On 16 July 2026, at Woolwich Crown Court, two young British men were sentenced to five years and six months in prison each for their part in the 2024 cyber-attack on Transport for London — the largest cybercrime prosecution the United Kingdom has ever brought under the Computer Misuse Act. Owen Flowers, 18, from Walsall, and Thalha Jubair, 20, from East London, were both handed identical custodial terms for an intrusion that the National Crime Agency puts at roughly £39 million in total cost, that rendered 148 of TfL’s IT systems inoperable, that forced 27,000 employees to attend an office in person to reset their passwords, and that exposed the personal data of as many as 10 million customers. Both men are members of Scattered Spider, the loosely organised, English-speaking social-engineering collective drawn from the wider online community known as “The Com”.
What matters to every UK SME is not the scale of the target but the ordinariness of the method. Scattered Spider did not break into TfL with a zero-day exploit or a bespoke piece of malware. They broke in with a telephone call. Armed with partial credentials bought from criminal marketplaces, the attackers rang a TfL help-desk worker and, after several attempts, talked them into resetting a two-factor authentication code — then escalated their access until they held domain-administrator rights, what investigators called the “keys to the kingdom”. That same phone call works just as well against a 30-person accountancy practice as against a transport authority with 27,000 staff. This article sets out what the court heard at sentencing, why the National Crime Agency has named home-grown social-engineering threat actors as one of the biggest challenges facing UK business in 2026, and why managed IT support built around strict identity verification — not another antivirus licence — is now the decisive line of defence.
What the Court Heard at Sentencing
The sentencing hearing on 16 July 2026 drew a line under a case the National Crime Agency describes as its largest-ever cybercrime prosecution and only the second of its kind brought under the Computer Misuse Act. The judge described the pair’s conduct as driven by “selfish bravado” — a phrase that captures the character of the whole Scattered Spider operation, in which teenagers with no state backing and no advanced tooling caused tens of millions of pounds of damage for status, money and the thrill of it. The court accepted mitigating factors, including the defendants’ youth at the time of the offending and autism diagnoses, which is reflected in the identical five-and-a-half-year terms rather than the longer sentences the aggravating features might otherwise have attracted.
The aggravating features were considerable. Jubair, the court heard, has 22 prior convictions dating back to the age of 14, and is separately wanted in the United States, where he is linked to ransom payments totalling around $115 million extracted from 47 victim organisations. Flowers was arrested in a raid that caught him mid-attack against two US healthcare providers — a detail that underlines how the group treated hacking as continuous, full-time work rather than a one-off. Most strikingly, both men were found with contraband mobile phones while on remand in prison, still using them to plan further intrusions. This was not a pair of curious adolescents who strayed once across a line; it was, on the NCA’s account, a determined and prolific criminal enterprise that continued operating even from a cell.
The technical account read to the court is the part every business owner should sit with. The attackers began with partial credentials — usernames and fragments of authentication data — purchased from criminal markets, the kind of low-grade stolen information that circulates for a few pounds after any commodity phishing campaign. They then telephoned a TfL help-desk worker and requested a reset of a two-factor authentication code. It did not work first time; it took multiple attempts and multiple calls. But persistence paid, the reset was granted, and from that single foothold the attackers escalated their privileges step by step until they controlled the domain. Every stage of that chain turned on a human being making a helpful decision under pressure. No firewall was breached in the conventional sense. No unpatched server was exploited. The perimeter that failed was a person on a phone.
Every control Scattered Spider defeated at TfL exists inside a small business too — almost always in a weaker form. A 40-person firm has a help desk (often one overstretched IT manager or an outsourced first-line desk), uses SMS or basic app-based multi-factor authentication, keeps one or two shared administrator logins, and has no written identity-verification procedure for password resets. The attackers reached a £39 million target using nothing more than bought credentials and a persuasive phone call — the exact ingredients present in every SME. Social engineering does not lose effectiveness as the target shrinks; if anything it gains, because smaller organisations run more informal processes and their staff are more directly reachable. The National Crime Agency has been explicit that although Scattered Spider has been “heavily degraded and disrupted” by arrests, the threat from home-grown, English-speaking social engineers remains one of the UK’s biggest cybersecurity challenges. The phone call that reached TfL will reach your business unless you have deliberately designed it not to.
The Timeline: From Attack to Sentencing
How the Attack Chain Bypasses Every Technical Control
The most uncomfortable truth in the Scattered Spider case is that almost every security product a typical SME buys would have been irrelevant to the outcome. Antivirus does not stop a help-desk worker from resetting a two-factor code for someone who sounds legitimate and persists across several calls. A firewall does not inspect a telephone conversation. An email gateway does not see partial credentials being bought on a criminal forum, nor a privilege-escalation step being taken by an account that has already authenticated. The breach succeeds in the space between technology and human process — and in most organisations that space is owned by the IT support function. The bar chart below shows where the attack chain actually exerts its pressure, and how little of it perimeter technology addresses on its own.
