Skip to Content

What I Learned from Sitting in on a Scattered Spider Sentencing

Flowers and Jubair Sentencing
24 July 2026 by
What I Learned from Sitting in on a Scattered Spider Sentencing
John Fitzpatrick


Last week I spent a morning sitting in the public gallery at Woolwich Crown Court, watching the sentencing of Owen Flowers and Thalha Jubair - two prominent members of the notorious Scattered Spider collective.

I wasn't there for the drama of the court case. The mainstream media has already covered that much better than I could. I was there because I wanted to better understand how Flowers and Jubair operated and to capture some of the technical information that will never be reported in mainstream media.

We hear a lot about Scattered Spider and the organisations they have targeted. We hear about the impact of the attacks, the stolen data and the disruption. But we hear much less about how they actually operate and the tooling and techniques they employ.

There were definitely a few things that surprised me. There were also a few things that I found myself thinking about long after I left the courtroom.

So, this is my attempt to pull together some of the more interesting technical details that came out during the proceedings, and to think about what we might learn from them.


A quick note on the evidence

In the UK, courtrooms generally have a public gallery, meaning that members of the public can turn up and observe proceedings.

Because Flowers and Jubair pleaded guilty, there was no full trial. Instead, the proceedings moved on to sentencing.

From an intelligence-gathering perspective, this is a bit of a double-edged sword.

On the one hand, you get a concentrated summary of a huge amount of evidence over a relatively short period of time, rather than sitting through weeks of testimony.

On the other hand, because there is no need to establish every fact from scratch, the technical detail shared in open court is naturally more limited.

It is also worth remembering that the evidence was presented primarily by prosecution and defence barristers. These are legal experts, not cyber security specialists.

There were therefore several points where I wasn't entirely sure what was being described technically. Where possible, I have tried to distinguish between what was explicitly said in court and what is my own interpretation based on my notes and the wider context.

I have also deliberately left some details out. Court proceedings are public, but that doesn't necessarily mean that every detail discussed in court needs to be repeated publicly.

My interest here is in how Flowers and Jubair appeared to operate, and what we can learn from that, rather than in revisiting every detail of the incidents or victims.


The arrests, and the attacks recordings

One of the first things we learned was that the attacks had been recorded (the prosecution described this as "live streamed" - but hold that thought for now). The key point here is that the prosecution had access to many hours of video evidence showing what the attackers were doing.

I suspect that may have had some influence on the guilty pleas from both defendants.

My understanding was that much of the activity was carried out through infrastructure controlled by Flowers, and this is where he had recorded almost everything that took place. Law enforcement also had transcripts from chat logs (primarily Telegram) and on multiple occasions extracts from these were read out in court.

When Flowers was arrested by the NCA on 6 September 2024, he was, “mid-hack” against a US healthcare provider.

The laptop he was using was seized. He handed over the PIN, which enabled law enforcement to keep the system alive and gather further evidence.

There was very little evidence discussed during the hearing that had been obtained directly from Jubair's own systems. My assumption is that this was largely because most of the relevant evidence was present on the infrastructure and systems operated by Flowers.

The court also heard about Kasm. I have assumed this referred to Kasm Workspaces, a platform for streaming remote desktop environments. This raised an interesting possibility: when the prosecution referred to the attacks being “live-streamed”, perhaps this did not mean that the attacks were being broadcast publicly, but rather that the attackers were streaming the desktop environment they were using - this is almost certainly where the recordings came from. Those recordings must have made the prosecution's job considerably easier.


The infostealer pipeline

One of the things mentioned relatively early in the proceedings was the presence of infostealer logs dating back to 2022.

The barrister stated that Jubair had possessed logs since 2022, although I suspect that date was more likely to relate to the date the credentials were lifted. 

Infostealers came up several times during the proceedings.

My main takeaway was that Flowers' default approach to obtaining access was remarkably simple: Buy credentials.

Russian Market (a prolific marketplace for stolen credentials and browser logs) was mentioned, as was RedLine Stealer.

There was no suggestion that either defendant was actively involved in the infostealer ecosystem, other than as a customer. So, joining things together, in all likelihood, at least some of the credentials being purchased through Russian Market had originally been stolen by RedLine.

Stolen credentials appeared to be a key part of obtaining initial access.

