In a landmark development for international cybersecurity, two prominent members of the notorious "Scattered Spider" hacking collective—an organization that has terrorized global corporations and critical infrastructure for years—have pleaded guilty to criminal charges in the United Kingdom. Their admission of guilt, delivered on the opening day of what was anticipated to be a grueling six-week trial, marks a significant victory for law enforcement agencies on both sides of the Atlantic.
Thalha Jubair, 20, of East London, and 18-year-old Owen Flowers of Walsall, stand at the center of this legal storm. The duo faced charges stemming from a devastating August 2024 cyberattack that paralyzed Transport for London (TfL), the backbone of the Greater London public transit network. Their pleas represent more than just a local conviction; they signal the crumbling of a syndicate that has extracted over $115 million in ransom payments and breached hundreds of high-profile entities.
The Core Conviction: Crippling London’s Infrastructure
The charges against Jubair and Flowers highlight the shifting target profile of modern cyber-extortionists. While many groups focus on corporate data theft, the August 2024 assault on Transport for London demonstrated a willingness to threaten "serious damage to human welfare."
By infiltrating TfL’s internal systems, the duo disrupted the operational technology governing one of the world’s busiest metropolitan transport networks. The incident caused widespread chaos for commuters, forcing officials to scramble to restore essential services. In court, both men admitted to conspiring to perform unauthorized acts against computer systems, an acknowledgment that carries severe sentencing implications.
For Owen Flowers, the scope of his criminal activity extended well beyond the U.K. borders. He entered additional pleas regarding a conspiracy to infiltrate major U.S. healthcare providers, including SSM Health Care Corporation and Sutter Health, in September 2024. These actions underscore a calculated pattern of targeting critical sectors—transportation and healthcare—where the pressure to pay ransoms is highest due to the immediate risk to life and public safety.
A Chronology of Digital Chaos: From Phishing to Ransomware
To understand the severity of the Scattered Spider threat, one must look at the timeline of their escalation, which transformed from low-level credential theft into a sophisticated, multi-national criminal enterprise.
The Early Days (2022): The SMS Phishing Spree
The foundation of the group’s success was built on a massive, summer-long SMS phishing campaign in 2022. Using advanced social engineering, the group harvested single sign-on (SSO) credentials from employees at hundreds of organizations. This campaign facilitated breaches at industry giants, including LastPass, DoorDash, Mailchimp, Plex, and Signal.
The "Star Chat" and SIM-Swapping Era
Jubair, operating under various handles including "Rocket Ace," co-managed an infamous Telegram channel known as "Star Chat." This digital marketplace served as a nexus for SIM-swapping operations. By compromising the internal tools of major U.S. and U.K. wireless carriers, the group could hijack phone numbers, effectively bypassing multi-factor authentication (MFA) protocols and intercepting sensitive one-time codes.
The Infamous Casino Attacks (2023)
By September 2023, the group had matured into a full-scale ransomware operation. Their attacks on MGM Resorts and Caesars Entertainment in Las Vegas made global headlines. It is widely alleged that Owen Flowers was the primary voice behind the group’s media strategy, providing anonymous interviews to news outlets to amplify the pressure on the casino giants to meet the group’s ransom demands.

The 2024–2025 Escalation
The group’s footprint continued to grow, hitting British retail icons such as Marks & Spencer, Harrods, and the Co-op Group. Simultaneously, U.S. federal investigators were building a massive case against the group, linking 47 U.S. entities to a spree of 120 intrusions between May 2022 and September 2025.
The Anatomy of an Investigation
The investigation into Scattered Spider has been characterized by an unprecedented level of cooperation between the U.K.’s National Crime Agency (NCA) and U.S. law enforcement, including the Department of Justice and the FBI.
The "Everlynn" Connection
The investigation also shed light on the early development of these young hackers. It was revealed that as early as age 15, Jubair operated under the handle "Everlynn." During this period, he specialized in "emergency data requests" (EDRs). By compromising police and government email accounts, he would send fraudulent, high-priority requests to major tech firms, demanding private user data under the guise of life-or-death emergencies—a tactic that bypassed the need for traditional legal warrants.
The Network of Conspirators
The fall of Jubair and Flowers is part of a larger purge of the Scattered Spider ranks:
- Tyler "Tylerb" Buchanan: A 24-year-old British national who pleaded guilty in April 2026 to wire fraud conspiracy. He was a key player in the 2022 SMS phishing spree, helping to funnel at least $8 million in stolen cryptocurrency.
- Noah Michael Urban: A Florida-based member sentenced in August 2025 to 10 years in federal prison, reflecting the severity of the charges now facing the group’s members.
- The Unresolved: The U.S. Department of Justice continues to pursue other members, including Ahmed Hossam Eldin Elbadawy (a.k.a. "AD"), Evans Onyeaka Osiebo, and Joel Martin Evans (a.k.a. "joeleoli").
Implications for Global Security
The guilty pleas in the London court serve as a stark warning to the cyber-criminal underground. The era of impunity for young, technically proficient hackers is rapidly closing as international law enforcement becomes more adept at tracking digital footprints across borders.
The Erosion of "Anonymity"
The downfall of Flowers and Jubair illustrates that even the most "careful" hackers are susceptible to human error and rigorous forensic analysis. From the interviews given to the press to the digital paper trail left on Telegram and through internal corporate tools, the group’s ego and desire for notoriety became their greatest liability.
Corporate Resilience
The Scattered Spider saga has forced a massive re-evaluation of security protocols. The effectiveness of their attacks on SSO systems and MFA—previously considered the "gold standard" of security—has forced companies to adopt more robust, phishing-resistant hardware keys and zero-trust architectures. The $115 million in damages cited by U.S. prosecutors serves as a sobering reminder of the financial stakes for companies that fail to harden their defenses against social engineering.
Sentencing and Future Deterrence
With sentencing for Flowers and Jubair scheduled for July 15, 2026, the global cybersecurity community will be watching closely. The outcome will likely serve as a barometer for how Western courts intend to handle the next generation of cyber-terrorists—balancing the need for rehabilitation with the necessity of deterring a new wave of digital-native criminals who view infrastructure as a playground for extortion.
As the dust settles, the conviction of these two men marks a pivotal moment in the fight against cyber-crime. It proves that despite the global reach and technological sophistication of modern hacking collectives, they are not untouchable. By bridging the gap between national jurisdictions and tightening the net around these digital fugitives, the U.K. and U.S. have sent a clear message: the long reach of the law is catching up to the spiders.
