The two members of the notorious Scattered Spider hacking group responsible for the cyber attack on Transport for London have today been sentenced to five years and six months in prison.

Thalha Jubair, 20, and Owen Flowers, 18, admitted their involvement in the attack that compromised millions of customer records, disrupted services across London's transport network and left TfL with a recovery bill of £29 million

The pair may now be behind bars, but the techniques they used remain some of the biggest cyber security threats facing organisations today.

One Phone Call Was All It Took

Many people assume major cyber attacks begin with sophisticated malware or unknown software vulnerabilities.

This one didn't.

Instead, the attackers convinced a TfL helpdesk employee that they were a legitimate member of staff who had lost access to their account. Once the authentication process had been reset, they gained access to the network before escalating their privileges until they effectively had unrestricted control over large parts of the organisation. 

In court, prosecutors described this as obtaining the "keys to the kingdom".

It highlights a reality many businesses overlook. Criminals are increasingly targeting people before they target technology.

The Cost Was Far More Than Financial

The attack affected TfL for months.

Approximately seven million customer records were compromised. More than 27,000 employees had to reset their passwords in person. Around 148 technology systems became unavailable, while online services, Oyster functionality and customer support were heavily disrupted. 

The final recovery cost reached £29 million, but the financial impact only tells part of the story.

Incidents like this consume thousands of hours of internal resource, damage customer confidence and place enormous pressure on operational teams trying to keep services running.

It Could Have Been Much Worse

During sentencing, the court heard the attackers had reached the highest level of administrative access within TfL's environment.

Had they chosen to deploy ransomware, delete critical systems or deliberately disrupt operations, the consequences could have been significantly worse.

Fortunately, TfL's cyber security teams, working alongside the National Crime Agency, were able to isolate systems before that happened. 

Social Engineering Remains One of the Biggest Threats

This attack reinforces a lesson cyber security professionals have been highlighting for years.

The biggest vulnerability in most organisations isn't outdated software.

It's trust.

Helpdesks and support teams are designed to help people. Cyber criminals know this, which is why social engineering continues to be one of the most successful methods of gaining access to corporate networks.

Technology can block many attacks, but if an attacker successfully impersonates a trusted employee, traditional security controls can quickly be bypassed.

What Businesses Should Be Doing

No organisation can guarantee it will never be targeted.

The goal is to make it as difficult as possible for attackers to gain access and to minimise the damage if they do.

Businesses should ensure they have:

  • Strong identity verification procedures for password resets.

  • Multi-factor authentication across all critical systems.

  • Ongoing cyber awareness training for employees.

  • Continuous monitoring to detect suspicious activity.

  • Privileged access controls to limit lateral movement.

  • A tested incident response and disaster recovery plan.

Cyber security is no longer just about prevention. It's about resilience.

Final Thoughts

The sentencing of Jubair and Flowers closes one of the UK's highest-profile cyber crime investigations, but it does not signal the end of attacks like these.

Groups such as Scattered Spider continue to demonstrate that determined attackers can exploit a single weakness to gain access to even the largest organisations.

Whether you're a public sector organisation, an SME or a large enterprise, the lesson is the same.

Cyber security is no longer optional. It's a fundamental part of protecting your people, your customers and your business.