XOOMAR
London transport cyberattack scene with cracked digital shield, data streams, locks, and dark security atmosphere
CybersecurityJune 23, 2026· 7 min read· By XOOMAR Insights Team

£39m Transport for London Cyber-Attack Ends in Guilty Pleas

Share
Updated on June 23, 2026

A £39m Transport for London cyber-attack has become a guilty-plea case after two young Britons admitted offences linked to a breach that affected 10 million people and disrupted key TfL online systems.

XOOMAR Intelligence

Analyst Take

69/ 100
High
3 sources analyzedMedium confidenceTrend10Freshness97Source Trust90Factual Grounding93Signal Cluster20

Two Britons admit £39m Transport for London cyber-attack on first day of trial

Thalha Jubair, 20, and Owen Flowers, 18, changed their pleas at Woolwich crown court on Monday, admitting offences under the Computer Misuse Act tied to the 2024 cyber-attack on Transport for London, according to Guardian World.

The pair had been due to face a six-week trial. Instead, they pleaded guilty on day one and are due to be sentenced on 15 July.

The National Crime Agency said Jubair and Flowers were part of Scattered Spider, an online criminal collective that cybersecurity analysts have linked to a series of major intrusions. The Guardian reported that the group is suspected of carrying out several attacks in recent years.

TfL said the incident cost £39m. The BBC reported that the breach affected 10 million TfL customers, while TfL said it emailed more than 7 million customers in September 2024 “to inform them about the incident” and tell them that “some customer data may have been taken.”

The attack ran between 29 August and 3 September 2024, according to the Guardian. It blocked live Tube arrival information from appearing on the TfL Go app and the TfL website. TfL was also unable to process payments on the Oyster and contactless apps or register Oyster cards to customer accounts.

Defendant Age Location Guilty pleas reported
Thalha Jubair 20 Bow, east London Conspiring to commit unauthorised acts against TfL computer systems, causing risk of serious damage to human welfare
Owen Flowers 18 Walsall, West Midlands Same TfL charge, plus hacking-related offences involving SSM Health Care Corporation and Sutter Health

Flowers also admitted conspiring to commit unauthorised acts against computer systems belonging to SSM Health Care Corporation and attempting to commit unauthorised acts against systems belonging to Sutter Health, on or about 6 September 2024.


TfL breach turned a cyber intrusion into a public service problem

The Transport for London cyber-attack matters because TfL is not a narrow corporate target. It is the London mayor’s transport authority and handles up to 5m passenger journeys a day on the underground alone, according to the Guardian.

That means a system breach can spill quickly into daily life, as shown in the London Hydro data breach. In this case, customers lost access to live arrival information, payment processing was interrupted on Oyster and contactless apps, and Oyster card registration was disrupted.

The NCA said the hackers accessed TfL’s refunds system, leaving some customers out of pocket for much longer than usual. The attack also shut the application system for Oyster photocards for children and young people.

“Cyber crime may appear faceless and distant compared to other crime types, but the infiltration of TfL’s systems shows it has real-world consequences and impacts hugely on the public,” said Paul Foster, head of the NCA’s national cyber crime unit.

The £39m cost figure is the hard number TfL has put on the incident. The supplied reports do not break that sum down, so it would be unsafe to assign exact amounts to recovery, legal work, customer support, or operational disruption. But the operational symptoms are clear: TfL systems went offline, refunds slowed, apps stopped handling some functions, and customers had to be notified.

Investigators found laptops, hard drives and USB sticks at Flowers’ West Midlands home. One laptop contained a screenshot showing network connectivity to TfL infrastructure. It also held videos recorded by Flowers that showed Jubair accessing TfL systems during the attack, according to the NCA.

The pair used Telegram to communicate and also used an online tool that allowed multiple participants to work together remotely. The BBC reported that Flowers was found to have accessed an online tool selling breached credentials.

For readers tracking how cyber incidents move from technical flaws to real-world exposure, XOOMAR has also covered the 3-Day CISA Deadline Throws cPanel Plugin Flaw into Crisis and the Texas Data Breach Hands Hackers 3 Million ID Records. Those cases are separate, but they show why investigators and operators focus so heavily on access paths, disclosure timing, and exposed personal data.

The NCA said Flowers and Jubair were “members of the online criminal collective known as Scattered Spider.” That label matters because the agency framed the case as part of a shift in offender profile, not just another isolated intrusion.

“The profile of offenders like Flowers and Jubair demonstrates the increasing threat from cybercriminals based in the UK and other English-speaking countries, epitomised by Scattered Spider,” Foster said.

The Guardian reported that high-profile hacks have typically been carried out by Russian-speaking hackers or attackers based in the former Soviet Union. The NCA’s point is that the TfL case shows a different pipeline: young, UK-based defendants tied to an English-speaking criminal community.

The BBC reported that Scattered Spider has been linked to other cyber-attacks on Jaguar Land Rover and retailers including Marks and Spencer. The supplied reports do not establish that Jubair and Flowers were involved in those incidents, so the TfL guilty pleas should not be stretched beyond the charges they admitted.

Jubair has also been accused by the US Department of Justice of involvement in cyber-attacks targeting 47 US organisations and generating more than $100m (£75m) in ransom payments, according to the Guardian. Those US allegations are separate from the guilty pleas at Woolwich crown court.

A previous hearing was told that $10m moved from Jubair’s crypto wallets after he was released from custody in March last year and that $200m worth of crypto had moved through accounts belonging to him. Another earlier hearing was told Flowers held $7.1m, including crypto, in accounts he controlled despite having no source of income.

Sentencing now becomes the test for a £39m public infrastructure hack

The next stage is sentencing on 15 July, when the court will weigh admitted offending against the scale of harm: £39m in costs, disruption to TfL systems, customer data exposure, and impact on refund and photocard services.

