Teenagers who hacked TfL causing millions of pounds of damage jailed for five years

Thalha Jubair; Owen Flowers

Thalha Jubair and Owen Flowers disrupted TfL’s online services for months, inconveniencing thousands of customers

Two young men who carried out a cyber-attack on Transport For London when they were teenagers have been jailed.

Thalha Jubair, 20, from east London, and Owen Flowers, 18, from Walsall, West Midlands, pleaded guilty in June to carrying out the hack two years ago which disrupted TfL’s online services for months, costing tens of millions of pounds in losses and inconveniencing thousands of customers.

READ ALSO: TfL suspends live travel data after cyberattack

Both men have been sentenced to five years and six months in prison at Woolwich Crown Court. The court heard they were loners who had few offline friends and spent most of their time online unsupervised.

Both were known to the police. Flowers had been given a cease and desist order for minor cyber crime in October 2023 shortly after he turned 16.

Jubair was first arrested in February 2021 at the age of 14 and received a Youth Rehabilitation Order in 2023 when he was 16 for hacking with the Lapsus$ cyber crime group, which targeted major companies including Nvidia and BT.

His defence team claimed in court he was lonely and suicidal and had effectively been groomed by older cyber criminals.

In his sentencing remarks Judge Mr Justice Turner referred to their young age and autism diagnoses as mitigating factors in making his judgement.

Citymapper and TfL Go apps

The National Crime Agency and City of London Police investigated Jubair and Flowers after TfL’s network was infiltrated between 31 August and 3 September 2024. They were arrested at their home addresses last September.

Both were members of the online criminal collective known as Scattered Spider, which has been linked to dozens of other cyber-attacks including on retailers Marks and Spencer and the Co-op.

While public transport services such as the London Underground and buses operated as normal during the hack, the disruption impacted real-time travel updates on popular travel apps like Citymapper and TfL Go, as well as the TfL website.

Data from TfL’s Oyster refunds system was accessed and the incident also affected TfL’s customer refund system, leaving some out of pocket for much longer than usual. It also closed down the application system for Oyster photocards for children and young people.

All 28,000 employees had to attend a TfL office for a password reset and the organisation suffered a reported £29 million in loss and recovery costs.

The National Crime Agency says the rise of young hackers in the UK as one of the biggest threats to the nation’s cyber security. It said if Jubair and Flowers had been successful in shutting down the transport network the estimated cost to the UK economy could have been up to £56 billion.

Tfl Plan a Journey online tool and Oystercard

The two boys joked and boasted to each other on Telegram about accessing people’s Oystercard data

“Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public”, said Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit.

“This has been a lengthy, highly complex and painstaking investigation”, he said when the two pleaded guilty last month.

“The perseverance and meticulousness of our officers, and the work of our partner organisations, meant that Jubair and Flowers had no option other than to plead guilty and take responsibility for their offending”.

Flowers was initially arrested for the TfL attack on 6 September 2024, at which point NCA officers identified further evidence that the networks of US healthcare companies SSM Health Care Corporation and Sutter Health had been infiltrated and damaged.

Investigators found a number of devices at his home including laptops, tower computers, hard drives and USB sticks. One Acer laptop contained a screen shot of showing network connectivity to TfL infrastructure.

Flowers had also accessed an online tool selling breached credentials.

The laptop also contained a number of videos that Flowers had recorded, showing Jubair accessing TfL systems during the attack. The pair were messaging each other over Telegram at the same time and also communicated via an online tool where multiple participants can work remotely on a common workspace.

They accessed TfL’s database of people with Oyster cards, searched the list for the personal details of London celebrities, and attempted to access banking details.

Dame Angela Eagle

After the sentences were announced Security Minister Dame Angela Eagle said:

“This shocking case shows the very serious threat that cyber criminals pose to our security and prosperity – a key part of our capital’s infrastructure lost millions of pounds and many ordinary paying customers suffered huge disruption.

“My thanks go to the National Crime Agency and the City of London Police for their exceptional work in tracking down these criminals and bringing them to justice. This should send a clear message to anyone planning illegal cyber activity that there will be consequences when you are caught”.