HomeData BreachU.Ok. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL...

U.Ok. Arrests Two Teen Scattered Spider Hackers Linked to August 2024 TfL Cyber Attack

Legislation enforcement authorities within the U.Ok. have arrested two teen members of the Scattered Spider hacking group in reference to their alleged participation in an August 2024 cyber assault concentrating on Transport for London (TfL), town’s public transportation company.

Thalha Jubair (aka EarthtoStar, Brad, Austin, and @autistic), 19, from East London and Owen Flowers, 18, from Walsall, West Midlands have been arrested at their residence addresses on Tuesday, the Nationwide Crime Company (NCA) stated. They’re 19 and 18, respectively.

It is price noting that Flowers was initially arrested for his alleged involvement within the TfL assault in September 2024, however was subsequently launched on bail. The company stated it discovered proof of Flowers concentrating on U.S. healthcare firms, and that he has additionally been charged with conspiring with others to infiltrate and harm the networks of SSM Well being Care Company and Sutter Well being.

DFIR Retainer Services

Jubair has additionally been charged underneath the Regulation of Investigatory Powers Act (RIPA) 2000 for failing to give up PINs and passwords for gadgets seized by legislation enforcement from him on March 19, 2025.

See also  France fines Free Cellular €42 million over 2024 data breach incident

“This assault brought about important disruption and hundreds of thousands in losses to TfL, a part of the UK’s essential nationwide infrastructure,” Deputy Director Paul Foster, head of the NCA’s Nationwide Cyber Crime Unit, stated. “Earlier this yr, the NCA warned of a rise within the risk from cyber criminals based mostly within the U.Ok. and different English-speaking nations, of which Scattered Spider is a transparent instance.”

In tandem, the U.S. Division of Justice (DoJ) unsealed a criticism charging Jubair with conspiracies to commit pc fraud, wire fraud, and cash laundering in relation to no less than 120 pc community intrusions and extorting 47 U.S. entities from Could 2022 to September 2025.

These assaults concerned using social engineering methods to achieve unauthorized entry to the goal networks, after which leveraging that entry to steal and encrypt data, and demand ransom from victims in return for regaining management and stopping the leak of the exfiltrated information.

See also  Ease the Burden with AI-Pushed Menace Intelligence Reporting

In response to the criticism, victims paid no less than $115,000,000 in ransom funds. The incidents, the DoJ added, brought about widespread disruption to U.S. companies and organizations, together with essential infrastructure and the federal court docket system, in October 2024 and January 2025.

In July 2024, the DoJ stated legislation enforcement seized cryptocurrency wallets on a server allegedly managed by Jubair and confiscated digital property price about $36 million on the time. Jubair can be stated to have transferred a portion of the proceeds that originated from one of many victims, price about $8.4 million on the time, to a different pockets.

CIS Build Kits

Jubair has been charged with pc fraud conspiracy, two counts of pc fraud, wire fraud conspiracy, two counts of wire fraud, and cash laundering conspiracy. If convicted, he faces a most penalty of 95 years in jail.

“Jubair went to nice and complicated lengths to maintain himself nameless whereas he and his legal associates continued to assault these victims and extort tens of hundreds of thousands of {dollars} in ransom funds,” stated Alina Habba, Performing U.S. Legal professional and Particular Legal professional for the District of New Jersey.

See also  Crypto alternate Gemini discloses third-party data breach
- Advertisment -spot_img
RELATED ARTICLES

LEAVE A REPLY

Please enter your comment!
Please enter your name here

- Advertisment -

Most Popular