Two members of the Scattered Spider cybercrime group have been sentenced to prison in the UK following the 2024 cyber attack on Transport for London (TfL), in a case that also highlights the group’s role in the ransomware attack on MGM Resorts that disrupted casino operations across Las Vegas.

At Woolwich Crown Court, 20-year-old Thalha Jubair was sentenced to five years and six months’ imprisonment after admitting offences under the Computer Misuse Act. Fellow Scattered Spider member Owen Flowers, 18, was also sentenced after pleading guilty to related offences.

Jubair is separately facing charges in the United States over his alleged involvement in the September 2023 ransomware attack on MGM Resorts, which brought major disruption to the operator’s casino and hotel properties across Las Vegas and the wider US.

The MGM attack caused widespread operational failures, with slot machines, ATMs, payment systems and digital hotel room keys all affected as the company worked to contain the breach. US authorities allege that members of Scattered Spider deployed ransomware that encrypted company systems and demanded payment to restore access. According to the US Department of Justice, victims of the group’s wider ransomware campaign paid at least $115m in ransom demands.

The UK prosecution focused on the September 2024 attack against TfL, which disrupted Oyster card services, live travel information and systems supporting the Dial-a-Ride service. Prosecutors said the incident left more than 140 TfL systems inoperable and resulted in losses estimated at £29m, while personal data relating to millions of Oyster card users was compromised.

Sentencing the pair, Mr Justice Turner said their actions were driven by “selfish bravado” and showed little regard for the impact on victims.

The UK’s National Crime Agency described the case as the largest criminal prosecution of its kind. Paul Foster, head of the NCA’s National Cyber Crime Unit, said Scattered Spider had represented the UK’s most significant organised cyber threat over the past two years, adding that law enforcement action had substantially disrupted the group’s activities.

Investigators describe Scattered Spider as a loose network of predominantly English-speaking young hackers who coordinate attacks online. The group has been linked to a series of high-profile breaches targeting major corporations in the gaming, retail, telecommunications and financial sectors.

Jubair had previously been convicted in connection with attacks carried out by the Lapsus$ hacking group against companies including Nvidia and BT before reoffending. Authorities also revealed that Flowers had previously received warnings and cybercrime intervention support but failed to engage.

While UK authorities said cyber attacks attributed to Scattered Spider have fallen sharply since the arrests, investigators cautioned that remaining members continue to operate and could re-emerge under different identities.