TfL hackers jailed after £39m cyberattack exposed gaps
Two young hackers have been jailed after a 2024 breach of Transport for London systems that disrupted services and cost the authority £39m
Two young hackers have been jailed for their roles in a cyberattack on Transport for London that exposed how heavily the capital depends on connected transport systems and back-office digital infrastructure.
Thalha Jubair, 20, and Owen Flowers, 19, were each sentenced to five and a half years after the attack, which TfL said cost it £39m. The case has drawn attention not only because of the scale of the financial damage, but also because the breach reached deep into systems that support everyday travel across London.
How the attack affected TfL
According to details supplied by TfL, the incident took place between 31 August and 3 September 2024. During that period, the authority was unable to process payments through Oyster and contactless apps, and it could not register Oyster cards to customer accounts.
The breach also forced 27,000 TfL staff to reset their passwords. In addition, the data of millions of commuters was stolen, increasing the seriousness of the incident and raising concerns about the exposure of personal information used in a major public transport network.
TfL said the attack left its systems vulnerable to what it described as potentially catastrophic damage. The authority also warned that the incident could have triggered significant and extended disruption to transport services.
Why the case matters
The episode matters because TfL is one of the largest transport operators in Europe and its systems are tied to millions of passenger transactions and staff accounts. Even though the main tube and bus networks were not directly affected, the disruption reached important supporting services, including bookings for the dial-a-ride service used by disabled passengers.
That contrast is important. It shows how a cyberattack does not need to stop trains or buses to create serious damage. Interrupting payment systems, account access and booking services can still cause widespread inconvenience, operational strain and cost.
Andy Lord, the head of TfL and a veteran of British Airways, said the attack was the worst incident he had faced in his career. That assessment underlines the scale of the threat and the pressure such breaches place on public bodies responsible for essential services.
The Guardian reported that the hackers had gained access to the heart of TfL’s IT systems and held what was described as the keys to the kingdom, reflecting the level of access investigators believed they had achieved. The phrase captures how dangerous this kind of breach can be when attackers move beyond a single device or account and into systems that support an entire organisation.
Broader lessons from the breach
The sentencing brings a legal conclusion to a case that highlighted the challenge facing transport operators and other large organisations as they defend against cybercrime. The attack affected both customer-facing services and internal staff systems, showing how one intrusion can spread across multiple parts of a business.
It also shows the cost of remediation after a major security incident. TfL said the breach cost £39m, a figure that reflects more than lost revenue and likely includes the work needed to contain the attack, restore systems and strengthen defences.
While the main railway and bus services were not directly interrupted, the damage to payment and booking infrastructure was still enough to make the attack one of the most serious cyber incidents TfL had encountered.
The case serves as a reminder that transport networks now depend on a wide digital ecosystem, where a compromise in one part of the system can affect millions of people even when the physical network keeps running.
With the jail sentences now imposed, the focus for TfL will remain on security, recovery and reducing the risk of a similar breach in future.
Comments
No approved comments yet.



