20°C

few clouds

TFL Updates
London Daily News

TfL cyber attack: Two men convicted for 2024 hack that crippled London transport

TfL cyber attack: Two men convicted for 2024 hack that crippled London transport

Two young men, known in court as Flowers and Jubair, have been convicted for the 2024 cyber-attack that crippled Transport for London systems, the court heard today. Both defendants, described by prosecutors as having long histories of cyber-offending and already known to police, face sentencing on 16 July 2026. US law enforcement has also indicated it will seek extradition proceedings against the pair.

Attack that paralysed London transport

The incident, which took place in 2024, targeted the computer systems that underpin Transport for London, causing large-scale disruption across the capital’s network. Prosecutors told the court the attack “crippled” TfL systems, an outcome that prompted immediate emergency responses and a prolonged restoration effort. The event was widely regarded at the time as one of the most serious assaults on critical transport infrastructure in recent UK history.

Details presented in court set out how the breach overwhelmed key operational and administrative systems, with TfL forced to implement contingency measures while engineers worked to restore services and data integrity. The conviction marks the culmination of a multi-agency criminal investigation that involved specialist cyber teams and months of forensic work to trace the attack and link it to the defendants.

The defendants and their offending histories

Both Flowers and Jubair were described at trial as young men with extensive records of cyber-offending, and witnesses for the prosecution emphasised that each was known to police before the 2024 incident. Prosecutors argued their prior conduct demonstrated a pattern of behaviour that culminated in the TfL attack.

Legal documents made public in court noted previous interactions with law enforcement, and the defendants were said to have participated in online communities where hacking techniques and tools are shared and discussed. Defence counsel sought to characterise elements of the defendants’ past behaviour as youthful experimentation, but the jury accepted the prosecution’s case that the 2024 attack represented a deliberate and harmful escalation.

Court proceedings focused on establishing a clear chain of digital evidence linking the men to the intrusion, including analysis of internet traffic, device logs and communications. Experts called by the prosecution detailed how the technical footprints left by the perpetrators were matched against data recovered in searches of devices associated with Flowers and Jubair.

Court process and international interest

Conviction in this case carries significant potential penalties, and the court has scheduled sentencing for 16 July 2026. That date gives both defence and prosecution time to prepare mitigation and aggravating evidence for the judge to consider, including the scale of disruption caused and the defendants’ previous records.

In addition to domestic legal consequences, US law enforcement agencies have notified UK authorities they will seek extradition proceedings relating to alleged offences connected to the same or related activity. Extradition requests of this kind typically hinge on outstanding charges in the requesting jurisdiction, and could lead to separate legal processes if the US proceeds. Officials involved in the investigation said the matter is being handled through formal channels, with ongoing liaison between UK and US prosecutors.

The prosecution was carried out amid a complex legal and technical landscape, where digital evidence must be authenticated and shown to a criminal standard. Defence teams raised questions during trial about attribution in cyberspace, arguing that technical indicators can sometimes be misleading. The jury, however, found the evidence sufficient to convict.

Wider implications and what comes next

The convictions are likely to reverberate across public and private sectors as policymakers and industry leaders assess the adequacy of defences protecting critical infrastructure. Transport networks and other essential services are increasingly reliant on interconnected digital systems, and this case underscores how a successful attack can have immediate and wide-reaching consequences for commuters, businesses and emergency services.

Security specialists say the verdict will add momentum to calls for greater investment in cyber resilience across government and regulated industries, including more rigorous incident response planning, regular red-teaming exercises, and improved information sharing between organisations and law enforcement. There will also be renewed scrutiny of pathways by which individuals move from low-level cyber misbehaviour to offences that threaten national infrastructure.

For the families of people affected by the 2024 disruption, and for TfL employees who worked to restore services, the convictions will bring a measure of closure, though the sentencing next month will be a key moment for victims and the public to see the full legal consequences applied. If extradition requests from the United States proceed, the defendants could face additional charges overseas, prolonging the legal process.

As the justice process moves to sentencing and possible international proceedings, authorities say they will continue to prioritise strengthening defences and international cooperation to deter and respond to future attacks. The coming weeks will show whether the sentences imposed, and any further action abroad, prompt changes in policy or practice to reduce the likelihood of a repeat incident in London’s vital transport network.

Pin It on Pinterest