TfL cyberattack: Two teenagers jailed for five-and-a-half years after £29m disruption
Two young men were sentenced to 5½ years after pleading guilty to the TfL cyberattack that cost the authority £29 million and halted services.
Sentencing after TfL cyberattack
A British court on Thursday handed five-and-a-half-year prison terms to Talha Jabeer, 20, and Owen Flowers, 18, for their roles in the TfL cyberattack of 2024.
The pair admitted last month to breaching Transport for London systems in an intrusion that prosecutors say inflicted £29 million in losses and widespread operational disruption.
Court finds motive of bravado and self-interest
Judge Mark Turner told the court he was satisfied the men’s primary motive was to boast and show off, describing their conduct as driven by “vanity and selfishness.”
Both defendants received identical sentences after prosecutors argued the severity of the intrusion and the extensive planning behind the attack warranted custodial terms.
How the August–September intrusion unfolded
Prosecutors say the attack took place between August 31 and September 3, 2024, with the defendants working up to 16 hours a day to penetrate TfL systems.
Investigators allege Jabeer operated from his parents’ flat in east London while Flowers worked from his grandmother’s home in the English Midlands as they moved through networks and accessed critical infrastructure.
Key evidence and livestreamed activity
The prosecution presented digital evidence including a recording found on Flowers’s laptop and material the court heard showed Jabeer broadcasting parts of the operation live online.
The recording and device logs were described as pivotal, providing a clear chronology of their actions and linking the two defendants to the break-in.
Operational impact and TfL response
Authorities said the attack forced TfL to isolate and disconnect key computer systems to prevent further damage, a move that halted certain services and operations.
TfL then spent approximately six months repairing systems and restoring normal operations, with investigators and cyber teams working to recover data and harden defenses against follow-up intrusions.
Broader hacking activity and ongoing concerns
Flowers also admitted to conspiring with others to target two US health charities shortly after the TfL intrusion, according to the prosecution.
Evidence recovered from devices indicated continued attempts to access online domains connected to the Crown Prosecution Service and the prison where one defendant was later held, suggesting persistent targeting even after initial arrests.
The court was told investigators attributed the assault in part to the hacking group known as Scattered Spider, though the two teenagers were the individuals charged and convicted.
Prosecutors additionally highlighted the risk posed by such intrusions to public services, warning that a more extensive breach could have effectively paralysed the transport authority.
Security experts say the case underlines the growing threat posed by relatively young and technically capable attackers who can cause disproportionate damage.
The sentencing is likely to prompt a renewed focus on cyber hygiene, third-party vulnerability assessments, and rapid-response protocols across transport and public-sector organisations.
TfL said it continues to invest in cyber resilience and to work with law enforcement to deter and detect future attacks, while officials urged organisations to review access controls and incident readiness.
Police and cybercrime units indicated enquiries remain ongoing, and they encouraged members of the public and private sectors to report suspicious online activity that could signal coordinated attacks.
The convictions mark a high-profile result in the prosecution of cyber intrusions against critical infrastructure, and the case will be cited in future policy and security discussions.
Authorities say the sentences reflect both the tangible financial harm and the broader risk to public safety posed by attacks on transport networks.