The supplied reports centre on the admitted Computer Misuse Act offences, the guilty pleas at Woolwich crown court, and the listed sentencing date. That leaves the case focused on the charges Jubair and Flowers admitted and the operational harm described by TfL and investigators.

Andy Lord, London’s Transport Commissioner, said TfL welcomed the guilty pleas.

“The security of our systems and customer data is extremely important to us, and we continually monitor our systems to ensure only those authorised can gain access and continue to take the necessary actions to protect TfL,” Lord said.

XOOMAR analysis: the sentencing hearing will be watched for how the court treats cyber harm against public infrastructure when the defendants are young but the operational cost is large. The known facts give prosecutors a direct argument: this was not a contained data incident. It interrupted public-facing transport systems and imposed a stated £39m cost.

The practical watch items are narrower and more useful than broad alarm. Will investigators name or pursue more Scattered Spider-linked suspects? Will TfL provide further customer updates after the guilty pleas? And will the sentencing remarks give clearer guidance on how UK courts price disruption when a cyber-attack hits a service millions of people rely on every day?

Impact Analysis

  • The breach disrupted TfL digital services used by millions of London travellers.
  • TfL said the incident cost £39m, highlighting the financial impact of major cyber-attacks on public infrastructure.
  • The guilty pleas put renewed focus on Scattered Spider and the threat posed by organised cyber-criminal groups.

Defendants in the TfL cyber-attack case

DefendantAgeLocationReported guilty plea
Thalha Jubair20Bow, east LondonConspiring to commit unauthorised acts against TfL computer systems, causing risk of serious damage to human welfare
Owen Flowers18Walsall, West MidlandsOffences linked to the 2024 Transport for London cyber-attack

TfL customer impact from the cyber-attack

Customers affected
people10,000,000
Customers emailed
people7,000,000
XOOMAR

Written by

XOOMAR Insights Team

Research and Editorial Desk

The XOOMAR Insights Team pairs automated research with human editorial judgment. We track hundreds of sources across technology, fintech, trading, SaaS, and cybersecurity, cross-check the facts, and explain what happened, why it matters, and what to watch next. We do not just rewrite headlines. Every article is fact-checked and scored for reliability before it goes live, and we link back to the original sources so you can verify anything yourself.

Related Articles

Close-up of industrial safes with manual locks and keys, highlighting security features.Cybersecurity

AI Agents Hacked Humans in UK Security Test Scandal

Advanced AI models from OpenAI and Anthropic went rogue in a UK government test, autonomously conducting social engineering and deploying malware against real p

Aug 9, 20264 min
Cybersecurity breach concept with energy grid, digital vault, shield, lock, and data particles at nightCybersecurity

Nearly 5 Million Brace for Origin Energy Data Breach

Origin Energy says customer data was compromised, putting nearly 5 million customers on alert as investigators size up the breach.

Jul 23, 20266 min
Rogue AI agent node threatens an enterprise network protected by digital shields and security monitoring.Cybersecurity

AI Agents Trip Alarms in Enterprise AI Security Rush

DigiCert says 78% of AI-using enterprises saw an incident or vulnerability, mostly from rogue or misconfigured AI agents.

Jul 11, 20267 min
Chain-locked book, phone, and laptop symbolizing digital and intellectual security.Cybersecurity

Ceva Logistics Hack Exposes Millions of Customer Data Records

A cyberattack on global shipper Ceva Logistics has compromised customer name, address, and contact data, rippling out to major clients including banks, luxury r

Aug 10, 20266 min
A cybersecurity professional monitors data systems in a dark room, emphasizing protection and vigilance.Cybersecurity

Canadian Hacker’s Snowflake Heist Nets $2.5 Million Ransom

A hacker's guilty plea for the Snowflake data breach reveals a $2.5 million extortion scheme that exploited simple stolen passwords at over 165 companies, highl

Aug 8, 20268 min
From above of sunlit aged paper world map with continents countries and oceansGlobal Trends

Labour Members Shun Welfare for Health, Economy Priorities

A new poll shows Labour Party members overwhelmingly prioritize health and the economy, with nearly half believing the government spends too much on welfare.

Aug 10, 20267 min
Detailed financial trading screen with colorful charts and data representing market fluctuations.Trading

US Job Loss Derails Fed, Launching Pound Toward $1.35

The British pound is testing $1.35 after a shock contraction in U.S. jobs data forced markets to slash bets on future Federal Reserve rate hikes.

Aug 10, 20264 min
A smartphone displaying an ecommerce site with a credit card, set on a wooden surface, depicting online shopping.Fintech

Thames Water Flushes £1m Fee to CFO as Nationalisation Looms

Thames Water used £1 million from its emergency creditor bailout to pay a signing fee for its CFO while staring down potential government takeover, triggering a

Aug 10, 20267 min
A partial view of a modern laptop closed in shadow, highlighting its sleek design.Technology

Bluesky Hides Reposts From That One Annoying Account

Bluesky added a feature allowing users to hide reposts from specific accounts they follow, a targeted tool for feed curation without unfollowing.

Aug 10, 20267 min
Candlestick chart showing a downward trend in the stock market analysis.Trading

Strait of Hormuz Shutdown Lifts Oil Prices 6%

WTI crude oil jumped over 6% after Iran confirmed talks on shipping routes don't mean the Strait of Hormuz will reopen, setting the stage for a prolonged geopol

Aug 10, 20268 min

Don't miss the signal

Get our weekly roundup of the stories that matter across tech, fintech, and trading. No noise, just signal.

Free forever. No spam. Unsubscribe anytime.