Who did it
Thalha Jubair (20, east London) and Owen Flowers (18, Walsall) — two individuals operating within the loosely organized cybercrime collective known as "Scattered Spider." Unlike the pseudonymous, unconfirmed claims covered elsewhere in this Threat Lab, this case reached a criminal conviction: both pleaded guilty and were sentenced to 5.5 years in prison each in July 2026.
Timeline
The same pattern hit UK retail within days
The same collective — though not necessarily the identical two individuals in every case — was linked to a near-simultaneous 2025 wave against Marks & Spencer, Co-op and Harrods. Marks & Spencer officially confirmed customer data (names, dates of birth, contact details, order history) was stolen, and quantified the damage: an estimated £300 million hit to profit and a £120 million loss in the following quarter.
🎯The technique, not the tech
Notably, none of this relied on a sophisticated exploit. The core trick was social engineering a helpdesk into resetting security credentials for someone impersonating a legitimate employee — the same fundamental pattern behind countless phone scams targeting individuals, just aimed at an organization's support desk instead of a person's phone.
Why this case matters to you
Most of the hacks covered in this Threat Lab remain, to some degree, unverified claims by the attacker. This one is different: a public authority (the NCA) confirmed the financial damage, and a court confirmed the perpetrators. It's a rare, fully-documented look at how little technical sophistication some of the costliest breaches actually require — impersonation and pressure on a human being, not a zero-day exploit.
Frequently asked questions
Who hacked Transport for London?
Two individuals, Thalha Jubair and Owen Flowers, operating within the cybercrime collective known as Scattered Spider. Both pleaded guilty and were sentenced to 5.5 years each in July 2026 — this case went to conviction, unlike most claimed hacks covered in this Threat Lab.
How did they get in?
Not a technical exploit: they used stolen partial credentials plus social engineering against a TfL helpdesk employee to get a staff member's two-factor authentication reset, then used that access to move through internal systems.
What does this have to do with the scams an ordinary person receives?
The technique — impersonating someone to a helpdesk to bypass security checks — is the same core trick behind many phone and messaging scams targeting individuals, just aimed at an organization instead of a person.
Go further
Egidio — The Threat Laboratory, "The Transport for London hack: the UK's biggest cybercrime case", egidio.app/en/laboratoire/tfl-hack-scattered-spider/. Licensed CC BY 4.0.
Free to reuse, including commercially, with attribution. Reuse terms.