The Fall of a Cyber Syndicate: Inside the Scattered Spider Prosecution

In a landmark moment for international cybersecurity enforcement, two young British nationals—Thalha Jubair, 20, and Owen Flowers, 18—have pleaded guilty to criminal charges stemming from a devastating August 2024 cyberattack that paralyzed Transport for London (TfL), the backbone of the Greater London transit network. Their admission of guilt, entered on the first day of what was scheduled to be a grueling six-week trial, marks a significant victory against "Scattered Spider," a prolific and elusive cybercrime collective that has wreaked havoc on both sides of the Atlantic.
The guilty pleas represent more than just a local legal victory; they serve as a critical turning point in the global effort to dismantle a group responsible for hundreds of millions of dollars in losses and the disruption of essential services.
The Charges and the Scope of the Crime
Thalha Jubair, of East London, and Owen Flowers, of Walsall, stood before a UK court this week to face the consequences of their digital incursions. Both men admitted to conspiring to commit unauthorized acts against Transport for London’s complex computer systems, specifically acknowledging that their actions created a risk of serious damage to human welfare—a charge that reflects the severity of disabling a public transport network.
While the London attack serves as the immediate catalyst for their prosecution, the breadth of their criminal enterprise extends far beyond the UK. Owen Flowers has additionally confessed to his role in a separate, high-stakes conspiracy targeting major U.S.-based healthcare providers, specifically SSM Health Care Corporation and Sutter Health, in September 2024.
For the victims, these crimes were not merely technical glitches; they were calculated assaults on infrastructure. The disruption of TfL crippled travel for millions of residents and commuters, while the targeting of medical providers threatened the continuity of life-saving care.
A Chronology of Digital Chaos
The rise and fall of these young hackers provide a chilling insight into the rapid evolution of modern cybercrime. The timeline of their activities is both extensive and alarming:
- Summer 2022: The foundation of the group’s notoriety was established through a massive SMS phishing campaign. By targeting employees at hundreds of organizations—including household names like LastPass, DoorDash, Mailchimp, Plex, and Signal—the group harvested sensitive single sign-on credentials.
- September 2023: Scattered Spider gained international infamy by launching a high-profile ransomware attack on MGM Resorts and Caesars Entertainment in Las Vegas. Investigative sources later identified Owen Flowers as the individual who acted as the group’s spokesperson, giving anonymous media interviews to brag about the chaos they had sown.
- August 2024: The group targeted Transport for London, leading to a massive operational shutdown of the transit network.
- September 2024: Flowers expanded his activities, participating in the hack against U.S. healthcare providers.
- July 2025: UK authorities executed a series of arrests, taking Flowers and Jubair into custody in connection with earlier ransomware attacks against retail giants including Marks & Spencer, Harrods, and the Co-op Group.
- September 2025: U.S. federal prosecutors in New Jersey unsealed a sweeping indictment against Jubair and his associates, alleging involvement in 120 separate network intrusions across 47 U.S. entities.
- April 2026: Tyler "Tylerb" Buchanan, a 24-year-old British member of the group, entered a guilty plea in the U.S. for his role in the 2022 phishing spree.
- July 15, 2026: Flowers and Jubair are scheduled for sentencing in a London court.
The Mechanics of the Syndicate: "Star Chat" and Beyond
The prosecution of Jubair has shed light on the sophisticated infrastructure that allowed Scattered Spider to operate. According to court filings, Jubair was a primary operator of "Star Chat," a Telegram channel that functioned as a clearinghouse for criminal services.
Central to their business model was "SIM-swapping." By utilizing voice- and SMS-based phishing attacks to compromise employees at major wireless providers in the U.S. and UK, the group gained the ability to intercept a target’s phone number. This allowed them to bypass multi-factor authentication (MFA) protocols, effectively "owning" the digital identities of their victims.
Furthermore, investigative reports have tied Jubair to a darker persona known as "Everlynn." As early as age 15, he was selling fraudulent "emergency data requests." By compromising police and government email accounts, he and his peers would trick major tech companies into handing over sensitive subscriber data—such as IP addresses and account details—by claiming the requests were matters of life-and-death urgency.
Supporting Data: The Cost of Ransom
The scale of the financial damage inflicted by Scattered Spider is staggering. According to the U.S. Department of Justice, the group’s victims paid at least $115 million in ransom payments between May 2022 and September 2025.

Beyond the raw ransom figures, the group was highly efficient at monetizing their access. In the 2022 phishing campaign alone, Buchanan, Jubair, and their co-conspirators utilized stolen credentials to siphon off at least $8 million in cryptocurrency from victims across the United States.
The sentencing of Noah Michael Urban, a 20-year-old Florida resident and member of the group, provides a glimpse into the legal repercussions. In August 2025, Urban was sentenced to 10 years in federal prison and ordered to pay $13 million in restitution—a stark warning to other aspiring members of the syndicate.
Official Responses and the Long Arm of Justice
The collaboration between UK authorities, such as the National Crime Agency (NCA), and the U.S. Department of Justice has been pivotal in this case. The US DOJ has signaled that their work is far from over. Three other defendants named in the New Jersey indictment remain at large or are currently undergoing legal proceedings: Ahmed Hossam Eldin Elbadawy ("AD"), Evans Onyeaka Osiebo, and Joel Martin Evans ("joeleoli").
The message from law enforcement is clear: the digital realm is no longer a safe haven for those who hide behind pseudonyms and encrypted messaging apps. The unmasking of figures like Jubair and Flowers demonstrates that even the most "prolific" hackers are susceptible to forensic investigation and international legal cooperation.
Implications for Global Cybersecurity
The conviction of these young men brings several critical issues to the forefront of the cybersecurity landscape:
1. The Vulnerability of Human Infrastructure
The success of Scattered Spider relied heavily on social engineering. By targeting the human element—through phishing and SIM-swapping—rather than just the technology, the group exploited the weakest link in corporate security. This serves as a mandate for organizations to implement more robust identity verification processes that move beyond traditional SMS-based MFA.
2. The Rise of "Cyber-Mercenary" Youth
The ages of the defendants—some of whom began their criminal careers as teenagers—highlight a disturbing trend: the rise of highly skilled, tech-native youths who view cybercrime as a viable, high-stakes career path. The "Everlynn" alias, used by Jubair at 15, proves that the barrier to entry for high-level cybercrime has been lowered significantly.
3. The Necessity of International Cooperation
The Scattered Spider case would not have been solved without the seamless coordination between UK and U.S. law enforcement. As cybercriminals continue to operate across jurisdictional borders, the ability of global agencies to share intelligence, synchronize arrests, and pursue extradition will remain the most effective tool in deterring large-scale ransomware operations.
As the London court prepares to sentence Flowers and Jubair on July 15, the tech world watches closely. While this chapter is closing, the broader struggle against decentralized, profit-motivated cyber-syndicates remains one of the most pressing challenges of the digital age. The fall of Scattered Spider is a victory, but it is also a reminder that the cost of digital negligence is paid in both dollars and the stability of the public infrastructure upon which society depends.
