Find notable cyber news and cases, enriched with sources, timelines, and signals.

Sentencing of Owen Flowers and Thalha Jubair in TfL cyber-attack case

Law Enforcement
First reported
Last updated
Happening score
H score 53
3 unique sources, 4 articles

Summary

Hide ▲

Owen Flowers and Thalha Jubair were sentenced at Woolwich Crown Court for the 2024 Transport for London (TfL) hack, receiving five and a half years in prison each under Section 3ZA of the UK Computer Misuse Act. UK police and the National Crime Agency have used the case to push for Cybercrime Risk Orders (CCROs), arguing current powers leave a gap for managing high-risk cyber offenders during long investigations. The TfL intrusion is linked to Scattered Spider, with reported costs of £29m in damages and £10m in lost income and disruption affecting between seven and 10 million people across the UK.

Related Happenings

NCA charges five London suspects in Russian Coms case

Law Enforcement
H score22 First: 14.07.2026 11:21 Last: 14.07.2026 11:21 Sources 1

About this happening: The NCA charged five London suspects in the Russian Coms fraud case, advancing a cybercrime prosecution tied to millions of scam calls. The suspects face allegatio...

Peter Stokes extradited and charged in Scattered Spider cybercrime case

Law Enforcement
H score57 First: 02.07.2026 11:45 Last: 02.07.2026 11:45 Sources 1

About this happening: The US Justice Department arrested and extradited Peter Stokes in a cybercrime case, bringing an alleged Scattered Spider member into US custody for prosecution. H...

Transport for London (TfL) customer data exposed after Transport for London (TfL) breach

Data Leak
H score46 First: 23.06.2026 18:31 Last: 23.06.2026 18:31 Sources 1

How related: TfL revealed on September 12, 2024, that the attackers had also stolen customer data (including names, addresses, and contact details).

About this happening: The Transport for London (TfL) intrusion became a confirmed data leak after customer data was stolen from the Oyster refunds system, raising misuse risk for affect...

Lytvynenko guilty plea in Conti ransomware case

Law Enforcement
H score36 First: 15.06.2026 14:33 Last: 15.06.2026 14:33 Sources 1

About this happening: Oleksii Oleksiyovych Lytvynenko was indicted by guilty plea in a US court over his role in the Conti ransomware case, extending criminal exposure for a defendant t...

DOJ guilty plea for Oleksii Oleksiyovych Lytvynenko in Conti ransomware case

Law Enforcement
H score36 First: 12.06.2026 20:54 Last: 12.06.2026 20:54 Sources 1

About this happening: Oleksii Oleksiyovych Lytvynenko pleaded guilty to conspiracy to commit wire fraud in a Conti ransomware case, resolving a major U.S. prosecution tied to attacks on vic...

Timeline

  1. 16.07.2026 14:51 1 articles · 13d ago

    Flowers and Jubair plead guilty in the TfL cyber-attack case

    Legal Policy Action Update

    Owen Flowers and Thalha Jubair pleaded guilty on June 22, 2026 to carrying out unauthorized acts against Transport for London under the UK's Computer Misuse Act. The case was described as only the second criminal prosecution of its kind in the UK under the CMA.

    Show sources
  2. 16.07.2026 14:51 5 articles · 13d ago

    Flowers and Jubair receive five years and six months for the TfL cyber-attack

    Legal Policy Action Update

    Judge Justice Turner at Woolwich Crown Court in London sentenced Owen Flowers, 18, and Thalha Jubair, 20, to five years and six months in prison each for the Transport for London cyber-attack. The court considered their guilty pleas, their youth and diagnosed neurodiversity as mitigating factors, and the judge said their high expertise meant they likely understood the impact of their actions.

    Show sources
  3. 16.07.2026 14:51 1 articles · 13d ago

    TfL cyber-attack costs £29m and disrupts customer-facing systems

    Victim Impact Update

    The Transport for London cyber-attack cost TfL £29m in loss and recovery costs, with TfL also claiming £10m in lost income. The intrusion affected internal and customer-facing systems, forced more than 27,000 TfL employees to reset their passwords in person, closed Oyster photocard applications for children and young people, shut down the Dial-a-Ride booking system, and took live tube time data for TfL Go and CityMapper offline.

    Show sources