Teens who hacked TfL were known to police years before cyber-attack

Lobsters Hottest News

Summary

Two UK teenagers, part of the Scattered Spider cyber-crime collective, were known to police years before carrying out the TfL hack, highlighting challenges in early intervention against high-risk cyber offenders.

<p><a href="https://lobste.rs/s/f3boqg/teens_who_hacked_tfl_were_known_police">Comments</a></p>
Original Article
View Cached Full Text

Cached at: 06/26/26, 12:08 PM

# Teens who hacked TfL were known to police years before cyber-attack Source: [https://www.bbc.co.uk/news/articles/cx2kx8jr244o](https://www.bbc.co.uk/news/articles/cx2kx8jr244o) Flowers and Jubair's trial heard they were part of the cyber\-crime collective, Scattered Spider\. The loosely organised gang of young English\-speaking cyber\-criminals has been linked to dozens of other cyber\-attacks including on retailers[Marks and Spencer and the Co\-op](https://www.bbc.co.uk/news/articles/ckgnndrgxv3o)\. But the BBC has learned Flowers initially came to the attention of police shortly after he turned 16 years old\. In October 2023 he was caught carrying out low\-level cyber\-crime and visited by West Midland's Regional Cyber Crime Unit prevent officers\. Police say that during the visit Flowers did not engage with officers and was given a cease and desist order to deter him from further offending\. Police had the option to invite him to enrol in the national Cyber Choices programme, which works to steer young people away from cyber\-crime\. However Flowers was already being investigated for an offence and was reluctant to engage with officers, so they deemed him not suitable\. Just months later, the teenager \- who was living with his grandmother \- went on to commit a series of increasingly serious cyber\-offences with Scattered Spider which culminated in the TfL attack\. NCA deputy director Paul Foster, head of its National Cyber Crime Unit, said the case highlighted the challenges posed by a small number of highly capable offenders\. He called for stronger legal powers \- such as the proposed Cyber Crime Risk Orders \(CCROs\) \- to deal with cases like this\. CCROs, announced by the UK government as part of planned reforms to the Computer Misuse Act, are designed to let police and courts place restrictions on people considered high risk before they carry out further serious breaches\. They would "enable earlier law enforcement interventions against high\-risk cyber\-crime offenders," Foster said\. Flowers was eventually arrested on 16 September 2024 in connection with the TfL attack, which had started on 31 August\. In the arrest raid, investigators seized multiple devices from his bedroom, including laptops, desktop computers, hard drives and USB storage devices\. They reportedly discovered cryptocurrency holdings worth millions of pounds\. During the investigation, NCA officers uncovered evidence that computer systems belonging to two US healthcare organisations, SSM Health and Sutter Health, had also been infiltrated and damaged\. Flowers later pleaded guilty to offences relating to those hacks\. He is wanted in the US but the BBC understands authorities there will not be persuing further action against him\. After being charged, Flowers was released on bail under strict conditions\. He breached those conditions twice, in March 2025 and May 2025\. His co\-defendant Jubair had also been known to police for years\. In 2023, while still a juvenile, he received a Youth Rehabilitation Order for cyber offences linked to the Lapsus$ hacking group, which targeted major companies including Nvidia and BT/EE\. Because he was under 18, his identity could not be reported at the time\. Jubair has 22 previous convictions in total and began offending at 14 years old\. He is also wanted in the US in connection with cyber\-crimes that allegedly stole and extorted $87m \(£66\.1m\) from victims\.

Similar Articles

Scattered Spider Hackers Plead Guilty on Day 1 of Trial

Krebs on Security

Two key members of the Scattered Spider cybercrime group, Thalha Jubair and Owen Flowers, pleaded guilty in the UK for their roles in a 2024 cyberattack on Transport for London and other attacks involving ransomware, SIM-swapping, and phishing campaigns affecting over 130 organizations.

‘Scattered Spider’ Member ‘Tylerb’ Pleads Guilty

Krebs on Security

A senior member of the cybercrime group Scattered Spider, Tyler Robert Buchanan, has pleaded guilty to wire fraud and identity theft for orchestrating SMS phishing attacks that compromised major tech companies and stole millions in cryptocurrency.