TfL Hackers Sentenced: What the Scattered Spider Case Teaches Ordinary Users
Two men linked to Scattered Spider have been jailed over the Transport for London cyberattack. The case is a reminder that social engineering, stolen credentials and account recovery weaknesses can hurt real-world services.
Quick takeaways
- The National Crime Agency says two men were sentenced to five years and six months each for the 2024 Transport for London cyberattack.
- The NCA says the attack caused £29 million in reported TfL losses and recovery costs, forced employees through password resets, and disrupted customer-facing services.
- For households, the practical lesson is account security: a VPN can protect network traffic, but it cannot stop phishing, SIM-swap abuse, help-desk social engineering or stolen session tokens.
What happened?
The National Crime Agency says Thalha Jubair, 20, and Owen Flowers, 18, have each been sentenced to five years and six months in prison for the 2024 cyberattack on Transport for London. The NCA described the case as the largest cybercrime prosecution ever brought before UK courts.
According to the NCA, the attack took place between 31 August and 3 September 2024 and caused major disruption across TfL systems. The agency says TfL reported £29 million in losses and recovery costs, 148 systems became inoperable, and all 27,000 TfL employees had to attend an office for a password reset.
The Register reported further courtroom context and said the defendants were associated with the Scattered Spider cybercrime ecosystem, a group known for social engineering, data extortion, SIM-swap attacks and network intrusion.
Why this matters to ordinary users
A transport authority breach may sound like a corporate IT problem, but the effects land on real people: delayed refunds, disrupted booking systems, slower customer support, exposed account data and knock-on inconvenience when public services have to rebuild trust and systems.
It also shows why modern cybercrime is often less about movie-style hacking and more about identity. Attackers look for weak passwords, reused credentials, compromised email accounts, SIM-swap opportunities, help-desk mistakes, stolen tokens and gaps in multi-factor authentication.
What you can do now
Use unique passwords for transport, banking, email and shopping accounts, and store them in a password manager rather than reusing a memorable password everywhere. Turn on multi-factor authentication where it is offered, with an authenticator app or hardware key preferred over SMS for high-value accounts.
Be cautious with urgent messages about refunds, travel cards, account suspension or failed payments. Go directly to the official app or website instead of following links in texts or emails. If a service announces a breach, change the password on that service and anywhere else you reused it.
Where a VPN helps — and where it does not
A VPN can help if you are using public Wi-Fi at a station, airport, hotel or cafe because it encrypts traffic between your device and the VPN server and reduces what the local network can see. It can also reduce basic IP-location exposure and hotspot tracking.
A VPN does not stop phishing, SIM swaps, password reuse, malicious account recovery, stolen browser sessions or a company-side breach. If a criminal tricks you or a service into handing over access, the VPN tunnel is not the control that saves the account.
VPN Rocks view
The TfL case is a useful reality check for VPN buyers. A good VPN belongs in a wider privacy and security setup, but it is not a substitute for strong account hygiene. The safest practical stack is layered: password manager, MFA, software updates, phishing caution, breach response habits and a reputable VPN for untrusted networks.
Sources and further reading
VPN Rocks adds plain-English analysis and practical advice. Source links are included so readers can check the underlying guidance directly.