Two Scattered Spider Members Plead Guilty as London Trial Opens
Thalha Jubair and Owen Flowers admitted roles in the TfL intrusion and a sprawling SIM-swap and SMS-phishing operation that turned harvested SSO credentials into nine-figure ransom payouts.

Two members of Scattered Spider pleaded guilty in a London court this week on what was supposed to be day one of a six-week trial. The pleas close one chapter of a years-long identity-abuse spree that ran on stolen SSO credentials, SIM swaps, and intercepted MFA codes.
Thalha Jubair, 20, of East London and Owen Flowers, 18, of Walsall admitted conspiring to commit unauthorized acts against Transport for London's systems in August 2024, and to causing a risk of serious damage to human welfare. Flowers separately admitted conspiring to intrude on U.S. healthcare providers SSM Health and Sutter Health in September 2024.
Jubair is also wanted in the United States. A New Jersey indictment unsealed in September 2025 ties him to 120 network intrusions across 47 U.S. entities between May 2022 and September 2025, with victims paying at least $115 million in ransoms.
The operational pattern is, by now, dismally familiar.
Prosecutors say Jubair co-ran a Telegram channel called Star Chat that ran voice- and SMS-based phishing against carrier employees in the U.S. and U.K. Once inside the carriers' internal tooling, the crew sold SIM redirection on demand — port a target's number, intercept the calls and texts, and harvest the one-time codes that prop up SMS-based MFA. SS7-era authenticators meeting their natural predator.
This is the part where I'd normally ask whether MFA would have helped. It was the MFA. That's the point. SMS OTP is a knowledge-of-channel factor, not a possession factor, the moment a carrier insider can re-point the SIM. Phishing-resistant authenticators bound to the device — WebAuthn/FIDO2 per RFC 8809 and the broader passkey stack — are the only credible answer for workforce IdPs at this threat tier.
The summer 2022 SMS phishing campaign tied to Jubair is the other instructive piece. That weeks-long run scraped single sign-on credentials from employees at more than 130 organizations, including LastPass, DoorDash, Mailchimp, Plex, and Signal. The lure was a fake Okta-style login page. The payload was a valid OIDC session against the real IdP, which is exactly why downstream blast radius was so wide: one phished SSO assertion fans out to every SAML and OAuth-connected app the victim can reach.
U.S. prosecutors also link Jubair to the "Everlynn" persona, which sold fraudulent emergency data requests using compromised police email accounts to coerce subscriber data out of major platforms. Authn abuse to drive authz abuse, with a side of social engineering against legal-process teams.
Co-defendant Tyler Buchanan pleaded guilty in April and is scheduled for sentencing October 2. Noah Urban drew 10 years and $13 million in restitution in August 2025. Three other alleged members — Ahmed Elbadawy, Evans Osiebo, and Joel Evans — still face U.S. charges.
Flowers and Jubair are due back in London for sentencing on July 15, 2026.



