惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

V
V2EX
aimingoo的专栏
aimingoo的专栏
S
SegmentFault 最新的问题
博客园_首页
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
IT之家
IT之家
博客园 - 【当耐特】
月光博客
月光博客
C
Check Point Blog
T
The Blog of Author Tim Ferriss
罗磊的独立博客
博客园 - Franky
MongoDB | Blog
MongoDB | Blog
H
Help Net Security
Microsoft Security Blog
Microsoft Security Blog
B
Blog
阮一峰的网络日志
阮一峰的网络日志
腾讯CDC
美团技术团队
N
Netflix TechBlog - Medium
Stack Overflow Blog
Stack Overflow Blog
Y
Y Combinator Blog
L
LangChain Blog
The Cloudflare Blog

Enterprise – Silicon Republic

EU finally gets its hands on Anthropic’s Mythos New Irish dispute body to tackle illegal online content launched Rhysida leaks 5.7TB of sensitive Berlin state data in major hack ‘Keeping OT security up to date is more than patching systems’ HSE fined €645,000 for storing records in decrepit conditions Boston Scientific cyberattack: Cork staff asked to work remotely Report: Only sectors aiding AI adoption sure to grow from it Why connectivity and cybersecurity can't be treated separately French authorities investigating hack of national tax authority Why employee retention is at the heart of the cyber skills gap Levi Strauss corporate data stolen in cyberattack Levi Strauss corporate data stolen in cyberattack How might a system ‘leak secrets’ without being hacked? What is a side-channel attack in cybersecurity? OpenAI agents breach Modal client system after Hugging Face hack OpenAI agents breach Modal client system after Hugging Face hack Report: EMEA businesses not reaping benefits from their AI spend Report: EMEA businesses not reaping benefits from their AI spend Transport for London hackers jailed for five and a half years Commission refers Ireland to CJEU for failing to enact cyber rules Commission refers Ireland to CJEU for failing to enact cyber rules Cloudflare to block AI crawlers from ad-supported webpages by default Cloudflare to block AI crawlers from ad-supported webpages by default Google ordered to pay Klarna nearly $2bn in abuse-of-power row Google ordered to pay Klarna nearly $2bn in abuse-of-power row Upcoming iPhone 18 model leaked in Tata Electronics hack New iPhone 18 models reportedly leaked in Tata Electronics hack Data breaches going unreported – Irish compliance survey Data breaches going unreported, says Irish compliance survey Cybersecurity warning for Irish businesses ahead of EU Presidency
Transport for London hackers jailed for five and a half y...
Colin Ryan · 2026-07-16 · via Enterprise – Silicon Republic

The duo behind the major 2024 cyberattack are reported to have been leading members of the Scattered Spider cybercrime collective.

Two men responsible for the 2024 cyberattack on Transport for London (TFL) have each been sentenced to five and a half years in prison by a UK court.

Owen Flowers and Thalha Jubair, who were teenagers at the time of the cyberattack, were sentenced today (16 July) at Woolwich Crown Court after previously pleading guilty to the hack. The pair were arrested and charged last year.

In late August and early September in 2024, Flowers and Jubair gained access to TFL customer data after impersonating an employee and tricking a phone helpdesk worker into resetting that employee’s password – leading to the theft of around 10m customers’ data.

The cyberattack – which cost TFL £29m – disrupted a number of transportation services in the UK’s capital, including a booking service that provides transport to vulnerable Londoners, while 148 technology systems were rendered inoperable.

In order to stop the attack, all 27,000 TFL employees were summoned to one of the authority’s offices for a password reset and its IT team disconnected its system from the internet.

Had the attack been successful in shutting down TFL’s entire network, it’s estimated that damages could’ve totalled up to £56bn.

According to the UK’s National Crime Agency, both Flowers and Jubair were leading members of cybercrime collective Scattered Spider, which has been linked to other major cyberattacks such as the Marks and Spencer hack.

As well as the TFL attack, Flowers also admitted to conspiring to launch cyberattacks on American nonprofit healthcare systems SSM Health and Sutter Health.

According to the Crown Prosecution Service (CPS), devices belonging to Flowers linked him to all three attacks, while information linking Jubair to the TFL cyberattack was reportedly found overseas.

During the trial – which began last month – the court heard that the duo livestreamed the TFL hack online. Telegram messages of Flowers and Jubair joking about the consequences of the cyberattacks were also uncovered and then used by the prosecution as evidence of the pair’s involvement.

According to the CPS, Flowers and Jubair are believed to be the first hackers to be successfully prosecuted under Section 3ZA of the UK’s Computer Misuse Act 1990.

“Flowers and Jubair broke into and accessed sensitive systems to extract information from millions of Oyster card-holders,” said Lionel Idan, chief crown prosecutor for SEOCID Regional and Wales Division in a press release.

“The evidence revealed not only the sophistication and persistence of their attack but also the recklessness of those responsible. Both defendants showed a staggering disregard for the consequences of their actions as their cyberattack led to TfL having to ‘pull the plug’ on their own network to protect it from wider disruption to the transport network.

“This successful prosecution was a perfect example of collaboration with investigators, prosecutors and international partners working together to build a watertight case that left Jubair and Flowers with little choice but admit their crimes.”

Don’t miss out on the knowledge you need to succeed. Sign up for the Daily Brief, Silicon Republic’s digest of need-to-know sci-tech news.