The digital underworld, often characterized by its anonymity and reach, faced a significant reckoning this week. In a London courtroom, two young men—Thalha Jubair, 20, and Owen Flowers, 18—formally entered guilty pleas for their roles in a sophisticated cyberattack that paralyzed the public transport network of Greater London. Their admission, delivered on the opening day of what was anticipated to be a six-week trial, marks a pivotal moment in the ongoing battle against "Scattered Spider," one of the most prolific and audacious cybercrime syndicates to emerge in the last decade.
The scale of the damage caused by these two individuals—and the broader network they belonged to—is staggering. From the disruption of London’s transit systems to the extortion of multinational corporations and the theft of tens of millions of dollars in cryptocurrency, their digital fingerprints are found across a global landscape of cyber-devastation.
The Charges and the Plea
Thalha Jubair, a resident of East London, and Owen Flowers, hailing from Walsall, faced severe charges regarding their activities against Transport for London (TfL). Both defendants admitted to conspiring to commit unauthorized acts against the organization’s computer systems, specifically acknowledging that their actions posed a "risk of serious damage to human welfare."
For Flowers, the legal jeopardy extends well beyond the United Kingdom. He further admitted to his involvement in a conspiracy to infiltrate major U.S.-based healthcare providers, specifically SSM Health Care Corporation and Sutter Health, in September 2024. These admissions underscore a pattern of behavior that ignores international borders and targets critical infrastructure, moving beyond simple data theft into the realm of endangering public safety.
A Chronology of Digital Chaos
To understand the gravity of the Scattered Spider phenomenon, one must look at the timeline of their escalation. The group did not appear overnight; rather, they evolved from opportunistic phishers into a sophisticated ransomware-as-a-service entity.
2022: The SMS Phishing Spree
The foundation of the group’s notoriety was laid in the summer of 2022. During this period, a massive, coordinated SMS phishing campaign—often referred to as "smishing"—swept across the United States. Jubair and other key members, including Tyler "Tylerb" Buchanan, harvested single sign-on (SSO) credentials from employees at hundreds of organizations.
This campaign was not merely about access; it was about infiltration. The breach successfully compromised over 130 entities, including high-profile tech and service firms such as LastPass, DoorDash, Mailchimp, Plex, and Signal. Prosecutors allege that the credentials harvested during this period were subsequently used to facilitate the theft of at least $8 million in cryptocurrency.
2023: The Las Vegas Siege
By late 2023, Scattered Spider had moved into the spotlight with their brazen ransomware attacks on MGM Resorts and Caesars Entertainment. These attacks crippled the operational capacity of some of the largest casino operators in Las Vegas. In the aftermath, it was revealed that Owen Flowers acted as a primary media spokesperson for the group, anonymously granting interviews to news outlets to boast of the group’s prowess and dictate the terms of their extortion.
2024–2025: Expanding the Net
The group’s reach continued to expand throughout 2024. They targeted major British retailers, including Marks & Spencer, Harrods, and the Co-op Group, forcing the U.K. National Crime Agency (NCA) to intensify its investigations. By the time of their arrest in July 2025, Flowers and Jubair were being sought not just by British authorities, but by a coalition of U.S. federal agencies, including the Department of Justice and the FBI.
The Anatomy of an Infrastructure: "Star Chat" and SIM Swapping
One of the most damning pieces of evidence against Jubair is his role in managing "Star Chat," a Telegram channel that functioned as a central hub for cybercrime. The channel facilitated a service known as "SIM-swapping."
By utilizing voice- and SMS-based phishing, the group gained access to the internal tools of major U.S. and U.K. wireless providers. Once inside, they could redirect a victim’s phone number to a device under the attacker’s control. This allowed them to intercept multi-factor authentication (MFA) codes, effectively bypassing the security measures meant to keep corporate accounts safe.

Jubair’s digital alter ego, "Rocket Ace," was heavily involved in selling these services. Receipts recovered by investigators show the group charging for the ability to hijack a victim’s communication lines, turning a standard mobile phone into a gateway for corporate account takeover.
A History of Escalation: From "Everlynn" to International Fugitive
Jubair’s trajectory in the cybercrime world began early. Investigators identified him as the user behind the handle "Everlynn," a persona he adopted as early as age 15. Even then, he was engaged in highly illegal activities, selling "emergency data requests" (EDRs).
EDRs are supposed to be reserved for genuine life-and-death situations, allowing law enforcement to bypass court orders to secure urgent data. By compromising police and government email accounts, "Everlynn" sold these fraudulent requests to other criminals, tricking major tech companies into handing over sensitive subscriber information, such as IP addresses and private emails. This early exposure to the mechanics of corporate security gaps laid the groundwork for his later, more destructive exploits.
Official Responses and the Regulatory Landscape
The U.S. Department of Justice has been relentless in its pursuit of the Scattered Spider collective. The indictment unsealed in New Jersey in September 2025 painted a harrowing picture: 120 separate network intrusions involving 47 U.S. entities. The total ransom payments extracted by the group are estimated at no less than $115 million.
U.S. prosecutors have emphasized that the fight against Scattered Spider is far from over. While Tyler Buchanan has already pleaded guilty to wire fraud and identity theft, and Noah Michael Urban was sentenced to 10 years in prison in August 2025, several key figures remain at large or are currently facing trial. These include Ahmed Hossam Eldin Elbadawy ("AD"), Evans Onyeaka Osiebo, and Joel Martin Evans ("joeleoli").
The NCA in the U.K. has characterized the arrest of Flowers and Jubair as a major blow to the group’s operational hierarchy. However, the ease with which these individuals were able to navigate global telecommunications infrastructure has led to renewed calls for stricter oversight of how telcos protect their internal administrative tools.
The Implications: A New Era of Cyber-Risk
The case of Flowers and Jubair serves as a sobering reminder of the changing face of cyber-threats. The "Scattered Spider" model is not the work of state-sponsored intelligence agencies, but rather a loose confederation of digitally native teenagers and young adults who leverage social engineering and existing corporate vulnerabilities to devastating effect.
Impact on Public Infrastructure
The Transport for London attack demonstrated that the digital world and the physical world are now inextricably linked. When computer systems at a major transit authority are held for ransom, the result is not just lost data—it is stalled trains, interrupted commutes, and a fundamental breakdown in public trust.
The Failure of MFA as a Panacea
For years, cybersecurity professionals pushed Multi-Factor Authentication as the "silver bullet" for security. The rise of SIM-swapping and the exploitation of SSO credentials by groups like Scattered Spider prove that MFA is not infallible. As long as the human element of telecommunications—the customer service representative or the system administrator—can be socially engineered, the security of the end-user remains at risk.
What Comes Next?
Flowers and Jubair are scheduled to be sentenced in a London court on July 15, 2026. Their sentencing will likely be a bellwether for how the judiciary intends to treat young, highly skilled cyber-criminals who transition from "script kiddies" to architects of massive, systemic disruption.
As the legal proceedings continue, the global cybersecurity community remains on high alert. The dismantling of Scattered Spider is a significant victory for international law enforcement, but the methodologies used by the group—phishing, social engineering, and the exploitation of internal administrative tools—remain open-source templates for the next generation of digital insurgents. The question for corporations and government entities alike is no longer just how to stop the hackers, but how to harden the human and administrative systems that hackers rely on to succeed.
