Two teenage hackers, Thalha Jubair and Owen Flowers, launched a cyber-attack on Transport for London (TfL) from August 31 to September 3, 2024, giving them the highest privileged access to TfL's IT systems described as the "keys to the kingdom" [1, 2, 3].

Their attack compromised data of about 7 million TfL customers, including names and contact details, while disrupting vital services such as the dial-a-ride booking system for disabled passengers [1, 3, 2]. Around 27,000 TfL employees were forced to reset their passwords after the breach [1, 3].

The hackers initially gained entry by impersonating an employee and tricking a TfL phone help desk worker into resetting a password, allowing them to take control [2]. During the 16-hour attack, Jubair and Flowers live-streamed portions and boasted via Telegram, with Flowers messaging, "Scattered Spider is creating webs on the London Underground" [1, 2].

The hack disrupted 148 technology systems across TfL, leading to severe impacts on transport services and estimated damages costing TfL between £25 million and £29 million, depending on sources [2, 3].

TfL head Andy Lord called the attack "the worst incident he had faced in his career," underscoring its scale and impact [1].

Jubair and Flowers pleaded guilty in June 2026 and were sentenced on July 16 at Woolwich Crown Court to 5.5 years each for the TfL hack. Flowers received additional sentences for unrelated hacks on U.S. healthcare providers [1, 3]. Judge Mark Turner said their "actions had caused very serious disruption and were motivated primarily by selfish bravado" [3].

At sentencing, questions remained about Flowers' exact age during the attack, with reports ranging between 17 and 19 years old [1, 2, 3].

The next steps include ongoing recovery efforts within TfL to secure systems and prevent future breaches, with the network still addressing the disruption caused by the 2024 attack [2, 3].