Metro, Thursday 16 July 2026
Metro reports that two teenage hackers, Thalha Jubair, now 20, and Owen Flowers, 18, face sentencing after admitting conspiracy over a 2024 attack on Transport for London that a prosecutor said could have caused a potential £56billion loss to the UK economy. The pair spent six days inside TfL's servers using the log-ins of its chief information security officer, obtained after requesting a password reset, gaining what the prosecution called "the keys to the kingdom." They stopped contactless and Oyster payments, disrupted live Tube information, and viewed celebrities' account details, forcing TfL to pull the plug on its whole system and 27,000 staff to change passwords. The remedial work cost the public purse £29million. The pair, part of hacking gang Scattered Spider, face a maximum of 14 years in jail.
The prosecution's own language, "keys to the kingdom," names the actual finding here more precisely than the £56billion figure does. That number describes a hypothetical worst case the pair chose not to trigger. What they did trigger, a single password reset request against the login of TfL's own chief information security officer, is the more useful piece of information, because it is not a story about sophisticated infiltration defeating a hardened target. It is a story about a critical national infrastructure system whose security depended, at the point that mattered, on a process no more robust than the one an ordinary customer uses to get back into a locked account.
Chapter 13's discussion of dormant capability is usually about tools that exist but sit unused. This is close to the inverse: a vulnerability that existed, unused, until two people the prosecution's own framing repeatedly calls teenagers found it in an afternoon. The £29million remedial cost and the 27,000 forced password changes are the visible bill for a gap that was, on the specific facts here, cheap and simple to open. "Remarkably sophisticated, on a grand scale," as the prosecutor called it, describes the consequences accurately and the method less so. A system whose defences turn out to hinge on a single support-desk process is not a fortress that fell to a sophisticated siege. It is a system that had never been seriously tested until someone bothered to try the front door, and calling the result sophisticated is easier than admitting how little was actually required to walk through it.
This entry shows a critical infrastructure system's security resting, at the point that mattered, on a process no stronger than an ordinary customer support request, with the language of sophistication arriving only after the fact.