type: entity ยท created: 2026-07-11 ยท updated: 2026-07-18 ยท tags: [ransomware-group, cybercrime-group, incident, le-action] ยท confidence: high ยท affected_sectors: [technology, healthcare, government, transport] ยท au_impact: false
Scattered Spider
Scattered Spider is a prolific cybercrime group known for ransomware attacks and network intrusions targeting a wide range of sectors across the US and UK. The group has been linked to at least $115 million in ransom payments across 47 US entities, with 120 documented network intrusions.
Members
- Owen Flowers (18) โ pleaded guilty in the UK in June 2026; sentenced to 5.5 years at Woolwich Crown Court for the Transport for London ransomware attack (August 2024) and hacking US healthcare providers Ssm Health Care and Sutter Health.
- Thalha Jubair (20) โ pleaded guilty alongside Flowers; also wanted by US authorities under a New Jersey indictment; also sentenced to 5.5 years.
Both pleaded guilty on the first day of their trial in the UK. (raw/digests/Cyber-Digest-2026-07-07)
Known Attacks
| Victim | Sector | Date | Notes |
|---|---|---|---|
| Transport for London (TfL) | Transport | August 2024 | Ransomware attack; disrupted London transport services; 148 systems inoperable; ยฃ29M cost; all 27,000 employees forced to reset passwords in person |
| SSM Health Care Corporation | Healthcare | September 2024 | Admitted by Owen Flowers |
| Sutter Health | Healthcare | September 2024 | Admitted by Owen Flowers |
| 47 US entities (various) | Cross-sector | Ongoing | At least $115M in ransom payments collected |
Law Enforcement Action
- June 2026: Flowers and Jubair pleaded guilty in UK court
- July 16, 2026: Both sentenced to 5.5 years at Woolwich Crown Court for the TfL attack
- Believed to be the first hackers successfully prosecuted under Section 3ZA of the UK Computer Misuse Act (raw/digests/Cyber-Digest-2026-07-18)
- US indictment: New Jersey charges pending against Thalha Jubair
- The group's trial collapsed on opening day with both defendants entering guilty pleas (raw/digests/Cyber-Digest-2026-07-09)
TTPs
- Network intrusions via initial access brokers
- Ransomware deployment against enterprise targets
- Multi-sector targeting including healthcare, which resulted in patient care disruptions
Related Pages
- Netnut Takedown โ Another significant FBI/LE action in the same period
- Goddamn Ransomware โ Current ransomware variants
- Blackcat Alphv โ Related ransomware group with recent prosecutions