The cyber-attack that crippled Transport for London (TfL) in 2024 was carried out by two teenagers who had been known to law enforcement for years prior to the breach, according to a BBC investigation. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, pleaded guilty on Monday to carrying out the attack that disrupted TfL services for months and exposed the personal data of millions of people. All 28,000 TfL employees were forced to reset their passwords in person as a result.
Background: The Attack and Its Impact
The breach began on 31 August 2024 and severely affected TfL's digital infrastructure for months. The attack is one of the most significant cyber incidents targeting critical UK transport infrastructure. The BBC reported that the disruption left all 28,000 employees needing in-person password resets, and the personal data of millions of users was compromised. The attackers were part of the cyber-crime collective Scattered Spider, a loosely organised gang of young English-speaking cyber-criminals linked to dozens of other attacks, including on retailers Marks and Spencer and the Co-op.
The Perpetrators: Known to Police
Owen Flowers initially came to police attention shortly after turning 16, according to the BBC. In October 2023, he was caught carrying out low-level cyber-crime and was visited by officers from the West Midland's Regional Cyber Crime Unit. During the visit, Flowers did not engage with officers and was issued a cease and desist order to deter further offending. Police considered inviting him to the national Cyber Choices programme, which aims to steer young people away from cyber-crime, but deemed him unsuitable because he was already under investigation and reluctant to engage.
Just months later, Flowers—living with his grandmother—joined Scattered Spider and committed increasingly serious cyber-offences, culminating in the TfL attack. Thalha Jubair also had a long history of cyber-offending, though specific details of prior interventions were not detailed in the source.
Flowers was arrested on 16 September 2024 in connection with the TfL attack. In the arrest raid, investigators seized multiple devices from his bedroom, including laptops, desktop computers, hard drives, and USB storage devices. They reportedly discovered cryptocurrency holdings worth millions of pounds. During the investigation, the National Crime Agency (NCA) uncovered evidence that computer systems belonging to two US healthcare organisations—SSM Health and Sutter Health—had also been infiltrated and damaged. Flowers later pleaded guilty to offences related to those hacks and is still wanted in the United States.
Law Enforcement Response and Calls for Stronger Powers
The case has raised questions about the effectiveness of interventions with young cyber-criminals. Paul Foster, NCA deputy director and head of its National Cyber Crime Unit, said the case highlights the challenges posed by a small number of highly capable offenders. He called for stronger legal powers, such as the proposed Cyber Crime Risk Orders (CCROs), to deal with such cases. CCROs were announced by the UK government as part of planned reforms to the Computer Misuse Act and are designed to let police and courts place restrictions on people considered high risk before they carry out further serious breaches.
"They would enable earlier law enforcement interventions against high-risk cyber-crime offenders," Foster said.
The NCA says the case underscores the need for its officers to be given additional powers. Experts told the BBC that perpetrators of cyber-attacks often do not appear to understand the real-world consequences of their actions.
Implications for Enterprise Cybersecurity
For technology decision-makers, this case offers critical lessons. The fact that two teenagers with known histories of offending could execute a devastating attack on a major public transport authority underscores the importance of monitoring cyber-criminal ecosystems such as Scattered Spider. Enterprises should consider:
- Threat intelligence sharing: The attackers were linked to multiple organisations, including healthcare providers in the US. Organisations should participate in information-sharing communities.
- Incident response preparedness: TfL's need for all 28,000 employees to reset passwords in person illustrates the severe operational disruption a breach can cause. Enterprises should test password reset procedures and multi-factor authentication.
- Supply chain vetting: While not directly mentioned, the case highlights that cyber-criminals often target interconnected systems. Entities should assess the cybersecurity posture of critical partners.
| Party | Role | Key Detail |
|---|---|---|
| Owen Flowers | Perpetrator | Arrested 16 Sep 2024; crypto holdings worth millions; hacking of US healthcare firms |
| Thalha Jubair | Perpetrator | Pleaded guilty with Flowers |
| NCA | Law enforcement | Deputy director Paul Foster called for CCROs |
| TfL | Victim | 28,000 employees reset passwords; millions' data exposed |
| Scattered Spider | Cyber-crime group | Linked to M&S, Co-op, TfL |
The case also illustrates the challenge of deterring young offenders. Despite a cease and desist order and the availability of diversion programmes like Cyber Choices, Flowers continued offending. For corporate security teams, this reinforces the need for behavioral monitoring and early intervention within their own environments—perhaps via insider threat programs.
As Paul Foster noted, the NCA needs additional powers. For now, enterprises must remain vigilant, knowing that even known offenders can evade effective intervention until it is too late.