The sentencing of two young men for the high-profile 2024 cyber-attack on Transport for London (TfL) has ignited a fierce debate within the United Kingdom’s legal and law enforcement communities. Senior police officials, led by the National Crime Agency (NCA), are now using the case to advocate for a significant expansion of judicial powers, specifically the introduction of Cybercrime Risk Orders (CCROs). These proposed measures, described by some as "digital prisons," would allow authorities to impose strict behavioral restrictions on suspected cybercriminals even before a formal conviction is secured.
Owen Flowers, 19, and Thalha Jubair, 20, were each sentenced to five and a half years in prison on July 16 at London’s Woolwich Crown Court. The pair was convicted under Section 3ZA of the Computer Misuse Act (CMA) 1990, a rarely invoked provision reserved for "unauthorised acts causing or creating a risk of serious damage." This prosecution marks a milestone in British legal history, representing the largest and most complex cybercrime case ever brought before a UK court.
The Scale of the TfL Breach and Its Economic Fallout
The 2024 attack on Transport for London was not merely a data breach but a systemic disruption of critical national infrastructure. According to evidence presented in court, the financial impact was staggering. The NCA estimated the total cost of the incident at approximately £39 million ($51.5 million). This figure includes £29 million in direct damages—encompassing forensic investigations, system restoration, and cybersecurity upgrades—and a further £10 million in lost revenue.
Beyond the balance sheet, the human impact was vast. The disruption to TfL’s digital ecosystem affected between seven and ten million people. Commuters faced significant hurdles in journey planning, contactless payment systems were intermittently compromised, and internal administrative functions were paralyzed for weeks.
Paul Foster, Deputy Director of the NCA and head of the National Cyber Crime Unit (NCCU), emphasized that the severity of the attack warranted the use of Section 3ZA. This specific section of the CMA is unique because it targets individuals who are either intentional or reckless regarding the potential for "serious damage" to human welfare, the economy, or national security. To date, there has been only one other successful prosecution under this section—a case involving a former GCHQ employee who was jailed for six years after mishandling top-secret files. Foster noted that the TfL case is unprecedented in its scale and the level of technical sophistication involved.
Profiling the Offenders: The Scattered Spider Connection
Flowers and Jubair are identified as key members of "Scattered Spider," a notorious cybercriminal collective that has become a primary target for international law enforcement. The group, also known by aliases such as UNC3944 or Starfraud, is characterized by its young, Western-based members who specialize in aggressive social engineering and SIM-swapping techniques.
While the TfL hack was their most high-profile UK offense in 2024, the group’s activity continued well into the following year. Investigations linked the pair to major breaches at Marks & Spencer (M&S) and the Co-op in 2025. These incidents, which authorities have since classified as a "single cyber event" due to the shared infrastructure and tactics used by the hackers, further demonstrated the group’s ability to compromise large-scale retail and service providers.
The NCA’s investigation into Flowers and Jubair spanned nearly two years and required a massive international effort. The operation involved the City of London Police, the Crown Prosecution Service (CPS), the FBI, Europol, and the Australian Federal Police. Paul Foster described the investigation as even more challenging than "Operation Cronos," the high-profile 2024 takedown of the LockBit ransomware syndicate. The complexity arose not only from the group’s technical evasion tactics but also from the legal hurdles associated with the offenders’ ages and the limitations of current UK bail laws.
The Argument for Cybercrime Risk Orders
The core of the law enforcement push for reform centers on the perceived inadequacy of current preventative measures. Paul Foster revealed that Owen Flowers was just 17 at the time of his initial arrest. Despite being under investigation for one of the most damaging hacks in UK history, Flowers managed to breach his bail conditions on two separate occasions—once in October 2024 and again in May 2025.
Foster argued that existing legal tools, such as Serious Crime Prevention Orders (SCPOs), are insufficient for managing high-risk cyber offenders, particularly those under the age of 18. Currently, SCPOs cannot be applied to minors, and many computer misuse offenses do not meet the strict "serious crime" criteria required to trigger these orders. This creates a regulatory gap where sophisticated hackers can continue their activities while awaiting trial.
