---
title: "Scattered Spider Guilty Pleas: What the TfL Hac… | Firevault"
url: https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery
description: "Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer."
lang: en-GB
---

News · Threat Analysis · 22 June 2026

# Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

Image: Mark Fermor (https://fire-vault.com/assets/mark-fermor-DWFWqeWL.jpg)

Mark Fermor CTO, CMO & Founder, Firevault

4 min read

Share

Share on LinkedIn: https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery
Share on X: https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery&text=Scattered%20Spider%20Guilty%20Pleas%3A%20What%20the%20TfL%20Hack%20Confirms%20About%20Offline%20Recovery%0A%0ATwo%20Scattered%20Spider%20members%20have%20admitted%20the%20%C2%A339m%20TfL%20hack.%20Mark%20Fermor%20on%20identity%20blast%20radius%20and%20why%20offline%20recovery%20is%20the%20deciding%20layer.
Share on Facebook: https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery

Image: Transport for London signage at a station entrance, illustrating the 2024 Scattered Spider cyber attack (https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg)

Transport for London signage at a station entrance, illustrating the 2024 Scattered Spider cyber attack

Why it matters

## What this means for organisations holding critical data

> _I read this in The Times this morning. Two members of the loose hacking crew known as Scattered Spider have admitted the August 2024 attack on Transport for London. The cost has now passed £39 million, and the case is a clean illustration of how a single identity compromise reaches every system that depends on it. Reporting by Ali Mitib, The Times, 22 June 2026._

> **Key takeaways**
>
> - Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty at Woolwich Crown Court to the Computer Misuse Act offences behind the TfL hack. Sentencing is set for 15 July.
> - The 31 August 2024 intrusion exposed names, home addresses, contact details, bank account numbers and Oyster sort codes for around 5,000 customers, and forced all 27,000 TfL staff to recertify their credentials in person.
> - The same crew is linked by police to the 2026 attacks on Marks and Spencer, Co-op and Harrods. Flowers also admitted breaches of SSM Health and Sutter Health in the United States.
> - When identity is the blast radius, online backups inherit the compromise. Offline, controlled-access copies are what decides recovery.

Two men accused of belonging to the cybercrime collective known as Scattered Spider have pleaded guilty to the 2024 attack that paralysed Transport for London, in a case The Times reports has now cost the operator more than £39 million.

Thalha Jubair, 20, of east London, and Owen Flowers, 18, of Walsall in the West Midlands, admitted conspiring to commit unauthorised acts under the Computer Misuse Act before the opening of their trial at Woolwich Crown Court. They will be sentenced on 15 July.

## What actually happened to TfL

The intrusion on 31 August 2024 forced TfL to suspend a range of services across the capital. According to The Times, personal information for about 5,000 customers was exposed, including names, home addresses, contact details, bank account numbers and the sort codes linked to Oyster travel cards.

Major transport services kept running, but the operational fallout was significant. Passengers could not access their Oyster accounts online. Third-party services such as Citymapper went dark. The Dial-a-Ride service for disabled passengers was briefly suspended. Every one of TfL'''s 27,000 staff had to attend head office to recertify credentials and reset passwords.

That last detail is the one that should hold the attention of any board reading this. The recovery cost was not paid in ransom. It was paid in identity rebuild.

## Why Scattered Spider keeps winning

Scattered Spider is the industry label for a loose group of English-speaking attackers who combine social engineering with off-the-shelf tooling to compromise large enterprises. Police have linked the same crew to this year'''s incidents at Marks and Spencer, Co-op and Harrods. Flowers also pleaded guilty to hacks against SSM Health Care Corporation and Sutter Health, two United States healthcare systems.

The pattern is consistent. The attackers do not break encryption. They convince a help desk, capture a session, and walk through the front door of identity. From there, they reach the systems an authenticated user can reach, including the backup platforms.

## The Firevault view

The TfL case is not a story about a clever exploit. It is a story about what stays reachable once a privileged session is compromised. Three points stand out from our position.

First, identity is the blast radius. The moment a domain account is taken, every system that trusts that account becomes part of the incident. That includes the backup console, the snapshot scheduler, the immutability flags and the API keys that protect them.

Second, online backups inherit the compromise. A copy that sits behind the same directory as the production system is not a recovery copy. It is a second target. The attacker does not need to break it, they only need the credential that already governs it.

Third, recovery time is decided before the attack, not during it. The organisations that recover fastest are the ones that hold a physically disconnected, controlled-access copy of the systems and data that matter most. Nothing reachable from a stolen session can be encrypted, exfiltrated or quietly deleted.

This is the design principle behind Firevault Offline Secure Storage (https://fire-vault.com/solutions/offline-secure-storage). The golden copy lives at Layer 1, behind a deliberate human authorisation step. The directory cannot reach it. The attacker cannot phish it. The help desk cannot release it by mistake.

For boards, the practical posture is simple. Assume the credential is already lost. Rehearse recovery from a copy the attacker cannot see. Read our briefing on recovery independence (https://fire-vault.com/learn/guides/recovery-independence) for the questions to put to your IT and security leadership this quarter.

