Teenage Hackers Who Crippled Transport for London Jailed: A £39 Million Warning for Critical Infrastructure

Teenage Hackers Who Crippled Transport for London Jailed: A £39 Million Warning for Critical Infrastructure

They operated from bedrooms in east London and the West Midlands, yet between them they brought one of the world’s most complex urban transit networks to its knees. Thalha Jubair, 20, and Owen Flowers, 18, were sentenced this week to five and a half years in prison after pleading guilty in June to conspiracy to commit unauthorised acts in relation to a computer causing or creating risk of serious damage. The attack on Transport for London, executed over four days between 31 August and 3 September 2024, cost the organisation a combined £39 million — £29 million in operational damage and disruption, and a further £10 million in lost income.

The scale of the breach was extraordinary. Some 148 technology systems became inoperable. All 27,000 TfL employees were required to reset their passwords in person. Seven million commuters had personal data stolen. Live tube arrival times vanished from the TfL Go app. Oyster and contactless payment processing ceased. Services including Dial-a-Ride, which exists specifically to serve disabled and vulnerable passengers, were severely disrupted. The prosecution told Woolwich Crown Court that had the pair chosen to lock or destroy TfL’s central systems, the potential loss to the UK economy could have run to billions of pounds.

This was not opportunistic mischief. It was a methodical, technically sophisticated intrusion.

The attack began with a social engineering manoeuvre of the sort that consistently exposes the human weakness at the heart of even well-resourced organisations. An unnamed co-conspirator telephoned the TfL helpdesk armed with stolen login credentials, impersonating an employee locked out of the network. The helpdesk reset the password. From that foothold, Jubair and Flowers logged into Microsoft Azure and began, in the prosecution’s words, “using TfL’s own systems to hack itself,” escalating privileges until they held what the court described as “the keys to the kingdom” — the highest privileged access within the entire network. To conceal their tracks, they routed the intrusion through remote servers and created virtual machines inside TfL’s own infrastructure to destroy forensic evidence. Flowers livestreamed portions of the hack online throughout.

The brazenness is difficult to overstate. At one point during the attack, Flowers messaged Jubair via Telegram: “U won’t be laughing when ur sat in prison.” He was, of course, correct.

Both defendants were teenagers when the offences took place, a fact that featured prominently in mitigation but should not obscure the gravity of what occurred. Jubair had been writing computer programs by the age of ten and had entered the world of hacking by thirteen. By the time of the TfL attack, he had already accumulated convictions for thirteen counts of fraud, two of unauthorised computer access, one of obtaining access to a computer, one of blackmail, and stalking offences against two young women. He had also hacked a City of London Police server. US authorities separately want him in connection with alleged cyber crimes against forty-seven American victims, crimes that purportedly generated $115 million in ransomware payments to Jubair and associates. Flowers, meanwhile, had been known to West Midlands Police since the age of sixteen and had been served a cease-and-desist notice for making hoax calls to emergency services. He had declined an offer of intervention training. At the moment of his arrest in September 2024, his laptop was actively mid-intrusion into two US healthcare systems — attacks halted only, as the court noted, by the “fortuitous timing” of his detention.

Both men have been diagnosed with autism. Jubair additionally suffers from depression and a severe mood disorder and had previously attempted suicide. His counsel, Paul Keleher KC, characterised his client as a “modern day Oliver Twist,” groomed from childhood into a criminal network that exploited his technical gifts. The analogy has a certain rhetorical appeal, but it sits uneasily alongside the evidence of deliberate, sustained, and financially motivated criminal conduct across multiple jurisdictions.

Money, it turns out, was very much part of the picture. Jubair and Flowers were associated with Scattered Spider, a loose collective of hackers whom the National Crime Agency and US investigators believe responsible for attacks on Jaguar Land Rover and major retailers including Marks & Spencer. Some $200 million in cryptocurrency passed through accounts linked to Jubair. After his release from custody in March last year, $10 million moved from his crypto wallets. Flowers held $7.1 million in accounts despite having no declared income. Both were notably cautious about conspicuous consumption — until food delivery services undid them. Jubair paid for a takeaway order using gift cards purchased with cryptocurrency linked to ransomware payments. That transaction allowed US authorities to identify the delivery address and, by extension, the individual behind it. A schoolboy error, in the most literal sense.

Sentencing the pair, Mr Justice Turner found the attack “primarily motivated by selfish bravado, heedless of the severe consequences to others.” The prosecuting counsel, Mark Fenhalls KC, was blunter still, describing the defendants as “highly skilled with computers and capable of wreaking havoc” and “wholly indifferent to the consequences for the public.” TfL’s own victim impact statement warned that the access obtained could have enabled “catastrophic damage to many technology systems,” with cascading effects on Londoners’ access to education, healthcare, and essential services, as well as serious harm to the capital’s economy.

The NCA has identified the growing cohort of young British hackers as one of the most acute threats to national cyber security. The convictions of Jubair and Flowers have, the agency says, “effectively halted” Scattered Spider’s criminal activity — for now. The deeper lesson, however, is institutional. A phone call to a helpdesk, a reset password, and two teenagers in their bedrooms came within a decision of paralysing a city. The vulnerability was not primarily technical. It was procedural, human, and entirely preventable. That is the question policymakers and infrastructure operators ought to be asking with some urgency.