{"id":7045,"date":"2025-09-19T10:03:27","date_gmt":"2025-09-19T10:03:27","guid":{"rendered":"https:\/\/serisec.com\/index.php\/2025\/09\/19\/uk-arrested-2-scattered-spider-hackers-linked-to-london-transport-system-breach\/"},"modified":"2025-09-19T10:03:27","modified_gmt":"2025-09-19T10:03:27","slug":"uk-arrested-2-scattered-spider-hackers-linked-to-london-transport-system-breach","status":"publish","type":"post","link":"https:\/\/serisec.com\/index.php\/2025\/09\/19\/uk-arrested-2-scattered-spider-hackers-linked-to-london-transport-system-breach\/","title":{"rendered":"UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach"},"content":{"rendered":"<p>    UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n    <!-- no image --><br \/>\n \t<BR><br \/>\n<BR><\/BR><\/p>\n<div>\n<p>UK law enforcement has arrested two individuals linked to the notorious <a href=\"https:\/\/cybersecuritynews.com\/scattered-spider-hackers-aviation\/\" target=\"_blank\" rel=\"noreferrer noopener\">Scattered Spider<\/a> cybercriminal group, including 19-year-old Thalha Jubair from London, who faces charges in connection with over 120 network intrusions that resulted in more than $115 million in ransom payments.\u00a0<\/p>\n<p>The arrests represent a significant breakthrough in dismantling one of the world\u2019s most prolific <a href=\"https:\/\/cybersecuritynews.com\/sensata-technologies-hacked-ransomware-attack\/\" target=\"_blank\" rel=\"noreferrer noopener\">ransomware operations<\/a>, which targeted critical infrastructure, including the London Transport system.<\/p>\n<h2 class=\"wp-block-heading\" id=\"h-scattered-spider-hackers-charged\"><strong>\u201cScattered Spider\u201d Hackers Charged<\/strong><\/h2>\n<p>The coordinated operation involved multiple international agencies, with the FBI\u2019s Cyber Division, the UK\u2019s National Crime Agency, the City of London Police, and the West Midlands Police working together to track down the cybercriminals.\u00a0<\/p>\n<p>Jubair, operating under aliases including \u201cEarthtoStar,\u201d \u201cBrad,\u201d \u201cAustin,\u201d and \u201c@autistic,\u201d was charged with computer fraud conspiracy, wire fraud conspiracy, and money laundering conspiracy in a complaint filed in the District of New Jersey.<\/p>\n<p>The investigation revealed that Scattered Spider, also known as \u201cOcto Tempest,\u201d \u201cUNC3944,\u201d and \u201c0ktapus,\u201d employed sophisticated <a href=\"https:\/\/cybersecuritynews.com\/hackers-using-advanced-social-engineering-techniques\/\" target=\"_blank\" rel=\"noreferrer noopener\">social engineering techniques<\/a> to infiltrate corporate networks.\u00a0<\/p>\n<p>The group\u2019s modus operandi included voice phishing attacks against help desks, <a href=\"https:\/\/cybersecuritynews.com\/sim-swapping-protection-esim\/\" target=\"_blank\" rel=\"noreferrer noopener\">SIM swapping<\/a> operations, and spear phishing campaigns to gain unauthorized access to victim systems.<\/p>\n<p>The cybercriminal operation spanned from May 2022 to September 2025, with attackers utilizing advanced persistence mechanisms and lateral movement techniques within compromised networks.\u00a0<\/p>\n<p>Law enforcement successfully <a href=\"https:\/\/www.justice.gov\/opa\/pr\/united-kingdom-national-charged-connection-multiple-cyber-attacks-including-critical\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">seized<\/a> cryptocurrency worth approximately $36 million from servers controlled by Jubair, though he managed to transfer an additional $8.4 million in cryptocurrency to alternative wallets during the seizure operation.<\/p>\n<p>The group\u2019s targeting of critical infrastructure included successful breaches of the U.S. Courts system and a U.S.-based critical infrastructure company in October 2024 and January 2025.\u00a0<\/p>\n<p>The London Transport system breach demonstrates the group\u2019s capability to compromise SCADA systems and operational technology networks that control essential public services.<\/p>\n<p>Assistant Deputy Chief Adrienne L. Rose from the Justice Department\u2019s Computer Crime and Intellectual Property Section (CCIPS) emphasized that since 2020, CCIPS has secured convictions of over 180 cybercriminals and facilitated the return of more than $350 million in victim funds.\u00a0<\/p>\n<p>If convicted on all charges, Jubair faces a maximum penalty of 95 years in prison, highlighting the severe consequences for ransomware-as-a-service operators and their affiliates.<\/p>\n<p class=\"has-text-align-center has-background\" style=\"background:linear-gradient(180deg,rgb(238,238,238) 89%,rgb(169,184,195) 100%)\"><strong>Find this Story Interesting! Follow us on <a href=\"https:\/\/news.google.com\/publications\/CAAqMggKIixDQklTR3dnTWFoY0tGV041WW1WeWMyVmpkWEpwZEhsdVpYZHpMbU52YlNnQVAB?hl=en-IN&amp;gl=IN&amp;ceid=IN:en\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">Google News<\/a>,\u00a0<a href=\"https:\/\/www.linkedin.com\/company\/cybersecurity-news\/\" target=\"_blank\" rel=\"noreferrer noopener nofollow\">LinkedIn<\/a>,\u00a0and\u00a0<a href=\"https:\/\/x.com\/cyber_press_org\" target=\"_blank\" rel=\"noreferrer noopener\">X<\/a>\u00a0to Get More Instant Updates<\/strong>.<\/p>\n<p>The post <a href=\"https:\/\/cybersecuritynews.com\/uk-arrested-2-scattered-spider-hackers\/\">UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach<\/a> appeared first on <a href=\"https:\/\/cybersecuritynews.com\/\">Cyber Security News<\/a>.<\/p>\n<\/div>\n<p> \t<BR><br \/>\n <BR><\/BR><br \/>\n    Florence Nightingale<br \/>\n \t<BR><br \/>\n<BR><\/BR><br \/>\n<a href=\"https:\/\/cybersecuritynews.com\/uk-arrested-2-scattered-spider-hackers\/\">Go to cyber-security-news<\/a><br \/>\n \t<BR><br \/>\n <BR><\/BR><\/p>\n","protected":false},"excerpt":{"rendered":"<p>UK Arrested 2 Scattered Spider Hackers Linked to London Transport System Breach UK law enforcement has arrested two individuals linked to the notorious Scattered Spider cybercriminal group, including 19-year-old Thalha Jubair from London, who faces charges in connection with over 120 network intrusions that resulted in more than $115 million in ransom payments.\u00a0 The arrests [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1636,129,63],"tags":[130],"class_list":["post-7045","post","type-post","status-publish","format-standard","hentry","category-cyber-attack-news","category-cyber-security","category-cyber-security-news","tag-cyber-security-news"],"_links":{"self":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7045"}],"collection":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/comments?post=7045"}],"version-history":[{"count":0,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/posts\/7045\/revisions"}],"wp:attachment":[{"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/media?parent=7045"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/categories?post=7045"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/serisec.com\/index.php\/wp-json\/wp\/v2\/tags?post=7045"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}