— Mark Fermor, Director and Co-Founder, Firevault

## Source

Ali Mitib, Cybercriminals admit hack that paralysed TfL systems (https://www.thetimes.com/article/892e87f0-041f-4a21-b299-6ff574b2fdae?shareToken=d6d34610b88a2e816a43e08e8f5bb87e&ver=article), The Times, 22 June 2026.

About the author

### Mark Fermor

Mark Fermor on LinkedIn (https://www.linkedin.com/in/mfermor)

CTO, CMO & Founder

Founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

Get started: https://fire-vault.com/get-started
Talk to the team: https://fire-vault.com/demo

**Hardware**Your copy sits on dedicated encrypted hardware

**Disconnect**Offline by default, connected only when you say so

**Recovery**A known-clean copy to rebuild from, on your timetable

**Location**Held in a secure Firevault Bunker

Related Reading

## You may also find these useful

Threat Analysis

### Fake job interviews infected 30,000 devices, FBI-led advisory says

A joint FBI-led advisory says North Korean WaterPlum actors used fake technical interviews and coding tests to infect at least 30,000 devices in more than 100 countries.

25 Sept 2026 5 min
https://fire-vault.com/news/waterplum-contagious-interview-30000-devices-2026

Threat Analysis

### Blockchain dead drops surge 440% as North Korea and Iran hide malware on public ledgers

Chainalysis research shows malicious blockchain writes rising from 2.06 to 11.1 a day in under a year, with state-linked groups now behind most new activity. Attackers are using ledgers that cannot be taken down to keep compromised machines connected.

24 Sept 2026 3 min
https://fire-vault.com/news/blockchain-dead-drops-malware-surge-2026

Threat Analysis

### UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

20 Jun 2026 5 min
https://fire-vault.com/news/ncsc-uk-critical-infrastructure-incidents-double

Threat Analysis

### 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

19 Jun 2026 4 min
https://fire-vault.com/news/24-billion-credentials-infostealer-leak

Threat Analysis

### FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

18 Jun 2026 4 min
https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed

Breach Analysis

### Dyfed-Powys Police confirms cyber attack as staff information may have been compromised

Dyfed-Powys Police has confirmed that a cyber attack identified on 14 September disrupted non-emergency systems and may have exposed staff information. The force says it has found no evidence that public data was accessed.

25 Sept 2026 3 min
https://fire-vault.com/news/dyfed-powys-police-cyber-attack-2026

## Suggested Reading

- What is Offline Secure Storage The foundation of physical disconnection: https://fire-vault.com/how-it-works/offline-secure-storage
- Why Offline Secure Storage The case for physical control: https://fire-vault.com/why-oss
- Ransomware Defence Hold gold copies offline: https://fire-vault.com/oss-for-ransomware-recovery
- Control Physical path control for IT and OT: https://fire-vault.com/solutions/control
- Knowledge Vault All articles, guides and whitepapers: https://fire-vault.com/learn/knowledge
- Book a Demo See Firevault in action: https://fire-vault.com/demo

