Two teenagers responsible for a significant cyber-attack on Transport for London (TfL) last year were already known to law enforcement years before the incident, according to recent court proceedings. Owen Flowers, 19, and Thalha Jubair, 18, pleaded guilty to offences under the Computer Misuse Act for their roles in the September 2023 breach, which disrupted internal systems and resulted in substantial recovery costs for the transport authority.
The intrusion targeted TfL’s internal corporate systems rather than the operational technology that controls trains or signalling. However, the breach forced the organisation to take several internal platforms offline as a precaution, disrupting staff access to email, HR systems, and other administrative tools. TfL confirmed that no customer payment data was compromised, but the incident triggered a large-scale forensic investigation and system rebuild. The transport body previously estimated the total cost of the response — including external security consultants, legal fees, and infrastructure remediation — at approximately £30 million.
During sentencing hearings, it emerged that both defendants had been on the radar of the National Crime Agency (NCA) and the Metropolitan Police’s Cyber Crime Unit well before the TfL attack. Flowers had been arrested in 2021, aged 16, in connection with separate hacking offences targeting educational institutions and private companies. He was released under investigation at the time. Jubair had also been spoken to by officers in 2022 regarding online cyber-crime forum activity. Neither was subject to active monitoring or restrictive orders at the time of the TfL breach.
The case highlights a growing challenge for UK law enforcement: the gap between identifying young people involved in cyber-crime and intervening effectively before they escalate to high-impact attacks. The NCA runs a “Cyber Choices” programme aimed at diverting talented but at-risk youth into legitimate tech careers, but participation is voluntary. Critics argue that without stronger early intervention — such as mandatory mentorship, restricted device access, or closer coordination with schools — known offenders can reoffend with greater sophistication.
For the millions who rely on the Tube, buses, and contactless payment daily, the attack did not halt services. But the £30 million recovery bill ultimately comes from public funding — fares and taxpayer subsidies. More broadly, the incident underscores that critical urban infrastructure remains a target for relatively low-sophistication actors. As cities digitise further, the resilience of administrative back-ends becomes as vital as the physical rails. The Flowers and Jubair case may prompt renewed debate over whether current youth diversion strategies are sufficient to protect essential services from insider-enabled or opportunistic cyber threats.
Image: Photo: Brett Jordan · Pexels
Based on reporting from bbc.co.uk.
Cookies & Privacy: This website uses cookies to ensure you get the best experience on our website. Read more.