惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Jina AI
Jina AI
Hugging Face - Blog
Hugging Face - Blog
博客园 - 三生石上(FineUI控件)
博客园 - 【当耐特】
大猫的无限游戏
大猫的无限游戏
IT之家
IT之家
宝玉的分享
宝玉的分享
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
Apple Machine Learning Research
Apple Machine Learning Research
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
爱范儿
爱范儿
小众软件
小众软件
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
The Cloudflare Blog
S
SegmentFault 最新的问题
博客园 - Franky
博客园_首页
T
Tailwind CSS Blog
雷峰网
雷峰网
罗磊的独立博客

The Stack

How Lloyds has transformed its trusted critical data for AI Micron's revenue surges with no end to the memory shortage in sight Ubiquiti UniFi OS vulnerabilities exploited in the wild Mistral's new OCR 4 model shows size matters EU approves €76m in state aid for chip testing firm Even FedEx is a winner of the data centre boom Why AWS thinks AI coding assistants need a new place to run Why China is forging closer ties with open-source foundations China's CPU-only supercomputer tops power list Runtime: Why 'Bring-your-own-Cloud' is taking off; the TRAIT&R framework for agents, and... AWS adds yet another security tool to speed up patching OSS security finally gets a Magic Quadrant Places for People forking out £60m for new ERP system Google offers ATT&CK for bad AI, with surging cost forecast STACKUP: The Stack's weekly tech startups and funding wrap Bring Your Own Cloud: why more enterprises are buying in AWS takes NVIDIA "G7" Blackwell instances GA Runtime: Vercel sets up a new framework for agents, Databricks finds a new Genie, and… Borussia Dortmund's IT head has to sometimes think "outside of the box" Accenture stumbles after Middle East, AI, merger questions Cabinet Office offering £100k+ for AI "ambassador" Critical Splunk Enterprise vulnerability being exploited Accenture buys majority stake in OT security company Dragos npm's security rethink, Satya’s warning, a COBOL win, and... US spending billions to counter China's tech influence NatGeo Society CTO on migrating 15 years of video data to the cloud Alibaba opens French data centres in Europe cloud push SpaceX to take over Cursor in $60bn play for AI coding market Hosting firm Hetzner hikes prices sharply amid supply chain pain HSBC's CIO: AI is easy. True impact is hard.
Scattered Spider: UK teen pleads guilty to TfL attack
Edward Targett · 2026-06-23 · via The Stack

Two British members of the Scattered Spider cybercrime group have pleaded guilty to a ransomware attack on Transport for London (TfL) in 2024.

The 2024 incident, said the National Crime Agency (NCA) this week, forced all 28,000 TfL employees to attend a TfL office for a password reset.

TfL’s annual report shows it suffered £29 million in loss and recovery costs after the incident, which took place between August 31 and September 4.

Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, both plead guilty to the attack. Flowers was initially arrested within days of the attack – police had raided his home on September 6.

They found hardware with evidence of other cybercriminal activity. 

The two had been communicating by Telegram and “an online tool where multiple participants can work remotely on a common workspace.”

Scattered Spider’s well-documented playbook typically saw social engineering used to gain an initial access vector – e.g. calling IT help desks or identity administrators while impersonating employees, in order to manipulate staff into resetting credentials or approving MFA requests. 

See also: MGM Resorts’ ransomware attack started with a single phone call

Cybersecurity firm Huntress suggested that high-profile attacks on Caesars, MGM Resorts, and Transport for London “all involved calling a help desk to reset credentials as the initial access vector” – TfL did not publish public Indicators of Compromise (IOCs) or detail the precise initial attack vector. 

Paul Foster, head of the NCA’s National Cyber Crime Unit, said the case was made possible because TfL engaged with law enforcement early – “I would urge any other organisation to please do the same in such circumstances.”

He added: “The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cyber criminals based in the UK and other English-speaking countries, epitomised by Scattered Spider.”

TfL said in its annual report that it had to suspend access to travel concessions for several months after the attack; access to both Oyster and contactless journey histories was finally  restored in December.

It has since added “significant cybersecurity incident” to its set of core enterprise risks; breaking it out from “significant security incident”. 

Jubair and Flowers were due to stand trial at Woolwich Crown Court on June 22 but changed their pleas to guilty on the first day of proceedings. They are due to be sentenced at the same court on 16 July.

Join peers following The Stack on LinkedIn...