Read the chart from the bottom up and the strategic implication is stark. The control most SMEs treat as their primary defence — antivirus and a perimeter firewall — sits at the very foot of the chart in terms of relevance to this style of attack. Every vector above it is about identity: who can prove they are who they claim to be, and what process exists to verify it before an account is reset or elevated. This is precisely why the National Crime Agency, the NCSC and successive Five Eyes advisories now place identity and access control at the centre of their recommendations to business leaders. The defence is not a product you install once and forget; it is a set of processes, verification standards and monitoring practices that must be designed, documented, enforced and watched continuously — which is exactly what a managed IT support relationship exists to provide.
The Identity Verification Gap — Where SMEs Are Most Exposed
The single most effective change an SME can make in response to the Scattered Spider sentencing is also one of the cheapest: a documented, mandatory identity-verification procedure for any password reset or two-factor-device change handled by the help desk. The reason TfL had to reset 27,000 employees in person is that, once it knew an attacker had been talking its support function into resets, it could no longer trust any remote identity claim. A pre-agreed verification standard — a call-back to a number already on record, a manager-approval step for privileged accounts, a one-time code delivered through a separate trusted channel, or an in-person check for the most sensitive resets — removes the worker’s discretion to be talked around. It converts a judgement call made under pressure into a checklist that persistence and a convincing story cannot defeat.
For SMEs, this gap is structural rather than a matter of carelessness. Most small businesses built their IT support around helpfulness and speed: the entire purpose of the help desk is to unblock a colleague who is locked out and needs to work. Scattered Spider weaponises exactly that helpfulness. The attacker presents as a stressed employee who cannot reach a critical system before an important deadline, applies time pressure, and counts on the worker’s instinct to close the ticket quickly. The TfL reset did not succeed on the first attempt — it took several — which tells you the human on the other end had doubts and was worn down anyway. Without a verification standard that the worker is required to follow regardless of how urgent or senior the caller sounds, the help desk is the softest point in the entire security model, and no amount of perimeter spending compensates for it.
The SME Social-Engineering Exposure Scorecard
The scorecard reflects a consistent pattern in what managed IT providers see day to day. The controls that defeat social engineering are disproportionately the ones SMEs have not implemented — not because they are expensive, but because they require process design and ongoing enforcement rather than a one-off purchase. A business can buy a firewall in an afternoon; it cannot buy a verification culture, a least-privilege model or a round-the-clock monitoring capability the same way. This is precisely the value of a proactive IT support relationship: the controls that matter most against the Scattered Spider method are operational, continuous and best owned by a partner whose job is to run them every day, rather than by an internal generalist juggling them alongside procurement, projects and the printer that will not connect.
The Cost of Getting This Wrong: Size-Band Analysis
| Organisation | Headcount | Typical help-desk model | Exposure to the Scattered Spider method | Indicative annual cyber spend |
|---|---|---|---|---|
| Micro business | 1–9 | Owner or ad-hoc external fixer | Very high — no formal verification at all | £10,000–£20,000 |
| Small business | 10–49 | One IT manager or first-line outsourcer | High — informal, pressure-driven resets | £30,000–£150,000 |
| Medium business | 50–249 | Small internal team, often no documented IAM | Medium-high — shared admin accounts common | £150,000–£500,000 |
| Large enterprise | 250+ | Dedicated SOC and IAM function | Medium — still breached via help desk (MGM, M&S) | £1m+ |
| TfL (public-sector benchmark) | 27,000 staff | Enterprise IT with formal controls | Realised — £39m total cost, 148 systems down | N/A |
The instructive comparison is between the bottom of the table and the top. TfL is a sophisticated, well-resourced organisation with a formal IT function and enterprise-grade tooling, and it still suffered a £39 million breach through social engineering — with 148 systems knocked out and up to 10 million customer records exposed. If an organisation of that scale and maturity can be reached through its identity and help-desk processes, the implication for a 40-person firm with one IT manager and SMS-based two-factor authentication is not subtle. The reassuring half of the picture is that the controls that would have mattered most — phishing-resistant MFA, a documented verification procedure, least-privilege access and continuous monitoring — are entirely within reach of an SME budget when delivered through a managed support model. The annual cyber spend that closes those gaps for a small business is a fraction of the recovery cost of a single serious account-compromise incident, let alone the £39 million TfL ultimately absorbed. Investigators also noted that had TfL been fully shut down, the knock-on cost to the wider economy could have run to as much as £56 billion — a reminder that the true blast radius of these attacks reaches far beyond the victim’s own balance sheet.
