Two Scattered Spider Members Plead Guilty as London Trial Opens
Thalha Jubair and Owen Flowers admitted roles in the TfL intrusion and a SIM-swap and SMS-phishing operation that turned harvested SSO credentials into nine-figure ransom payouts.

Key points
- Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty on what was scheduled to be day one of a six-week London trial.
- Flowers admitted separately to conspiring to intrude on U.S. Healthcare providers SSM Health and Sutter Health in September 2024.
- A New Jersey indictment ties Jubair to 120 intrusions across 47 U.S. Entities, with victims paying at least $115 million in ransoms.
- The crew sold SIM redirection by phishing carrier staff, then intercepted one-time codes to bypass SMS-based authentication.
- Sentencing is set for 15 July 2026 in London.
What did they actually plead guilty to?
Both defendants admitted conspiring to commit unauthorised acts against Transport for London's systems in August 2024, and to causing risk of serious damage to human welfare. Flowers also admitted joining a conspiracy to break into U.S. Healthcare providers SSM Health and Sutter Health in September 2024. Jubair faces a parallel U.S. Indictment unsealed in September 2025 alleging computer fraud, wire fraud and money laundering across 120 intrusions into 47 entities between May 2022 and September 2025, with at least $115 million paid out in ransoms.
How did the operation actually work?
Prosecutors say Jubair co-ran a Telegram channel called Star Chat, the hub of a crew that phished carrier employees by voice and SMS to get inside wireless-provider tooling. Access to that tooling let them sell SIM redirection: port a target's number, take over the incoming calls and texts, harvest the one-time codes that SMS-based multi-factor authentication relies on. SS7-era authenticators meeting their natural predator.
This is the part where I'd normally ask whether MFA would have helped. It was the MFA. SMS one-time passwords are a knowledge-of-channel factor, not a genuine possession factor, the moment a carrier insider can re-point the SIM. Phishing-resistant authenticators bound to the device, WebAuthn/FIDO2 passkeys being the practical standard, are the only credible answer for workforce identity providers at this threat tier. We looked at a related failure mode in our coverage of prompt bombing on 28 May: the common thread is that attackers have stopped needing your password when the second factor is easier to steal.
The summer 2022 SMS phishing campaign is the other instructive piece. That weeks-long run scraped single sign-on credentials from employees at more than 130 organisations, including LastPass, DoorDash, Mailchimp and Plex. The lure was a fake Okta-style login page; a valid OIDC session (a token proving identity to connected apps) against the real identity provider was the result, which is exactly why the blast radius was so wide. One phished SSO assertion fans out to every SAML and OAuth-connected app the victim can reach.
U.S. Prosecutors also link Jubair to the "Everlynn" persona, which sold fraudulent emergency data requests using compromised police email accounts to extract subscriber data from major platforms. Authentication abuse driving authorisation abuse, with social engineering against legal-process teams layered on top.
Should you worry about the defendants still in the pipeline?
Co-defendant Tyler Buchanan pleaded guilty in April 2026 and faces sentencing on 2 October. We covered his path to that plea in "The Boy Who Topped the Leaderboard". Noah Urban received a ten-year federal prison sentence and $13 million in restitution in August 2025. Ahmed Elbadawy, Evans Osiebo and Joel Evans still face U.S. Charges.
Flowers and Jubair are due back in London on 15 July 2026 for sentencing.
The wire that runs through every Scattered Spider prosecution is the same: commodity phishing infrastructure, insider-level carrier access and a workforce IdP that trusted SMS as a meaningful second factor. The credentials were never the hard part. The hard part, apparently, is convincing organisations to retire the authenticator the attacker already owns.



