Scattered Spider Hackers Sentenced to 5.5 Years Over £29 Million Transport for London Cyberattack — What Happened 

Scattered Spider Hackers Sentenced to 5.5 Years Over £29 Million Transport for London Cyberattack — What Happened 

Two Scattered Spider members received prison sentences for a cyberattack that disrupted Transport for London. Here’s what data was taken and how you can better protect yourself from follow-up fraud.

What Happened?

According to Help Net Security, two Scattered Spider members were jailed for attacking Transport for London between August 31 and September 3, 2024.

Thalha Jubair, 20, and Owen Flowers, 18, each received five years and six months in prison.

The cyberattack affected 148 TfL systems and forced 27,000 employees to reset their passwords in person.

It also disrupted refunds, digital payments, travel cards, and Dial-a-Ride services for older and disabled passengers.

TfL estimated that the attack caused £29 million in losses and recovery costs.

The source did not confirm whether the attackers stole or published customer information during the incident.

However, cybercriminals often target organizations because they store valuable personal and login information.

Your information may also have been leaked in another breach without you realizing it. Checking for these problems can help you respond before criminals misuse your details.

Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.

Who Was Affected and What TfL Data Was Taken?

TfL said names and contact details were taken for some customers.

Around 5,000 customers also had bank details accessed through Oyster refund records. Oyster cards are London’s transit payment cards.

The accessed details included bank account numbers and sort codes. TfL says it has found no evidence that the information was misused.

Names, addresses, and bank details can help criminals create convincing refund messages, bank calls, or identity theft attempts.

What Investigators Found About the TfL Break-In

The NCA has not publicly explained the exact first step the pair used to enter TfL’s network.

Investigators linked Flowers to a remote server, meaning a computer controlled from another location, used during the attack.

They also found videos showing Jubair inside TfL systems, plus Telegram messages and a shared online workspace.

Police found evidence that Flowers used an online service selling stolen login details.

The FBI says Scattered Spider often uses social engineering, SIM swapping, and data extortion.

Social engineering means tricking a worker into granting access. SIM swapping moves your phone number to a criminal-controlled SIM card.

That change may let criminals receive security codes sent to your number. Data extortion means threatening to publish stolen information unless money is paid.

However, officials have not confirmed that these methods opened TfL’s systems.