Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026

Badges, Bytes and Blackmail

February 7, 2026
Facebook X (Twitter) Instagram
Saturday, February 7
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Pair of Suspected Scattered Spider Hackers Charged by UK, US Authoriti
News

Pair of Suspected Scattered Spider Hackers Charged by UK, US Authoriti

Team-CWDBy Team-CWDSeptember 18, 2025No Comments5 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


US and UK authorities have charged two suspected members of the infamous Scattered Spider cybercrime group with offenses connected to multiple high-profile cyber-attacks.

The pair have been linked to attacks on US courts, a US critical infrastructure firm and the UK’s Transport for London (TfL).

The two UK-based individuals, Thalha Jubair, 19, from East London, and Owen Flowers, 18 from Walsall, were arrested at their home addresses on Tuesday, September 16.

The District of New Jersey unsealed charges against Jubair on September 18, with conspiracies to commit computer fraud, wire fraud and money laundering.

According to the charges, Jubair, also known as “EarthtoStar,”  “Brad,” “Austin,” and “@autistic,” conspired with others to use social engineering techniques to gain unauthorized access into the computer networks of victim companies.

Jubair is accused of participation in at least 120 computer network intrusions and extortion involving 47 US entities. It is believed that victims paid at least $115m in ransom payments to Jubair and his associates.

Portions of the ransom payments from at least five victims were sent to wallets on a server controlled by Jubair.

In July 2024, Jubair was observed transferring a portion of cryptocurrency that originated from one of the victims, worth approximately $8.4m at the time, to another wallet, while law enforcement was in the process of seizing the server.

Jubair and associates are accused of involvement in attacks from as early as May 2022 to as recently as September 2025.

FBI Special Agent in charge Stefanie Roddy, said: “The arrest of Thalha Jubair underscores an undeniable truth: no matter how elusive or destructive these cyber-criminal syndicates are, we will continue to pursue those who allegedly extort our businesses and ensure they are held accountable.”

Teenagers Charged with TfL Hack Involvement

The two teenagers have also been charged by UK authorities with offenses connected to the August 2024 cyber-attack on Transport for London (TfL).

They have been charged with conspiring to commit unauthorized acts against TfL under the Computer Misuse Act and appeared in Westminster Magistrates Court on September 18.

Flowers was initially arrested on suspicion of involvement in the TfL hack on September 6, 2024, while aged 17, at which point National Crime Agency (NCA) investigators identified further potential evidence of offences against US healthcare companies.

As a result, he was also charged on September 18, 2025 with conspiring with others to infiltrate and damage the networks of SSM Health Care Corporation and attempting to do the same to Sutter Health’s networks, both based in the US.

Jubair has been additionally charged under the UK’s Regulation of Investigatory Powers Act (RIPA) for failing to disclose the pin or passwords for devices seized from him.

The TfL hack impacted sensitive personal data of around 5000 customers. This information included Oyster refund data, encompassing bank account numbers and sort codes.

It reportedly cost the transport operator around £30m ($40.6m), including £5m ($6.7m) on external support to recover from the incident.

New Blow to Scattered Spider

The charges against Flowers and Jubair follow the arrests of four other suspected members of Scattered Spider by UK authorities in July 2025.

The four individuals, three of whom were teenagers at the time of the arrest, are suspected of involvement in the April 2025 the attacks on Marks & Spencer, the Co-op and Harrods.

Deputy Director Paul Foster, head of the NCA’s National Cyber Crime Unit, described the charges against Jubair and Flowers as a “key step” in a “lengthy and complex investigation.”

“This attack caused significant disruption and millions in losses to TfL, part of the UK’s critical national infrastructure,” he said, “Earlier this year, the NCA warned of an increase in the threat from cybercriminals based in the UK and other English-speaking countries, of which Scattered Spider is a clear example.”

Commenting on the charges, Jake Moore, global cybersecurity advisor at ESET and former UK police officer, highlighted the growing success of law enforcement in identifying and collecting evidence to prosecute cybercriminal actors.

However, he warned that there may still be significant challenges in this process.

“Collecting enough solid evidence to produce in court and prosecute is the most difficult aspect in any cybercrime investigation so it will be vital that these agencies work thoroughly towards locating outright proof of their involvement,” he noted.

“It is highly likely that these members of the gang will have reduced their evidence and communication trails down to a bare minimum, if at all, which will cause frustrations in the investigation,” Moore added.

Earlier in September, it was reported that Scattered Spider, along with 14 other ransomware groups, had announced their “retirement.” However, these announcements have been met with skepticism by security experts.

The arrests and charges against Jubair and Flowers followed a collaborative investigation between law enforcement agencies in the UK, the US, the Netherlands, Romania, Canada and Australia.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleNew York Blood Center Alerts 194,000 People to Data Breach
Next Article Adobe Commerce Flaw CVE-2025-54236 Lets Hackers Take Over Customer Accounts
Team-CWD
  • Website

Related Posts

News

Researchers Uncover Chrome Extensions Abusing Affiliate Links and Stealing ChatGPT Access

February 7, 2026
News

China-Linked UAT-8099 Targets IIS Servers in Asia with BadIIS SEO Malware

February 7, 2026
News

Badges, Bytes and Blackmail

February 7, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

Don’t let “back to school” become “back to bullying”

September 11, 2025

Why LinkedIn is a hunting ground for threat actors – and how to protect yourself

January 16, 2026

What’s at stake if your employees post too much online

December 1, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.