Scattered Spider Sentenced: 5.5 Years for £29M TfL Wreckage
Just saw the news regarding the sentencing of Owen Flowers and Thalha Jubair. It’s rare we see such heavy sentences handed out—5.5 years each is significant, especially given their ages. While the legal outcome is notable, the operational impact on Transport for London (TfL) is a stark warning for all of us managing critical infrastructure.
The attack took down 148 systems and forced 27,000 employees to physically come in for password resets. That level of operational disruption is terrifying. We know Scattered Spider’s playbook: heavy social engineering, MFA fatigue, and abusing legitimate RMM tools. Once they bypassed the perimeter, they likely moved laterally using credentials harvested from the O365 environment.
For those monitoring for this group, keep an eye out for unusual RMM process execution paths. Scattered Spider loves dropping tools like AnyDesk or ScreenConnect in user directories.
Here’s a basic KQL query to hunt for suspicious RMM activity in your environment:
DeviceProcessEvents
| where Timestamp > ago(7d)
| where FileName in~ ("anydesk.exe", "screenconnect.client.exe", "sunloginclient.exe")
| where FolderPath !contains @"Program Files" and FolderPath !contains @"Program Files (x86)"
| project DeviceName, AccountName, FileName, FolderPath, SHA256
The financial cost is pegged at £29 million, but the reputational hit is likely higher. With 148 systems inoperable, this suggests a lack of effective segmentation or a rapid spread via privileged credentials.
Given the scale of the password reset logistics, do you think forcing in-person resets is a valid emergency containment strategy, or does it just exacerbate the downtime?
Forcing in-person resets is a last-ditch effort, but honestly, I respect the call. If your identity provider (IdP) is fully compromised and you can't trust MFA, you have to assume the attacker still has persistence. It's brutal for ops, but it's the only way to guarantee the actor isn't sitting in the inbox waiting for the reset link.
The age of these actors (18 and 20) is what gets me. 5.5 years is a decent chunk of their lives, but will it act as a deterrent? Technically, the KQL you posted is solid, but don't forget to correlate it with sign-in logs. Scattered Spider often uses token theft. Look for UserAgent strings spoofing legacy browsers paired with impossible travel data.
We had a similar scare last year. We didn't go full in-person, but we forced a hardware key (FIDO2) rollout to all admins immediately. The £29M figure likely includes the overtime for those 27,000 staff. If they had FIDO2 enforced, would this have been stopped? Probably not initially if they phished credentials, but it stops the replay attacks.
Verified Access Required
To maintain the integrity of our intelligence feeds, only verified partners and security professionals can post replies.
Request Access