In a landmark moment for international cybersecurity enforcement, two young British men appeared before a London court this week to enter guilty pleas for their roles in a wave of cyberattacks that have cost global corporations and public institutions hundreds of millions of dollars. The defendants, 20-year-old Thalha Jubair and 18-year-old Owen Flowers, were identified as pivotal members of "Scattered Spider," a prolific and sophisticated cybercrime syndicate that has terrorized the digital infrastructure of both the United States and the United Kingdom for years.
Their admission of guilt on the first day of what was scheduled to be a grueling six-week trial marks the culmination of a massive, multi-jurisdictional investigation. The duo faced charges stemming from a devastating August 2024 cyberattack on Transport for London (TfL), the body overseeing the British capital’s massive public transport network. Their actions paralyzed essential services, demonstrating the group’s capability to weaponize digital intrusion against critical human welfare infrastructure.
The Charges and the Scope of the Crime
Thalha Jubair, hailing from East London, and Walsall-native Owen Flowers, admitted to conspiring to commit unauthorized acts against computer systems—a charge carrying significant weight under UK law due to the risk of serious damage to human welfare. While the TfL incident brought them to the immediate attention of British authorities, the breadth of their criminal enterprise extends far beyond London’s subway turnstiles.
Court documents reveal that Flowers also pleaded guilty to participating in a conspiracy to compromise U.S.-based healthcare providers, specifically SSM Health Care Corporation and Sutter Health, in September 2024. These intrusions underscore the group’s callous disregard for the stability of essential services, targeting health providers even as they simultaneously crippled transportation networks.
The U.S. Department of Justice (DOJ) remains hot on their heels. In September 2025, prosecutors in New Jersey unsealed a sweeping indictment against Jubair. The document alleges a staggering pattern of criminal activity spanning from May 2022 to September 2025. During this window, Jubair and his co-conspirators reportedly orchestrated 120 separate network intrusions across 47 U.S. entities. The financial toll of these operations is eye-watering: investigators believe the group successfully extracted at least $115 million in ransom payments from their victims.
A Chronology of Digital Chaos
To understand the rise of Scattered Spider, one must look at the evolution of their tactics, which shifted from opportunistic fraud to high-stakes corporate extortion.
2022: The SMS Phishing Spree
The foundation of the group’s success was built on "smishing"—mass SMS phishing campaigns. In the summer of 2022, Jubair and fellow syndicate member Tyler "Tylerb" Buchanan utilized sophisticated social engineering to harvest single sign-on (SSO) credentials from employees at hundreds of organizations. This campaign breached over 130 high-profile companies, including household names like LastPass, DoorDash, Mailchimp, Plex, and Signal. The objective was clear: use stolen credentials to access administrative backdoors and siphon cryptocurrency. Prosecutors estimate this specific campaign resulted in at least $8 million in stolen assets.
2023: The MGM/Caesars Crisis
The group’s notoriety skyrocketed in September 2023 when they executed a series of high-profile ransomware attacks against major Las Vegas casino operators, including MGM Resorts and Caesars Entertainment. Sources familiar with the investigations have identified Owen Flowers as the individual who acted as the group’s media liaison during this period, anonymously granting interviews to news outlets to boast about the chaos they had wrought.
2024–2025: Targeting Critical Infrastructure
By 2024, the syndicate had pivoted to targeting critical national infrastructure in the UK, including the August attack on Transport for London and concurrent ransomware efforts against major retailers like Marks & Spencer, Harrods, and the Co-op Group. The arrest of Flowers and Jubair in the summer of 2025 finally brought a temporary halt to their UK-based operations.

The Mechanics of Extortion: Star Chat and SIM Swapping
Central to the success of Jubair and his associates was a Telegram channel known as "Star Chat." This digital hub served as the nerve center for a specialized service: SIM-swapping.
The group specialized in voice- and SMS-based phishing attacks targeting employees of major telecommunications providers in the U.S. and the UK. By compromising internal employee tools—as evidenced by internal "Rocket Ace" (one of Jubair’s known aliases) receipts—the group could hijack a target’s phone number. Once a victim’s number was redirected to a device controlled by the hackers, they could intercept one-time multi-factor authentication (MFA) codes, effectively bypassing the security measures meant to protect corporate networks.
This technical proficiency was supplemented by "emergency data requests." As early as age 15, Jubair—operating under the alias "Everlynn"—was selling fraudulent requests that exploited compromised police and government email addresses. By posing as law enforcement, the group coerced major tech companies into handing over sensitive subscriber data, claiming urgent life-and-death situations that bypassed standard court-ordered oversight.
Global Enforcement and Judicial Implications
The legal net has tightened significantly around Scattered Spider over the past 12 months. The prosecution of Flowers and Jubair is merely the latest in a series of victories for international law enforcement.
In April 2026, 24-year-old Tyler Buchanan pleaded guilty to wire fraud and aggravated identity theft. His cooperation and the subsequent evidence provided by his digital footprints have been instrumental in the DOJ’s broader push against the group. Similarly, in August 2025, Noah Michael Urban, a Florida-based member of the syndicate, was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution—a stark warning to other aspiring cybercriminals.
However, the DOJ notes that the investigation is far from complete. Three other individuals named in the initial indictments remain under the scrutiny of federal prosecutors:
- Ahmed Hossam Eldin Elbadawy ("AD"), 24, of College Station, Texas.
- Evans Onyeaka Osiebo, 21, of Dallas, Texas.
- Joel Martin Evans ("joeleoli"), 26, of Jacksonville, North Carolina.
Implications for Corporate Security
The Scattered Spider case represents a paradigm shift in how security professionals view the "insider threat." The group did not rely solely on brute-force hacking; they relied on human psychology. By manipulating low-level employees through social engineering and exploiting the inherent trust placed in MFA systems, they were able to bypass the most expensive cybersecurity defenses in the world.
For the private sector, the implications are profound:
- MFA is not a Silver Bullet: The group’s ability to intercept SMS-based MFA and social-engineer employees highlights the need for hardware-based security keys and more robust identity verification.
- The "Human Firewall": Corporate training must evolve to recognize the specific tactics of SIM-swapping and SMS phishing.
- Cross-Border Cooperation: The successful prosecution of these individuals proves that when the FBI, the UK’s National Crime Agency (NCA), and other international bodies align their intelligence, the "anonymity" afforded by the dark web is effectively dismantled.
As Flowers and Jubair await their sentencing, scheduled for July 15, 2026, in London, the cybersecurity community is breathing a collective, albeit cautious, sigh of relief. The fall of these key members of Scattered Spider is a victory for the rule of law, but the persistence of their remaining co-conspirators suggests that the war against digital extortion is an ongoing struggle—one that requires constant vigilance, international cooperation, and a fundamental rethinking of how we protect our most critical digital assets.
