Executive Overview
In a landmark development for international cybersecurity and law enforcement, two key operatives of the notorious global cybercrime syndicate known as Scattered Spider pleaded guilty in a United Kingdom court to criminal charges stemming from a devastating August 2024 ransomware attack. The cyberattack completely crippled Transport for London (TfL), the critical entity responsible for managing the public transport network across the Greater London area.
The guilty pleas, entered on what was scheduled to be the opening day of a six-week trial, mark a significant milestone in the ongoing global crackdown against one of the world’s most destructive and agile threat groups. The defendants—Thalha Jubair, 20, of East London, and Owen Flowers, 18, of Walsall—admitted to conspiring to commit unauthorized acts targeting critical infrastructure computer systems, creating a substantial risk of serious damage to human welfare.
Beyond their operations in the U.K., the duo’s admissions pull back the curtain on a vast, transnational criminal enterprise. Scattered Spider has long bedeviled Western corporations, healthcare institutions, and critical infrastructure operators. While Flowers and Jubair face imminent sentencing in a London court, their legal battles are far from isolated. They form part of an expanding web of international indictments, extraditions, and high-profile prosecutions spanning the U.K. and the United States, underscoring the borderless nature of modern cybercrime and the tightening net of global law enforcement collaboration.
Detailed Chronology of Operations and Legal Proceedings
The Transport for London Crippling and U.K. Targeting
The core of the recent U.K. prosecution centers on the audacious August 2024 cyberattack against Transport for London. By paralyzing TfL’s internal administrative and operational networks, the hackers thrust daily commuting for millions of Londoners into chaos, prompting emergency responses from British law enforcement and national intelligence agencies.
Investigators soon linked the incident to Scattered Spider, a collective largely celebrated within underground forums for its youthful membership, social engineering prowess, and ruthless execution. British authorities swiftly moved in, culminating in the coordinated arrests of Flowers and Jubair in mid-2025. Investigations by the U.K. National Crime Agency (NCA) revealed that the duo’s reach extended well beyond public transit; they were heavily implicated in high-profile ransomware and extortion operations against prominent British retailers, including Marks & Spencer, Harrods, and the Co-op Group.
As the legal proceedings unfolded, the scope of their digital footprint widened. According to reports from the BBC, Owen Flowers additionally confessed to participating in a separate conspiracy to infiltrate major U.S.-based healthcare providers—specifically SSM Health Care Corporation and Sutter Health—in September 2024.
Furthermore, multiple investigative sources familiar with the inquiry revealed that Flowers was the anonymous Scattered Spider member who granted media interviews in the chaotic days following the group’s September 2023 ransomware blitz against Las Vegas casino giants MGM Resorts and Caesars Entertainment.
The Transnational Nexus: U.S. Indictments and Global Extortion
While Flowers and Jubair face justice in the U.K., their alleged crimes have drawn intense scrutiny from American law enforcement agencies, particularly the U.S. Department of Justice (DOJ) and the Federal Bureau of Investigation (FBI).
In September 2025, federal prosecutors in New Jersey unsealed a sweeping indictment detailing Jubair’s alleged involvement in a staggering wave of cybercrime. The indictment asserts that Jubair and other core members of Scattered Spider executed approximately 120 computer network intrusions targeting 47 distinct U.S. entities between May 2022 and September 2025. Driven by extortion and financial greed, the syndicate allegedly forced victims to pay at least $115 million in ransom payments to recover encrypted systems or prevent the public leak of sensitive corporate and consumer data.
SIM-Swapping, Mass Phishing, and the "Star Chat" Operation
To understand how Scattered Spider achieved such unprecedented access to corporate networks, investigators point to their mastery of human engineering and telecommunications exploitation. Prosecutors allege that Jubair co-ran a high-volume Telegram channel known as Star Chat (or Star Fraud Chat).
This channel served as the command-and-control hub for an active SIM-swapping ring. The group utilized sophisticated voice- and SMS-based phishing attacks to harvest corporate credentials from employees working at major wireless service providers in both the United States and the United Kingdom. Armed with these stolen internal credentials, the threat actors accessed proprietary carrier tools. They executed unauthorized SIM swaps, redirecting targets’ phone numbers to attacker-controlled mobile devices. This malicious maneuver allowed them to effortlessly intercept voice calls and text message verifications—including critical one-time passcodes (OTPs) used for multi-factor authentication (MFA).

The New Jersey indictment further ties Jubair to a sweeping mass SMS phishing campaign launched in the summer of 2022. This weeks-long campaign bombarded corporate employees across hundreds of organizations with convincing text messages designed to steal single sign-on (SSO) credentials. The campaign successfully compromised more than 130 high-profile organizations, resulting in catastrophic data thefts and operational disruptions at tech mainstays including LastPass, DoorDash, Mailchimp, Plex, and Signal.
