Business

Teens who hacked TfL were known to police years before cyber-attack

BBC Business · 2026-06-25

AI SUMMARY

• What happened: Two young men, Owen Flowers and Thalha Jubair, pleaded guilty to a cyber-attack on Transport for London (TfL) that disrupted services and compromised personal data of millions. • Why it matters: The case raises concerns about the effectiveness of interventions for young cyber-criminals, as both individuals had prior offenses and were known to law enforcement, highlighting the need for stronger legal measures against cyber-crime. • What to watch next: Sentencing for Flowers and Jubair is scheduled for July 16, 2025, and the case may influence discussions on proposed Cyber Crime Risk Orders aimed at preventing future offenses by high-risk individuals.

Image source, National Crime AgencyImage caption, Owen Flowers (left) and Thalha Jubair pleaded guilty on the first day of their trialByJoe TidyCyber correspondent, BBC World ServicePublished10 minutes agoTwo young men convicted over the cyber-attack that crippled Transport for London (TfL) in 2024 had long histories of cyber-offending and were both known to law enforcement bodies, the BBC has learnt.Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from east London, pleaded guilty on Monday to carrying out the attack.The breach disrupted TfL services for months, affected the personal data of millions of people and left all 28,000 TfL employees needing to reset their passwords in person.The BBC has discovered the authorities made frequent attempts to curb Flowers and Jubair's offending - raising questions over the effectiveness of such interventions with young cyber-criminals.Experts have told the BBC the case also indicates that perpetrators of cyber-attacks often do not appear to understand the real world consequences of their actions.The National Crime Agency (NCA) says it highlights the need for its officers to be given additional powers.Cease and desist orderFlowers and Jubair's trial heard they were part of the cyber-crime collective, Scattered Spider.The loosely organised gang of young English-speaking cyber-criminals has been linked to dozens of other cyber-attacks including on retailers Marks and Spencer and the Co-op.But the BBC has learned Flowers initially came to the attention of police shortly after he turned 16 years old.In October 2023 he was caught carrying out low-level cyber-crime and visited by West Midland's Regional Cyber Crime Unit prevent officers.Police say that during the visit Flowers did not engage with officers and was given a cease and desist order to deter him from further offending.Police had the option to invite him to enrol in the national Cyber Choices programme, which works to steer young people away from cyber-crime. However Flowers was already being investigated for an offence and was reluctant to engage with officers, so they deemed him not suitable.Just months later, the teenager - who was living with his grandmother - went on to commit a series of increasingly serious cyber-offences with Scattered Spider which culminated in the TfL attack.NCA deputy director Paul Foster, head of its National Cyber Crime Unit, said the case highlighted the challenges posed by a small number of highly capable offenders.He called for stronger legal powers - such as the proposed Cyber Crime Risk Orders (CCROs) - to deal with cases like this.CCROs, announced by the UK government as part of planned reforms to the Computer Misuse Act, are designed to let police and courts place restrictions on people considered high risk before they carry out further serious breaches. They would "enable earlier law enforcement interventions against high-risk cyber-crime offenders," Foster said.Millions in cryptoFlowers was eventually arrested on 16 September 2024 in connection with the TfL attack, which had started on 31 August.In the arrest raid, investigators seized multiple devices from his bedroom, including laptops, desktop computers, hard drives and USB storage devices. They reportedly discovered cryptocurrency holdings worth millions of pounds.During the investigation, NCA officers uncovered evidence that computer systems belonging to two US healthcare organisations, SSM Health and Sutter Health, had also been infiltrated and damaged. Flowers later pleaded guilty to offences relating to those hacks. He is still wanted in the US.After being charged, Flowers was released on bail under strict conditions. He breached those conditions twice, in March 2025 and May 2025.His co-defendant Jubair had also been known to police for years.In 2023, while still a juvenile, he received a Youth Rehabilitation Order for cyber offences linked to the Lapsus$ hacking group, which targeted major companies including Nvidia and BT/EE. Because he was under 18, his identity could not be reported at the time.Jubair has 22 previous convictions in total and began offending at 14 years old. He is also wanted in the US in connection with cyber-crimes that allegedly stole and extorted $87m (£66.1m) from victims.Image source, PAImage caption, Flowers (left) and Thalha Jubair pleaded guilty in court on MondayFlowers and Jubair are due to be sentenced for the TfL hack on 16 July.An expert witness who previously gave evidence in the Lapsus$ case involving Jubair agrees that the case demonstrates the need for stronger deterrents for the most prolific young cyber criminals."You have people who have already been caught and know they are in trouble with the law but carry out more crimes even under surveillance," Prof Peter Sommer said. "They don't seem to understand the consequences and there are real victims here losing their life savings in some case as well as corporations and their staff that are badly impacted," he added.Both Jubair and Flowers have been diagnosed with autism and the court heard that Jubair has depression and a severe mood disorder.Two men plead guilty over £39m TfL cyber attackPublished3 days agoTfL hack in 2024 affected around 10 million people, BBC can revealPublished6 MarchTfL contactless refunds return after cyber attackPublished4 December 2024Sign up for our Tech Decoded newsletter to follow the world's top tech stories and trends. Outside the UK? Sign up here.Related topicsLondonTransport for LondonCyber-crimeCyber-attacksCyber-securityComputer hacking

Source: BBC Business
RELATED NEWS

More Stories

All News
Business

Warning over power bank fire risk on flights as summer holidays begin

• What happened: Passengers are warned against packing power banks and vapes in hold luggage due to the increased fire risk from lithium batteries, which has ne...

Business

The abundant but expensive energy source that's under your feet

• What happened: There is growing bipartisan support in the U.S. for the development of geothermal energy, with new legislation introduced to enhance research a...

Business

Yes, there have been rows but here's how I've made moving back home work

• What happened: Natasha Suman, 24, moved back in with her parents in Bedford after university, initially planning to stay for a few months while job hunting, b...

Business

Apple hikes MacBook and iPad prices, blaming rising chip costs

• What happened: Apple has increased the prices of its MacBook and iPad products by nearly 20% due to rising costs of memory and storage chips, citing unprecede...

Business

How you can save money on your energy bill as debts rise

• What happened: Customer debts to energy suppliers in England, Wales, and Scotland have reached a record high of £4.79 billion, marking a 15% increase over the...

Business

EasyJet rejects fourth takeover offer

• What happened: EasyJet has rejected a fourth takeover offer from US investment firm Castlelake, valued at £4.93 billion, citing that the bid of £6.50 per shar...