The proposed Cybercrime Risk Orders (CCROs), first mentioned during the King’s Speech in May 2026, are designed to fill this void. CCROs would function as civil preventative measures, similar to Sexual Risk Orders. They would allow authorities to:
- Impose restrictions on an individual’s use of specific digital tools and platforms.
- Monitor account usage and limit the number of devices an individual can possess.
- Act on intelligence from international partners to arrest suspects sooner if they pose a continued threat.
- Apply conditions to offenders even if the "prosecution threshold" for a specific crime has not yet been met.
"CCROs would have allowed us to arrest Flowers much sooner," Foster stated, noting that the ability to monitor high-risk individuals actively is essential in an era where a single laptop can cause tens of millions of pounds in damage.
The Concept of the "Digital Prison"
The push for CCROs is supported by Ollie Shaw, Commander at the City of London Police, who advocated for the creation of "digital prisons." Shaw argued that traditional physical restrictions—such as barring a shoplifter from a specific high street—are meaningless in the digital realm.
"It is very easy with any digital device to access the tooling that you need to commit and carry on your offending," Shaw explained. The "digital prison" concept involves a partnership between law enforcement and technology providers to ensure that offenders are strictly limited in their online behavior. This could include mandatory monitoring software installed on any device the individual is permitted to use and the total prohibition of encrypted messaging apps or VPNs.
However, the proposal has met with significant skepticism from cybersecurity experts. Adam Pilton, a prominent UK-based consultant, warned that the "digital prison" moniker is more of a marketing term than a technical reality. Pilton argued that the effectiveness of CCROs would depend entirely on the technical proficiency of the officers enforcing them.
"The people subject to these proposed CCROs are going to be highly skilled and capable of tricking most officers," Pilton cautioned. He suggested that unless law enforcement can match the technical ingenuity of the hackers they are monitoring, these orders may provide a false sense of security. Pilton also raised concerns about the practicalities of enforcement, such as how to prevent an offender from simply using an unmonitored device or a public computer.
Chronology of the Investigation and Legislative Reform
The timeline of the TfL hack and the subsequent legal fallout illustrates the slow pace of justice in the face of rapid technological crime:
- 2024: The Transport for London (TfL) systems are compromised, causing widespread disruption and leading to a £39 million economic impact. Owen Flowers and Thalha Jubair are identified as suspects.
- October 2024: Flowers, then 17, is arrested but subsequently breaches his bail conditions.
- 2025: Scattered Spider continues its campaign, targeting Marks & Spencer and the Co-op.
- May 2025: Flowers breaches his bail for a second time, highlighting the limitations of current police powers.
- May 2026: The UK government announces plans to reform the Computer Misuse Act during the King’s Speech, introducing the concept of CCROs.
- July 16 (Current Year): Flowers and Jubair are sentenced to five and a half years at Woolwich Crown Court.
- Late 2024: Legislation for CMA reform is expected to be introduced in Parliament as part of a national security package.
- 2027–2028: Cybercrime Risk Orders are projected to be officially implemented into UK law.
Broader Implications for National Security
The conviction of Flowers and Jubair is being viewed as a "test case" for how the UK will handle the next generation of cyber threats. The shift toward civil preventative measures like CCROs represents a fundamental change in the British approach to cybercrime—moving from a reactive model (investigate and prosecute) to a proactive risk-management model.
While law enforcement insists these powers are necessary to protect the public, civil liberties groups and technical experts remain wary. The debate over the "digital prison" highlights a growing tension: the need to secure critical infrastructure versus the potential for government overreach in monitoring the digital lives of citizens.
As the government prepares to introduce these reforms to Parliament later this year, the TfL case serves as a stark reminder of the stakes. With Scattered Spider and similar groups continuing to evolve, the UK’s legal framework is under immense pressure to modernize. Whether CCROs will become an effective shield or a technical footnote remains to be seen, but for the millions of Londoners whose lives were disrupted in 2024, the demand for more effective deterrence has never been louder.
