UK Court Jails Two Men Over Major Cyberattack on London Transport
UK court jails two men over – A UK court has officially jailed two men over a significant cyberattack that targeted London’s public transport network in 2024. The sentencing at Woolwich Crown Court brought justice to one of Britain’s most substantial data breaches, which compromised the personal information of millions of TfL customers. Thalha Jubair, aged 20 and residing in east London, alongside Owen Flowers, 18 from England’s West Midlands, each received five-and-a-half-year prison sentences for their roles in the sophisticated hack.
The UK court jails two men over charges related to the unauthorized access of Transport for London’s systems between 31 August and 3 September 2024. During this critical period, the teenagers successfully obtained access to the names and contact details of approximately seven million customers. Their guilty pleas came last month, confirming their involvement in what prosecutors described as a well-coordinated operation that exploited vulnerabilities within the transport operator’s digital infrastructure.
Financial Impact and Court Proceedings
The financial consequences of this cyberattack were substantial, with Judge Mark Turner revealing that the incident cost Transport for London around £25 million (€29.3 million) in losses. While the attack did not cause immediate disruption to daily transport services, it left critical parts of TfL’s systems offline for three months. The City of London Police emphasized the severity of the situation, stating: “Two men have been sentenced for launching a cyber attack on Transport for London which cost tens of millions of pounds in losses and impacted thousands of customers.”
“Turner said the pair’s actions had caused ‘very serious’ disruption and were motivated primarily by ‘selfish bravado’,” highlighting the youthful arrogance behind the sophisticated cybercrime.
Methodology and Investigation
Prosecutor Mark Fenhalls detailed how the hackers gained their initial access to the transport network. They utilized TfL employee credentials discovered on “russianmarket,” a dark web marketplace specializing in stolen login information. The pair worked continuously for 16 hours, maintaining communication through the messaging app Telegram throughout the night. Their breakthrough came after successfully convincing the helpdesk to reset an employee’s password, opening the door to extensive network access.
Once inside, the teenagers explored the system thoroughly, searching for celebrities’ travel histories and attempting to access customers’ payment information. Over several days, they gained additional privileges, effectively holding “the keys to the kingdom” and giving them “control over the whole network,” according to Fenhalls. During the intrusion, Flowers expressed his motivations to Jubair, telling him that “the government deserves to be hacked.”
Both men were connected to Scattered Spider, a cybercrime organization responsible for numerous high-profile attacks, including incidents targeting British retailers Marks & Spencer and the Co-op. Their arrest in September 2025 followed an extensive National Crime Agency investigation, with prosecutors describing them as “experienced and talented” hackers who had been known to law enforcement for years.
Flowers had also been involved in hacking US-based healthcare providers Sutter Health and SSM Health Care Corporation. The NCA discovered these additional attacks when officers raided his home on 6 September 2024 as part of the TfL investigation. Meanwhile, Jubair carried a previous conviction as a juvenile for cyberattacks targeting US chipmaker Nvidia, and he had also admitted to hacking the City of London Police. The UK court’s decision to jail two men over this case demonstrates the seriousness with which British authorities treat cybercrime affecting essential public services.