Reactive vs Proactive IT Support: The Two Postures
Reactive posture
What most UK SMEs operate today
- Help desk resets passwords and MFA on request, under time pressure, with no formal identity check
- SMS or basic app push used for MFA on all accounts, including administrators
- One or two shared administrator logins used by whoever needs them
- Everyone holds broad access “to be safe” — no least-privilege model
- No monitoring of sign-ins; compromise discovered only after business impact
- Conditional-access policies licensed but never configured
- No tested runbook for a compromised account; response improvised on the day
- Staff told to “be careful” but never tested with a vishing simulation
Proactive posture
Where managed IT support takes you
- Mandatory, documented verification standard for every reset — call-back, manager approval or in-person for privileged accounts
- Phishing-resistant MFA (FIDO2 security keys / passkeys) on all admin and remote-access accounts
- Named, individual admin accounts with no shared credentials; privileged access granted just-in-time
- Least-privilege model; access reviewed regularly and revoked on role change
- 24/7 monitoring with anomaly and impossible-travel alerting on identity
- Conditional access enforcing device compliance, location and sign-in risk
- Tested incident-response runbook with a defined containment and recovery path
- Regular phishing and vishing simulations with measured staff response
The difference between these two columns is less a matter of budget than of operating model. The reactive posture treats IT support as a break-fix utility that exists to unblock people quickly — and speed, unqualified by verification, is exactly what the TfL attackers exploited when they wore down a help-desk worker over several calls. The proactive posture treats IT support as the owner of the identity perimeter: the function responsible for ensuring every access request is verifiable, every privileged action is logged, and every anomalous sign-in is seen and investigated. Scattered Spider attacks the reactive posture and is largely defeated by the proactive one. Moving from left to right is the single most valuable security investment an SME can make in 2026, and it is the core of what a managed IT support engagement delivers.
If you do nothing else this week, write down a help-desk verification standard and make it mandatory. It costs almost nothing, can be drafted in an afternoon, and removes the exact discretion the TfL attackers exploited — a worker’s freedom to grant a reset because a caller was persistent and sounded urgent. Pair it with phishing-resistant MFA on your handful of administrator, finance and director accounts — in most SMEs that is only a few people — and you have closed the two highest-probability paths a social-engineering attacker would take against your business. Everything else deepens the posture, but those two moves deliver the majority of the risk reduction for the lowest cost. A managed IT support partner can stand up both within the first fortnight of an engagement, without disrupting day-to-day operations.
At-a-Glance: Key Facts for UK Business Leaders
| Topic | Key figure or fact | Source |
|---|---|---|
| Total cost of the TfL breach | £39 million (£29m recovery + £10m lost income) | National Crime Agency |
| Sentence per defendant | 5 years 6 months each | Woolwich Crown Court, 16 July 2026 |
| Defendants | Owen Flowers (18, Walsall); Thalha Jubair (20, East London) | Woolwich Crown Court |
| IT systems rendered inoperable | 148 | National Crime Agency |
| Staff forced to reset passwords in person | 27,000 | National Crime Agency |
| Customers potentially affected | Up to 10 million | National Crime Agency |
| Initial access method | Phoned help desk, reset 2FA using purchased partial credentials | Court evidence |
| Escalation outcome | Domain administrator — the “keys to the kingdom” | Court evidence |
| Attack date | 31 August 2024 | National Crime Agency |
| Jubair’s prior convictions | 22, dating back to age 14 | Court evidence |
| Jubair’s US-linked activity | $115m in ransoms across 47 victims | US charges |
| Wider Scattered Spider targets | M&S, Co-op, Harrods, MGM Resorts, Caesars | Public reporting |
| Linked US extradition | Peter Stokes (19, US-Estonian), Finland to Chicago, 1 July 2026 | US Department of Justice |
| Prosecution status | UK’s largest-ever cybercrime prosecution; second of its kind under the CMA | National Crime Agency |
| Potential wider economic impact | Up to £56 billion had TfL been fully shut down | Investigation estimate |
Read Alongside: The 2026 Threat Landscape in Context
The Scattered Spider sentencing does not stand alone; it sits inside a run of 2026 developments that together define the threat environment UK SMEs now operate in. For the ransomware backdrop — the monetisation model that groups like this ultimately feed — our analysis of the 323 UK firms hit by ransomware and the City of London Police response shows how initial access so often begins with the same identity failures described here. The Check Point June 2026 data on 1,589 weekly attacks per UK organisation and The Gentlemen ransomware quantifies the sheer volume of pressure on the perimeter, while the NCSC and FSB router advisory covers the network-edge exposure that compounds it. On the patching side, our July 2026 Patch Tuesday review of the SharePoint and AD FS zero-days across 622 CVEs and the wider AI-driven CVE surge and patch programme analysis close out the technical half of the attack surface that identity controls cannot cover on their own. Read together, they describe the full baseline a UK SME should hold in mid-2026.
Close the gaps Scattered Spider exploited — before the next call comes in
Cloudswitched managed IT support owns the identity perimeter most SMEs leave exposed: documented help-desk verification, phishing-resistant MFA, least-privilege access, 24/7 monitoring and a tested incident-response runbook. Proactive by design, with a dedicated account manager and an industry-leading SLA response.
Talk to us about Managed IT SupportFrequently Asked Questions
The sentences are in — now fix the perimeter they exploited
The Scattered Spider sentencing is the most concrete proof yet that social engineering, not malware, is the threat that reaches UK businesses of every size. Cloudswitched managed IT support closes the exact gaps it exploited — verification, phishing-resistant MFA, least privilege and round-the-clock monitoring — with proactive ownership and a single point of contact. If your help desk could be talked into a reset today, this is where you start.
Talk to us about Managed IT Support