Back to Knowledge Vault: https://fire-vault.com/learn/knowledge

## Structured data

```json
[
  {
    "@context": "https://schema.org",
    "@type": "Organization",
    "@id": "https://fire-vault.com/#organization",
    "name": "Firevault",
    "legalName": "Firevault Limited",
    "url": "https://fire-vault.com",
    "logo": {
      "@type": "ImageObject",
      "url": "https://fire-vault.com/logo.png",
      "width": 200,
      "height": 60
    },
    "foundingDate": "2025-03",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "address": {
      "@type": "PostalAddress",
      "addressCountry": "GB",
      "addressLocality": "United Kingdom"
    },
    "contactPoint": [
      {
        "@type": "ContactPoint",
        "contactType": "customer service",
        "email": "hello@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      },
      {
        "@type": "ContactPoint",
        "contactType": "sales",
        "email": "sales@fire-vault.com",
        "availableLanguage": "English",
        "areaServed": [
          "GB",
          "EU",
          "US",
          "AE"
        ]
      }
    ],
    "founder": [
      {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Founder, CTO and CMO"
      },
      {
        "@type": "Person",
        "name": "David Bailey",
        "jobTitle": "Founder and CEO"
      }
    ],
    "areaServed": [
      "United Kingdom",
      "Europe",
      "United States",
      "Middle East"
    ],
    "sameAs": [
      "https://www.linkedin.com/company/firevault",
      "https://x.com/firevaultuk"
    ],
    "slogan": "Disconnect to Protect",
    "brand": [
      {
        "@type": "Brand",
        "name": "Offline Secure Storage"
      },
      {
        "@type": "Brand",
        "name": "Control by Firevault"
      },
      {
        "@type": "Brand",
        "name": "Firebreak"
      }
    ],
    "knowsAbout": [
      "Offline Secure Storage",
      "Physically disconnected data storage",
      "Physical Air Gap Data Protection",
      "Ransomware Protection",
      "Ransomware recovery",
      "3-2-1-1-0 backup rule",
      "AI kill switch",
      "Operational technology security",
      "Critical national infrastructure resilience",
      "Data Sovereignty",
      "GDPR Compliance",
      "NIS2 Compliance",
      "DORA Compliance",
      "NCSC Cyber Assessment Framework"
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "WebSite",
    "@id": "https://fire-vault.com/#website",
    "name": "Firevault",
    "alternateName": [
      "Firevault",
      "Firevault UK",
      "Firevault Limited"
    ],
    "url": "https://fire-vault.com",
    "publisher": {
      "@id": "https://fire-vault.com/#organization"
    },
    "inLanguage": "en-GB",
    "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
    "potentialAction": {
      "@type": "SearchAction",
      "target": {
        "@type": "EntryPoint",
        "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
      },
      "query-input": "required name=search_term_string"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "WebPage",
    "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery#webpage",
    "url": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery",
    "name": "Scattered Spider Guilty Pleas: What the TfL Hac…",
    "description": "Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.",
    "isPartOf": {
      "@id": "https://fire-vault.com/#website"
    },
    "about": {
      "@id": "https://fire-vault.com/#organization"
    },
    "primaryImageOfPage": {
      "@type": "ImageObject",
      "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg"
    },
    "inLanguage": "en-GB",
    "breadcrumb": {
      "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery#breadcrumb"
    }
  },
  {
    "@context": "https://schema.org",
    "@type": "BreadcrumbList",
    "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery#breadcrumb",
    "itemListElement": [
      {
        "@type": "ListItem",
        "position": 1,
        "name": "Home",
        "item": "https://fire-vault.com"
      },
      {
        "@type": "ListItem",
        "position": 2,
        "name": "Learn",
        "item": "https://fire-vault.com/learn"
      },
      {
        "@type": "ListItem",
        "position": 3,
        "name": "Knowledge Vault",
        "item": "https://fire-vault.com/learn/knowledge"
      },
      {
        "@type": "ListItem",
        "position": 4,
        "name": "Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery",
        "item": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery"
      }
    ]
  },
  {
    "@context": "https://schema.org",
    "@type": "NewsArticle",
    "headline": "Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery",
    "description": "Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.",
    "url": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery",
    "image": [
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
        "width": 1200,
        "height": 1200
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
        "width": 1200,
        "height": 900
      },
      {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
        "width": 1200,
        "height": 675
      }
    ],
    "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
    "author": {
      "@type": "Person",
      "name": "Mark Fermor",
      "jobTitle": "CTO, CMO & Founder",
      "worksFor": {
        "@id": "https://fire-vault.com/#organization"
      },
      "url": "https://fire-vault.com/why-oss/about"
    },
    "publisher": {
      "@type": "NewsMediaOrganization",
      "name": "Firevault",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 600,
        "height": 60
      }
    },
    "datePublished": "2026-06-22T15:26:35.26658+00:00",
    "dateModified": "2026-08-28T08:03:22.256672+00:00",
    "mainEntityOfPage": {
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery"
    },
    "inLanguage": "en-GB",
    "articleSection": "Threat Analysis",
    "wordCount": 792,
    "keywords": "Scattered, Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
    "articleBody": "> _I read this in The Times this morning. Two members of the loose hacking crew known as Scattered Spider have admitted the August 2024 attack on Transport for London. The cost has now passed £39 million, and the case is a clean illustration of how a single identity compromise reaches every system that depends on it. Reporting by Ali Mitib, The Times, 22 June 2026._ > **Key takeaways** > > - Thalh",
    "dateline": "United Kingdom",
    "speakable": {
      "@type": "SpeakableSpecification",
      "cssSelector": [
        "h1",
        ".article-summary",
        "h2"
      ]
    },
    "isAccessibleForFree": true,
    "copyrightHolder": {
      "@id": "https://fire-vault.com/#organization"
    },
    "copyrightYear": 2026
  },
  {
    "@context": "https://schema.org",
    "@type": "FAQPage",
    "mainEntity": [
      {
        "@type": "Question",
        "name": "Who are Scattered Spider?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Scattered Spider is the cybersecurity industry name for a loose collection of mostly English-speaking attackers who use social engineering, help desk impersonation and session theft to breach large enterprises. UK police have linked the same crew to the 2024 TfL hack and to the 2026 attacks on Marks and Spencer, Co-op and Harrods."
        }
      },
      {
        "@type": "Question",
        "name": "What customer data was exposed in the 2024 TfL hack?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "According to The Times, about 5,000 TfL customers had personal information exposed, including names, home addresses, contact details, bank account numbers and the sort codes linked to Oyster travel cards. All 27,000 TfL staff were required to recertify their credentials in person at head office."
        }
      },
      {
        "@type": "Question",
        "name": "How does offline secure storage change the outcome of an attack like this?",
        "acceptedAnswer": {
          "@type": "Answer",
          "text": "Offline secure storage holds a physically disconnected, controlled-access copy of critical systems and data at Layer 1. Because the directory cannot reach it and no stolen session can authenticate to it, the copy cannot be encrypted, exfiltrated or deleted by an attacker who has compromised production identity. That is what allows recovery without paying a ransom or rebuilding from scratch."
        }
      }
    ]
  }
]
```