Early Beginnings and the "Everlynn" Persona
Investigative reporting by KrebsOnSecurity revealed that Jubair’s cybercriminal career began during his early teens. Operating under the hacker handle “Everlynn” as young as age 15, Jubair allegedly specialized in selling fraudulent "emergency data requests" (EDRs).
By compromising legitimate police and government email accounts, Everlynn and associates sent fabricated legal demands to major technology companies. These requests falsely claimed that impending data disclosures—such as user account details and IP addresses—were matters of urgent life-and-death necessity that bypassed standard court-ordered warrants. This early exposure to corporate vulnerabilities laid the groundwork for Jubair’s evolution into a foundational pillar of Scattered Spider’s enterprise infrastructure.
Supporting Context & Metrics: The Broader Scattered Spider Ecosystem
The guilty pleas of Flowers and Jubair do not represent an isolated victory; rather, they are part of a coordinated, multi-year international law enforcement offensive designed to dismantle the entire infrastructure of Scattered Spider. The network’s reliance on youthful, English-speaking hackers who fluidly combine social engineering, SIM-swapping, and enterprise-grade ransomware has made them one of the most resilient cyber threat groups in history.
Key Metrics and Legal Milestones
- $115 Million+: The estimated total ransom payments extorted by Scattered Spider across dozens of enterprise victims, according to U.S. federal indictments.
- 120+ Intrusions: The volume of corporate network breaches tied to indicted members across nearly 50 major U.S. entities.
- 10-Year Federal Sentence: Handed down in August 2025 to 20-year-old Florida resident and prominent Scattered Spider SIM-swapper Noah Michael Urban, who was also ordered to pay $13 million in restitution for wire fraud and conspiracy.
- April 2026 Guilty Plea: 24-year-old British national Tyler “Tylerb” Buchanan pleaded guilty to wire fraud conspiracy and aggravated identity theft. Buchanan, alongside Jubair and others, utilized credentials harvested from the 2022 SMS phishing campaign to steal at least $8 million in cryptocurrency from U.S. victims. Buchanan’s sentencing is currently scheduled for October 2, 2026.
- Pending Defendants: The U.S. DOJ continues prosecution against remaining indicted members, including Ahmed Hossam Eldin Elbadawy (“AD,” 24, of College Station, Texas), Evans Onyeaka Osiebo (21, of Dallas, Texas), and Joel Martin Evans (“joeleoli,” 26, of Jacksonville, North Carolina).
Official Statements and Industry Impact
While formal sentencing guidelines and victim impact statements are slated to be finalized during upcoming court dates, the broader cybersecurity community has viewed these developments as a watershed moment.
Security researchers emphasize that Scattered Spider exposed a fundamental fragility in corporate security postures: the human element. By weaponizing help desks, outsourcing providers, and mobile telecommunications carriers via targeted social engineering, the group bypassed complex perimeter defenses like hardware tokens and advanced firewalls.
Law enforcement agencies on both sides of the Atlantic have lauded the unprecedented level of information sharing that made these prosecutions possible. The National Crime Agency in the United Kingdom, alongside the FBI and the U.S. Department of Justice, demonstrated that international borders offer no safe harbor for cybercriminals who exploit critical global infrastructure for financial gain.
Future Outlook
The legal reckoning for Owen Flowers and Thalha Jubair is rapidly approaching, with a U.K. court scheduled to hand down their formal sentences on July 15, 2026. Given the gravity of their admissions—specifically concerning the crippling of essential public transport systems and risks to human welfare—legal experts anticipate significant custodial sentences designed to send an unequivocal deterrent message to the underground cybercrime community.
However, security analysts warn that dismantling Scattered Spider will require sustained, long-term vigilance. While the capture and prosecution of core operators like Flowers, Jubair, Urban, and Buchanan severely degrade the syndicate’s operational capacity, the decentralized, fluid nature of modern cybercriminal forums ensures that splinter cells and opportunistic copycats will continue to adapt.
Organizations worldwide must treat the downfall of Scattered Spider not as the end of an era, but as a critical blueprint for fortifying defenses. Companies must implement phishing-resistant multi-factor authentication (such as FIDO2/WebAuthn hardware keys), enforce rigorous identity verification protocols for internal IT help desk requests, and maintain robust incident response frameworks. As global law enforcement tightens the noose, the message to cybercriminals is clear: the digital shadows are shrinking, and accountability is inevitable.
