled Transport for London in late 2024. The incident was not merely a data breach but a systemic disruption that forced the agency to shut down various internal systems, leading to significant operational challenges across the London Underground and bus networks. Jubair and Flowers admitted to conspiring to commit unauthorized acts against TfL computer systems, but the legal gravity was heightened by a second charge: causing a risk of serious damage to human welfare.

Under UK law, cyberattacks that threaten the stability of critical national infrastructure (CNI) are prosecuted with extreme severity. By targeting a transport network that millions of people rely on daily, the duo risked creating physical safety hazards, including the potential disruption of emergency communications or signal controls. While TfL managed to maintain core transit services during the breach, the administrative and back-end recovery costs were substantial, and the psychological impact on the city’s digital confidence was profound.

Expanding the Scope: Healthcare and Retail Targets

The court proceedings also unraveled a broader web of criminal activity involving the defendants. Owen Flowers admitted to a separate conspiracy targeting the United States healthcare sector. In September 2024, Flowers was involved in hacking SSM Health Care Corporation and Sutter Health. Attacks on healthcare providers are particularly scrutinized by international law enforcement due to the potential for delayed medical treatments and the exposure of sensitive patient data.

Furthermore, the duo’s criminal portfolio extended into the British luxury and retail sectors. Prior investigations by the National Crime Agency (NCA) linked Flowers and Jubair to ransomware attacks against iconic British brands, including Marks & Spencer, Harrods, and the Co-op Group. These attacks typically followed the Scattered Spider playbook: gaining entry through social engineering, stealing sensitive corporate data, and demanding exorbitant ransoms to prevent its release.

The Mechanics of Scattered Spider: Social Engineering and SIM-Swapping

Scattered Spider has earned a reputation as one of the most effective "social engineering" groups in the world. Unlike groups that rely solely on sophisticated malware, Scattered Spider members often gain initial access by simply calling corporate IT helpdesks. By posing as employees who have lost their passwords or lost access to their Multi-Factor Authentication (MFA) devices, they manipulate staff into granting them entry to the network.

A significant portion of the evidence against Thalha Jubair involved his management of a Telegram channel known as "Star Chat." This digital hub served as a marketplace and operational center for SIM-swapping services. In a SIM-swap attack, hackers convince a mobile carrier to port a victim’s phone number to a SIM card controlled by the attacker. Once they control the phone number, the hackers can intercept one-time passwords (OTPs) sent via SMS, effectively bypassing MFA protections for bank accounts, corporate logins, and cryptocurrency wallets.

U.S. prosecutors allege that Jubair, operating under the handle "Rocket Ace," gained access to internal employee tools at major American wireless providers. This allowed the group to perform SIM swaps at scale, leading to the theft of millions of dollars in digital assets.

The 2022 SMS Phishing Campaign and Global Impact

The legal troubles for the Scattered Spider members extend back to a massive 2022 campaign that targeted over 130 organizations. This campaign, often referred to by researchers as the "0ktapus" attack, utilized mass SMS phishing (smishing) to harvest credentials from employees at high-profile tech firms.

The list of victims included password manager LastPass, food delivery giant DoorDash, email marketing platform Mailchimp, and communication services like Plex and Signal. By sending deceptive texts that appeared to be legitimate corporate security alerts, the group tricked employees into entering their single sign-on (SSO) credentials into fraudulent landing pages. These credentials were then used to infiltrate corporate networks and steal proprietary data.

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

In the United States, an indictment unsealed in New Jersey in September 2025 alleged that Jubair and his associates were involved in at least 120 separate network intrusions across 47 U.S. entities between 2022 and 2025. The U.S. Department of Justice estimates that the group’s victims paid a staggering $115 million in ransom payments during this period.

International Law Enforcement Cooperation and Extradition

The prosecution of Flowers and Jubair is the result of an intensive multi-year collaboration between the UK’s National Crime Agency and the U.S. Federal Bureau of Investigation (FBI). The "Scattered Spider" task force has been working to dismantle the group’s leadership, which is believed to be scattered across the UK, United States, and Canada.

While Flowers and Jubair are currently facing justice in the UK, Jubair remains a high-priority target for U.S. authorities. The New Jersey indictment includes charges of computer fraud, wire fraud, and money laundering. Given the scale of the losses incurred by U.S. companies—including the $100 million revenue hit taken by MGM Resorts following a 2023 attack—there is a strong likelihood that U.S. prosecutors will seek Jubair’s extradition following the completion of his sentence in the United Kingdom.

Related Convictions and Pending Trials

The sentencing of Flowers and Jubair, scheduled for July 15, 2026, follows several other high-profile convictions within the group.

  • Tyler Buchanan: A 24-year-old British national known as "Tylerb," Buchanan pleaded guilty in April 2026 to wire fraud and identity theft. He was a central figure in the 2022 phishing spree that resulted in the theft of $8 million in cryptocurrency. He awaits sentencing in October.
  • Noah Michael Urban: A 20-year-old Florida resident, Urban was sentenced in August 2025 to 10 years in federal prison and ordered to pay $13 million in restitution for his role in the group’s wire fraud and SIM-swapping operations.

Several other defendants remain in the legal pipeline, including Ahmed Hossam Eldin Elbadawy of Texas, Evans Onyeaka Osiebo of Dallas, and Joel Martin Evans of North Carolina. The staggered arrests and guilty pleas suggest that law enforcement has successfully flipped several lower-level members to build cases against the group’s core organizers.

Technical Analysis: The "Everlynn" Alter Ego and EDR Fraud

One of the more chilling aspects of the investigation into Thalha Jubair was his early start in the cybercrime world. At just 15 years old, Jubair allegedly operated under the pseudonym "Everlynn." In this role, he pioneered a technique known as "Emergency Data Request" (EDR) fraud.

In an EDR fraud scheme, hackers compromise the email accounts of police departments or government agencies. They then use these official accounts to send urgent requests to tech companies like Apple, Google, or Meta, claiming that a situation involves an immediate threat to life (such as a kidnapping or suicide risk). Because of the purported urgency, companies often bypass the standard requirement for a court-ordered subpoena and hand over subscriber data, including IP addresses, phone numbers, and physical locations. This data is then used for further social engineering or physical harassment (doxing).

Broader Implications for Corporate Cybersecurity

The guilty pleas of Flowers and Jubair serve as a stark reminder that the "human element" remains the most vulnerable link in the cybersecurity chain. Scattered Spider did not rely on "zero-day" exploits or state-sponsored malware; they relied on the fact that humans are helpful, often hurried, and susceptible to manipulation.

The group’s success against giants like MGM Resorts and Caesars Entertainment—where one company reportedly paid a $15 million ransom to avoid a shutdown—has forced a total reevaluation of identity and access management (IAM). Organizations are now moving away from SMS-based MFA, which is vulnerable to SIM-swapping, toward hardware security keys and biometric authentication.

Furthermore, the TfL attack highlights the necessity of robust network segmentation. When a transit agency’s administrative network is breached, it should not have the capability to impact the safety-critical systems of the transport network itself. The fact that the "risk to human welfare" charge was applicable suggests that the wall between these systems was uncomfortably thin.

As Flowers and Jubair await their July sentencing in London, the global cybersecurity community continues to monitor the remnants of Scattered Spider. While these convictions represent a major blow to the group, the techniques they popularized—social engineering, Telegram-based coordination, and EDR fraud—have already been adopted by a new generation of digital predators. The legal resolution of the TfL hack marks the end of a chapter, but the era of the high-stakes, youth-led cyber-syndicate is far from over.

Leave a Reply

Your email address will not be published. Required fields are marked *