惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
MongoDB | Blog
MongoDB | Blog
博客园_首页
博客园 - 三生石上(FineUI控件)
博客园 - 聂微东
B
Blog RSS Feed
D
Docker
IT之家
IT之家
大猫的无限游戏
大猫的无限游戏
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
阮一峰的网络日志
阮一峰的网络日志
罗磊的独立博客
Recent Announcements
Recent Announcements
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
A
About on SuperTechFans
The GitHub Blog
The GitHub Blog
G
Google Developers Blog
V
V2EX
量子位
雷峰网
雷峰网
月光博客
月光博客
云风的 BLOG
云风的 BLOG
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
T
Tailwind CSS Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Critical Fortinet FortiSandbox Vulnerabilities Actively Exploited in Attacks Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Scattered Spider Hackers Who Breached London Transport Ne...
Abinaya · 2026-06-23 · via Cyber Security News

Two members of the Scattered Spider cybercriminal group have pleaded guilty to a cyberattack on Transport for London (TfL) that caused major service disruptions and resulted in an estimated £29 million in losses.

Thalha Jubair, 20, from East London, and Owen Flowers, 18, from Walsall, West Midlands, admitted their roles in breaching TfL’s internal network between August 31 and September 3, 2024.

The attack impacted critical systems and forced the organization to implement emergency remediation measures across its infrastructure.

According to investigators from the UK’s National Crime Agency (NCA) and the City of London Police (COLP), the attackers gained unauthorized access to TfL systems, triggering a full-scale password reset operation affecting approximately 28,000 employees.

Staff were required to attend physical offices to reauthenticate, highlighting the severity of the compromise and loss of trust in internal identity systems.

Two young men have admitted mounting a cyber attack on Transport for London (TfL), which cost tens of millions of pounds in losses and inconvenienced thousands of customers.

The NCA and @CityPolice investigated Thalha Jubair and Owen Flowers after TfL’s network was infiltrated… pic.twitter.com/qyWRTVhGTT

— National Crime Agency (NCA) (@NCA_UK) June 22, 2026

The breach also exposed data linked to TfL’s Oyster card refund system. This disruption delayed customer reimbursements and temporarily shut down the Oyster photocard application system used by children and young people.

Scattered Spider Hackers Breach TfL

While the full scope of data exposure has not been publicly disclosed, the operational impact significantly affected public services and customer experience.

Digital forensics played a critical role in the investigation. When Flowers was arrested on September 6, 2024, authorities seized multiple devices, including laptops, external drives, and USB storage.

One Acer laptop contained a screenshot showing active connectivity to TfL infrastructure, providing direct evidence of unauthorized access.

Investigators also found that Flowers had used online marketplaces to access or purchase compromised credentials, suggesting credential-based intrusion techniques were used during the attack.

Additional evidence included recorded videos showing Jubair actively navigating TfL systems during the breach. The pair coordinated via Telegram and other collaborative online tools, indicating a structured, real-time attack execution.

Further analysis linked Flowers to intrusions targeting US healthcare organizations, including SSM Health Care Corporation and Sutter Health, demonstrating the group’s broader international targeting footprint.

This aligns with known Scattered Spider tactics, which often involve social engineering, credential theft, and targeting large enterprises and critical infrastructure.

Flowers was later released on bail but violated conditions twice in 2025, raising concerns about continued risk behavior during the investigation period.

Both individuals, who were due to stand trial at Woolwich Crown Court, pleaded guilty at the start of proceedings and are scheduled to be sentenced on July 16, 202

Law enforcement officials emphasized the real-world impact of cybercrime, particularly when critical infrastructure is targeted. The attack disrupted essential public transport services and imposed significant recovery costs.

Authorities also highlighted the growing trend of young, English-speaking cybercriminals joining organized threat groups such as Scattered Spider.

The case underscores the importance of early incident reporting and coordinated response between organizations and law enforcement.

Officials noted that TfL’s cooperation was a key factor in the successful investigation and prosecution. Organizations are advised to strengthen identity security controls, monitor credential abuse, and implement rapid incident response procedures to mitigate similar threats.

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Abinaya

Abinayahttps://cybersecuritynews.com/

Abi is a Security Editor and fellow reporter with Cyber Security News. She is covering various cyber security incidents happening in the Cyber Space.