---
title: "Scattered Spider Guilty Pleas: What the TfL Hac… | Firevault"
description: "Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer."
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery#webpage",
      "url": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery",
      "name": "Scattered Spider Guilty Pleas: What the TfL Hac…",
      "description": "Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery",
          "item": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery",
      "description": "Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.",
      "url": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-06-22T15:26:35.26658+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/scattered-spider-tfl-guilty-plea-offline-recovery"
      },
      "inLanguage": "en-GB",
      "articleSection": "Threat Analysis",
      "wordCount": 792,
      "keywords": "Scattered, Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "> _I read this in The Times this morning. Two members of the loose hacking crew known as Scattered Spider have admitted the August 2024 attack on Transport for London. The cost has now passed £39 million, and the case is a clean illustration of how a single identity compromise reaches every system that depends on it. Reporting by Ali Mitib, The Times, 22 June 2026._ > **Key takeaways** > > - Thalh",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "Who are Scattered Spider?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Scattered Spider is the cybersecurity industry name for a loose collection of mostly English-speaking attackers who use social engineering, help desk impersonation and session theft to breach large enterprises. UK police have linked the same crew to the 2024 TfL hack and to the 2026 attacks on Marks and Spencer, Co-op and Harrods."
          }
        },
        {
          "@type": "Question",
          "name": "What customer data was exposed in the 2024 TfL hack?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "According to The Times, about 5,000 TfL customers had personal information exposed, including names, home addresses, contact details, bank account numbers and the sort codes linked to Oyster travel cards. All 27,000 TfL staff were required to recertify their credentials in person at head office."
          }
        },
        {
          "@type": "Question",
          "name": "How does offline secure storage change the outcome of an attack like this?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Offline secure storage holds a physically disconnected, controlled-access copy of critical systems and data at Layer 1. Because the directory cannot reach it and no stolen session can authenticate to it, the copy cannot be encrypted, exfiltrated or deleted by an attacker who has compromised production identity. That is what allows recovery without paying a ransom or rebuilding from scratch."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What actually happened to TfLWhy Scattered Spider keeps winningThe Firevault viewSourceMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Threat Analysis · 22 June 2026 

# Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery&text=Scattered%20Spider%20Guilty%20Pleas%3A%20What%20the%20TfL%20Hack%20Confirms%20About%20Offline%20Recovery%0A%0ATwo%20Scattered%20Spider%20members%20have%20admitted%20the%20%C2%A339m%20TfL%20hack.%20Mark%20Fermor%20on%20identity%20blast%20radius%20and%20why%20offline%20recovery%20is%20the%20deciding%20layer.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery)[](mailto:?subject=Scattered%20Spider%20Guilty%20Pleas%3A%20What%20the%20TfL%20Hack%20Confirms%20About%20Offline%20Recovery&body=Two%20Scattered%20Spider%20members%20have%20admitted%20the%20%C2%A339m%20TfL%20hack.%20Mark%20Fermor%20on%20identity%20blast%20radius%20and%20why%20offline%20recovery%20is%20the%20deciding%20layer.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Fscattered-spider-tfl-guilty-plea-offline-recovery)

![Transport for London signage at a station entrance, illustrating the 2024 Scattered Spider cyber attack](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg)

Transport for London signage at a station entrance, illustrating the 2024 Scattered Spider cyber attack

Why it matters

## What this means for organisations holding critical data

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

In this analysis

1.  01 [What actually happened to TfL](#section-0)
2.  02 [Why Scattered Spider keeps winning](#section-1)
3.  03 [The Firevault view](#section-2)

**On this page**[What actually happened to TfL](#section-0)[Why Scattered Spider keeps winning](#section-1)[The Firevault view](#section-2)

> _I read this in The Times this morning. Two members of the loose hacking crew known as Scattered Spider have admitted the August 2024 attack on Transport for London. The cost has now passed £39 million, and the case is a clean illustration of how a single identity compromise reaches every system that depends on it. Reporting by Ali Mitib, The Times, 22 June 2026._

> **Key takeaways**
> 
> -   Thalha Jubair, 20, and Owen Flowers, 18, pleaded guilty at Woolwich Crown Court to the Computer Misuse Act offences behind the TfL hack. Sentencing is set for 15 July.
> -   The 31 August 2024 intrusion exposed names, home addresses, contact details, bank account numbers and Oyster sort codes for around 5,000 customers, and forced all 27,000 TfL staff to recertify their credentials in person.
> -   The same crew is linked by police to the 2026 attacks on Marks and Spencer, Co-op and Harrods. Flowers also admitted breaches of SSM Health and Sutter Health in the United States.
> -   When identity is the blast radius, online backups inherit the compromise. Offline, controlled-access copies are what decides recovery.

