Home ยท Wiki ยท Entities & Threat Actors
type: entity ยท created: 2026-07-11 ยท updated: 2026-07-18 ยท tags: [ransomware-group, cybercrime-group, incident, le-action] ยท confidence: high ยท affected_sectors: [technology, healthcare, government, transport] ยท au_impact: false

Scattered Spider

Scattered Spider is a prolific cybercrime group known for ransomware attacks and network intrusions targeting a wide range of sectors across the US and UK. The group has been linked to at least $115 million in ransom payments across 47 US entities, with 120 documented network intrusions.

Members

  • Owen Flowers (18) โ€” pleaded guilty in the UK in June 2026; sentenced to 5.5 years at Woolwich Crown Court for the Transport for London ransomware attack (August 2024) and hacking US healthcare providers Ssm Health Care and Sutter Health.
  • Thalha Jubair (20) โ€” pleaded guilty alongside Flowers; also wanted by US authorities under a New Jersey indictment; also sentenced to 5.5 years.

Both pleaded guilty on the first day of their trial in the UK. (raw/digests/Cyber-Digest-2026-07-07)

Known Attacks

Victim Sector Date Notes
Transport for London (TfL) Transport August 2024 Ransomware attack; disrupted London transport services; 148 systems inoperable; ยฃ29M cost; all 27,000 employees forced to reset passwords in person
SSM Health Care Corporation Healthcare September 2024 Admitted by Owen Flowers
Sutter Health Healthcare September 2024 Admitted by Owen Flowers
47 US entities (various) Cross-sector Ongoing At least $115M in ransom payments collected

Law Enforcement Action

  • June 2026: Flowers and Jubair pleaded guilty in UK court
  • July 16, 2026: Both sentenced to 5.5 years at Woolwich Crown Court for the TfL attack
  • Believed to be the first hackers successfully prosecuted under Section 3ZA of the UK Computer Misuse Act (raw/digests/Cyber-Digest-2026-07-18)
  • US indictment: New Jersey charges pending against Thalha Jubair
  • The group's trial collapsed on opening day with both defendants entering guilty pleas (raw/digests/Cyber-Digest-2026-07-09)

TTPs

  • Network intrusions via initial access brokers
  • Ransomware deployment against enterprise targets
  • Multi-sector targeting including healthcare, which resulted in patient care disruptions

Related Pages