Two Britons plead guilty to £39m 2024 cyber-attack on Transport for London

79d ago · UK · primary source: theguardian.com

Two British men have pleaded guilty to a 2024 cyber-attack on Transport for London that cost the authority £39m and compromised the data of 10 million people, the National Crime Agency said. Thalha Jubair, 20, and Owen Flowers, 18, entered their pleas at Woolwich crown court on Monday, admitting conspiracy to commit unauthorised acts against TfL computer systems under the Computer Misuse Act [1]. The attack ran from 29 August to 3 September 2024, disabling live tube arrival information on the TfL Go app and website, halting Oyster and contactless payment processing, and blocking Oyster card registration [1]. TfL emailed more than 7 million customers in September 2024 to warn that some customer data may have been taken [1]. The pair were members of Scattered Spider, an online criminal collective identified by cybersecurity analysts [1]. Paul Foster, head of the NCA's national cyber crime unit, said the case "demonstrates the increasing threat from cybercriminals based in the UK and other English-speaking countries, epitomised by Scattered Spider" [1]. Investigators found laptops, hard drives and USB sticks at Flowers' home in Walsall, West Midlands. One laptop contained a screenshot showing network connectivity to TfL infrastructure and videos recorded by Flowers of Jubair accessing TfL systems during the attack [1]. The two communicated via Telegram and a remote collaboration tool [1]. The attack accessed TfL's refunds system, leaving some customers out of pocket for longer than usual, and shut the application system for Oyster photocards for children and young people [1]. TfL handles up to 5m passenger journeys a day on the underground alone [1]. Flowers also admitted hacking two US healthcare companies. He pleaded guilty to conspiring to commit unauthorised acts against SSM Health Care Corporation and attempting to commit unauthorised acts against Sutter Health on or about 6 September 2024 [1]. A hospital network, such as those targeted, can include multiple hospitals across one or more regions or states, often operating under a single headquarters [5]. Jubair faces separate accusations from the US Department of Justice of involvement in attacks on 47 US organisations that garnered more than $100m in ransom payments [1]. A previous hearing was told that $200m in cryptocurrency had moved through accounts belonging to him, and that $10m was moved from his crypto wallets after he was released from custody in March last year [1]. Flowers held $7.1m including crypto in accounts he controlled despite having no source of income [1]. Both defendants have been diagnosed with autism, and Jubair has depression and a severe mood disorder [1]. Jubair has been convicted of 22 offences, including 13 counts of fraud, two of unauthorised access to a computer, one count of obtaining access to a computer, and one count of blackmail [1]. He was subject to a youth rehabilitation order at the time of the TfL offences, stemming from his hacking of BT, EE and Nvidia, for which he was convicted at 17 [1]. Mr Justice Turner remanded both men in custody ahead of a two-day sentencing hearing on 15 July [1]. Flowers denied two further hacking charges, which were ordered to lie on file [1].

controversy

Background sources we checked (5)
  • en.wikipedia.org ↗ Events from the year 2024 in the United Kingdom. This year is noted for a landslide general election victory for the Labour Party under Keir Starmer.…
  • en.wikipedia.org ↗ Events of the year 2023 in the United Kingdom. This is the year of the coronation of King Charles III.…
  • en.wikipedia.org ↗ This is a list of hospitals in the United States that are verified as trauma centers by the American College of Surgeons.…
  • en.wikipedia.org ↗ A hospital network is a public, non-profit or for-profit company or organization that provides two or more hospitals and other broad healthcare facilities and services. A hospital network may include hospitals in one or more regions within one or more states within one or more c…
  • en.wikipedia.org ↗ The SMART Health Card framework is an open source immunity passport program designed to store and share medical information in paper or digital form. It was initially launched as a vaccine passport during the COVID-19 pandemic, but is envisioned for use for other infectious disea…

Sources

Spot something wrong? Report an issue