Two men accused of belonging to the cybercrime collective known as Scattered Spider have pleaded guilty to the 2024 attack that paralysed Transport for London, in a case The Times reports has now cost the operator more than £39 million.

Thalha Jubair, 20, of east London, and Owen Flowers, 18, of Walsall in the West Midlands, admitted conspiring to commit unauthorised acts under the Computer Misuse Act before the opening of their trial at Woolwich Crown Court. They will be sentenced on 15 July.

## What actually happened to TfL

The intrusion on 31 August 2024 forced TfL to suspend a range of services across the capital. According to The Times, personal information for about 5,000 customers was exposed, including names, home addresses, contact details, bank account numbers and the sort codes linked to Oyster travel cards.

Major transport services kept running, but the operational fallout was significant. Passengers could not access their Oyster accounts online. Third-party services such as Citymapper went dark. The Dial-a-Ride service for disabled passengers was briefly suspended. Every one of TfL'''s 27,000 staff had to attend head office to recertify credentials and reset passwords.

That last detail is the one that should hold the attention of any board reading this. The recovery cost was not paid in ransom. It was paid in identity rebuild.

## Why Scattered Spider keeps winning

Scattered Spider is the industry label for a loose group of English-speaking attackers who combine social engineering with off-the-shelf tooling to compromise large enterprises. Police have linked the same crew to this year'''s incidents at Marks and Spencer, Co-op and Harrods. Flowers also pleaded guilty to hacks against SSM Health Care Corporation and Sutter Health, two United States healthcare systems.

The pattern is consistent. The attackers do not break encryption. They convince a help desk, capture a session, and walk through the front door of identity. From there, they reach the systems an authenticated user can reach, including the backup platforms.

## The Firevault view

The TfL case is not a story about a clever exploit. It is a story about what stays reachable once a privileged session is compromised. Three points stand out from our position.

First, identity is the blast radius. The moment a domain account is taken, every system that trusts that account becomes part of the incident. That includes the backup console, the snapshot scheduler, the immutability flags and the API keys that protect them.

Second, online backups inherit the compromise. A copy that sits behind the same directory as the production system is not a recovery copy. It is a second target. The attacker does not need to break it, they only need the credential that already governs it.

Third, recovery time is decided before the attack, not during it. The organisations that recover fastest are the ones that hold a physically disconnected, controlled-access copy of the systems and data that matter most. Nothing reachable from a stolen session can be encrypted, exfiltrated or quietly deleted.

This is the design principle behind [Firevault Offline Secure Storage](/solutions/offline-secure-storage). The golden copy lives at Layer 1, behind a deliberate human authorisation step. The directory cannot reach it. The attacker cannot phish it. The help desk cannot release it by mistake.

For boards, the practical posture is simple. Assume the credential is already lost. Rehearse recovery from a copy the attacker cannot see. Read our briefing on [recovery independence](/learn/guides/recovery-independence) for the questions to put to your IT and security leadership this quarter.

— Mark Fermor, Director and Co-Founder, Firevault

## Source

Ali Mitib, [Cybercriminals admit hack that paralysed TfL systems](https://www.thetimes.com/article/892e87f0-041f-4a21-b299-6ff574b2fdae?shareToken=d6d34610b88a2e816a43e08e8f5bb87e&ver=article), The Times, 22 June 2026.

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg)

Threat Analysis 

### UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

20 Jun 2026 5 min 







](/news/ncsc-uk-critical-infrastructure-incidents-double)[

![24 billion credentials exposed in record infostealer leak](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg)

Threat Analysis 

### 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

19 Jun 2026 4 min 







](/news/24-billion-credentials-infostealer-leak)[

![FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials](/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg)

Threat Analysis 

### FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

18 Jun 2026 4 min 







](/news/fortibleed-74000-fortinet-firewalls-credentials-exposed)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)