惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

G
Google Developers Blog
宝玉的分享
宝玉的分享
月光博客
月光博客
B
Blog
云风的 BLOG
云风的 BLOG
Google DeepMind News
Google DeepMind News
Engineering at Meta
Engineering at Meta
aimingoo的专栏
aimingoo的专栏
N
Netflix TechBlog - Medium
博客园_首页
GbyAI
GbyAI
人人都是产品经理
人人都是产品经理
A
About on SuperTechFans
Y
Y Combinator Blog
L
LangChain Blog
有赞技术团队
有赞技术团队
D
Docker
爱范儿
爱范儿
博客园 - 司徒正美
H
Hackread – Cybersecurity News, Data Breaches, AI and More
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
酷 壳 – CoolShell
酷 壳 – CoolShell
Microsoft Security Blog
Microsoft Security Blog
D
DataBreaches.Net

The Record from Recorded Future News

Taiwan charges two businessmen over alleged role in Chinese espionage campaign Former UK privacy chief preparing legal action against woman who reported him, minister says Spain arrests alleged supporter of pro-Russian hacktivist groups after FBI tip EU unveils cyber plan to reduce reliance on foreign AI systems Supreme Court allows Texas app law requiring age verification to take effect Britain plans to build autonomous AI 'Cyber Shield' to defend nation Major Japanese telco says cyberattack exposed 12 million emails UK cyber pledge draws only a handful of top firms despite ministerial appeal Canadian spy agency reports hacking three criminal groups in 2025 Attackers vote themselves $20 million in BONK cryptocurrency Major medical device manufacturer notifies nearly 4 million of breach Japanese teen arrested over cyberattack that disrupted anime streaming service Ukrainian media outlets now among 'priority targets' for Russian hackers Spyware found on phone of European Parliament member probing it Launch of UK's National Cyber Action Plan delayed amid Labour leadership crisis Supreme Court decision threatens EU-US data transfer agreement Teen suspect in Scattered Spider hacks is extradited to US US lifts export controls on Anthropic’s frontier cybersecurity AI models Japanese insurer, brewer, manufacturer and telecom disclose cyber breaches CIA chief highlights major shifts in agency’s tech approach House passes kids’ online safety bill, but Senate approval unlikely An intelligence budget 'super user' job is now in the hands of Russ Vought Justices rule that cellphone location histories are protected by the Fourth Amendment US racks up about 400 wins over illegal World Cup streaming sites US posts $10 million reward over Russian cyber campaign targeting Signal, WhatsApp Ukraine to use seized crypto from cybercrime group to buy war bonds Russia accuses Apple of ‘political censorship’ after VK apps removed from App Store Turla group adds more malware to Russia’s espionage efforts against Ukraine Russia used social engineering to breach prominent messaging accounts, Ukraine says FCC votes to toughen rules in bid to better protect undersea cables
Two Scattered Spider members plead guilty over cyberattac...
Daryna Antoniuk · 2026-06-23 · via The Record from Recorded Future News

Two alleged members of the cybercrime gang Scattered Spider pleaded guilty Monday to carrying out a cyberattack against London's transport authority that disrupted services for months, exposed customer data and cost the organization tens of millions of pounds.

The U.K.'s National Crime Agency (NCA) said Thalha Jubair, 20, from East London, and Owen Flowers, 18, from England's West Midlands, admitted infiltrating the network of Transport for London in September 2024.

Both men had been scheduled to stand trial on Monday but changed their pleas on the first day of proceedings. Sentencing is scheduled for July 16.

Authorities said the pair were members of Scattered Spider, a loosely organized network of predominantly English-speaking cybercriminals linked to a series of high-profile intrusions targeting major U.S. and European companies across sectors including aviation, insurance and retail. U.S. prosecutors have previously alleged that the group extorted at least $115 million from victims over a three-year period.

The attack forced all 28,000 TfL employees to reset their passwords in person and resulted in about 29 million pounds ($38 million) in losses and recovery costs, according to the NCA. Disruptions continued for several months after the initial intrusion.

The breach also affected TfL's customer refund services and exposed data held in the refund system for Oyster,  the smart-ticketing platform used across London's public transportation network. The incident also disrupted applications for discounted Oyster photocards used by children and young people.

Flowers was arrested shortly after the attack in September 2024. Investigators searching his home seized laptops, desktop computers, hard drives and USB devices, the NCA said.

One laptop contained a screenshot showing connections to TfL infrastructure and evidence that Flowers had accessed an online marketplace selling stolen credentials, the NCA said. Investigators also recovered videos allegedly showing Jubair accessing TfL systems during the intrusion.

According to the NCA, the pair communicated via Telegram and collaborated through a shared online workspace while carrying out the attack.

Authorities said evidence uncovered during the investigation also indicated that the networks of U.S. healthcare providers SSM Health Care Corporation and Sutter Health had been infiltrated and damaged. The NCA did not provide further details, but both companies reported large data breaches in 2023.

Flowers later breached his bail conditions on two occasions, while Jubair faced an additional charge for failing to disclose passwords or PINs for seized devices.

The defendants faced some of the most serious charges available under British cybercrime legislation, including conspiracy to commit unauthorized computer acts that create a risk of serious damage to human welfare or national security — offenses that carry a maximum sentence of life imprisonment.

"This has been a lengthy, highly complex and painstaking investigation," Paul Foster, head of the NCA's National Cyber Crime Unit, said in a statement.

Get more insights with the

Recorded Future

Intelligence Cloud.

Learn more.

Recorded Future

No previous article

No new articles

Daryna Antoniuk

Daryna Antoniuk

is a reporter for Recorded Future News based in Ukraine. She writes about cybersecurity startups, cyberattacks in Eastern Europe and the state of the cyberwar between Ukraine and Russia. She previously was a tech reporter for Forbes Ukraine. Her work has also been published at Sifted, The Kyiv Independent and The Kyiv Post.