
Two teenagers-turned-defendants just got sentenced in London, and the way British officials talked about it afterward tells you a lot. UK Police Say Arrest of Two Young Hackers Disrupted Infamous Hacking Group — that’s more or less the exact line coming out of law enforcement, and it’s not just a headline writer’s spin. Cops are actually crediting this one case with knocking a major cybercrime outfit off balance.
Here’s the setup. Owen Flowers is 18. Thalha Jubair is 20. Both admitted, earlier this year, to breaking into Transport for London the agency that keeps the buses, tube, and rail network running across the capital. A judge handed down five and a half years. Not exactly what you’d picture for guys barely out of their teens, but then again, the damage they caused wasn’t small either. Also Read Roblox Launches AI-Powered Game Creation Feature in Mobile App
Table of Contents
The TfL Attack Nobody Saw Coming
People in London felt this one directly. The disruption to TfL systems dragged on for weeks, and the bill came out to somewhere around £29 million — call it $47 million. That’s not a rounding error. According to what The Guardian reported at the time, the access these two had was deep enough that they could’ve pulled the plug on the entire transit network if they’d wanted to. “The keys to the kingdom,” as one source put it.
So when UK Police Say Arrest of Two Young Hackers Disrupted Infamous Hacking Group, they’re not exaggerating for effect. This wasn’t some minor website defacement. It was a system that millions of commuters rely on daily, brought to its knees by two guys working out of, presumably, their bedrooms.
Not Their First Rodeo
What’s honestly a little unsettling is that neither Flowers nor Jubair was new to this. Jubair had already been convicted once before, as a minor, over attacks on the chipmaker Nvidia. He’d also separately admitted to hacking the City of London Police force the same police force chasing people like him, weirdly enough. Prosecutors called the pair “experienced and talented.” Police had apparently known about them for years before anything actually stuck.
Flowers didn’t stop at London transit either. He pleaded guilty to two more counts, these involving American healthcare companies, Sutter Health and SSM Health Care Corporation. When the National Crime Agency raided his home in September 2024 as part of the TfL case, agents walked in and found him mid-attack, running the healthcare intrusions live. So UK Police Say Arrest of Two Young Hackers Disrupted Infamous Hacking Group isn’t just about one incident. There was clearly a lot more going on behind it.

Who Is Scattered Spider
Both men have been linked to Scattered Spider, a hacking group that has built a bad reputation over the past couple years. They don’t really rely on cracking encryption or writing sophisticated malware. Mostly it’s phone calls. Someone rings up an IT help desk, sounds convincing, and walks away with access they were never supposed to have. Scattered Spider and a related group, ShinyHunters, have used this trick over and over, and companies keep falling for it because training staff is harder than patching software. Also Read How to Reserve and Change WhatsApp Username
The money tied to Jubair is a lot. He’s linked to schemes where victims paid out more than $100 million in ransom, and authorities have already seized crypto wallets connected to him worth tens of millions. On top of the UK sentence, he’s now facing separate US charges too, including computer fraud conspiracy and wire fraud.
Not the First Time Either
British police have done this before. Back in mid-2025, four people connected to Scattered Spider got arrested over attacks on Marks & Spencer, Co-op, and Harrods. One of those four was 17 years old.
UK Police Say Arrest of Two Young Hackers Disrupted Infamous Hacking Group fits into a pattern that keeps repeating: teenagers and people barely out of their teens pulling off attacks that used to require government-level resources. You don’t need a state budget for this kind of thing. You need patience, a convincing phone voice, and enough nerve to follow through. Also Read Why Raising Your First Round Is Harder Than Ever

What Happens From Here
The National Crime Agency says the wider investigation into Scattered Spider is still active. More arrests are possible as they go through the digital evidence from these raids. For now, officials are describing this arrest as a real hit to the group’s capability, not just a symbolic one.
Companies keep spending on firewalls and endpoint detection, and none of that is wasted money. But cases like this one keep showing the same thing the weak point is usually a person answering a phone, not a flaw in the code. Until that changes, groups like Scattered Spider will keep finding new recruits.