In fact, after Flowers had been arrested, he apparently managed to acquire a contraband phone from another inmate. He then used it to contact people outside the prison in order to obtain further sets of credentials.

That says quite a lot about how important credentials were to his operation.


Getting into TFL

The details around the initial access into TFL were not entirely clear to me.

It sounded as though the credentials dating back to 2022 were not actually the initial route into the environment.

Instead, a server operated by a third-party development company who specialised in software used for complex infrastructure projects played a role. As a result of that compromise, 857 rows of user records were taken. Presumably, these included credentials, and it sounded as though they provided an initial foothold, or at least the motivation to further their attack into TFL's environment.

No additional information was shared about how that server was compromised, exactly what its function was, or whether it formed part of TFL's infrastructure or was entirely separate.

Some of the credentials taken from the compromised server were then used in attempts to access what was describes as "a remote access portal".

Based on information discussed later, I assume this was Citrix.

The credentials were valid, but they were not valid for that particular environment.

This is where the attack chain started to become particularly interesting.

The attackers then resorted to getting credentials reset through the service desk.

The evidence strongly suggested that neither Flowers nor Jubair personally carried out the vishing that resulted in these resets.

My interpretation was that they relied on their access to other members of Scattered Spider who could carry out this sort of social engineering on their behalf. This occurred several times during their activities, and were not always successful.

This section of the evidence wasn't particularly clear to me, but it sounded as though the reset may have related to the MFA associated with the account rather than the underlying password itself. It sounded to me like the credentials were valid it's just the MFA was getting in the way, so they needed a way around that, and calling servicedesk was the answer to that.

Once access to Citrix had been obtained, the attackers moved further into the environment.

There was some pivoting and privilege escalation, although these activities were not discussed in any real technical detail. This eventually led to access to systems including Azure and vCenter.

There wasn't actually a huge amount of discussion about what happened once they were inside, but it very much felt as though roles shifted at this point. My interpretation was that Flowers was acting as the initial access broker. Once he had obtained access, Jubair then took over much of the activity inside the environment.

There is very little that was discussed once initial access had been obtained that would not be out of place on a typical red-team exercise. There was no pre-planned route or activity, they could and would adapt to the challenges they faced including when their access to systems or accounts was disabled as part of the response.


The Oyster database

The Oyster database appeared to be a particular point of interest.

From what was discussed, it seemed to be targeted mostly out of pure curiosity although there was some interest in understanding how and where payment card details were stored. Flowers joked, I assume!, that he'd sell the database on BF (presumably breach forums) for $100.

Once they got to the database, there was interest in looking for details about celebrities in the database.

That was one of the things that struck me about the whole case - not everything appeared to be driven by a clearly defined criminal objective. In fact, a lot of it seemed to be curiosity. Some of it seemed to be opportunism. And some of it, frankly, sounded a bit like people exploring a system simply because they had managed to get into it.

One interesting aspect was the use of the victim's virtualisation environment to create and replicate systems.

Some of this was presented by the prosecution as intended to help evade detection. But, in my opinion, a lot of what was described sounded more like an attempt to overcome the practical challenges of exfiltrating data.

The Oyster database was the main piece of data taken. However, it sounded as though getting it out of the environment was not straightforward.

The attackers first replicated it to another internal system, before eventually replicating it out to their own server.

That may sound fairly mundane, but it is a useful reminder that exfiltration is not always as simple as “copy data and send it to an external server”.

Sometimes the attackers have to solve the same sorts of practical engineering problems that defenders do.


Mail forwarding and tunnels

There was also interest in accessing the accounts of specific senior employees.

Mail forwarding rules were set up, presumably to provide some level of persistence if credentials were later reset.

There was also some debate between the prosecution and defence over the use of tunnels. Nevertheless various tunnelling tools were mentioned, including ngrok and Teleport.

The prosecution suggested that these were being used for persistence in case the attackers were kicked out of the environment. The defence disagreed with some of the technical interpretation around this.

I don't think the exact purpose was ever entirely clear from the evidence I heard, but I suspect a combination of persistence and exfiltration paths.

TFL was informed of the compromise by the NCA which enabled TFL to undertake a number of containment activities, including disabling accounts and services.

No information was shared about how the NCA became aware of the activity but my suspicion would be that network telemetry or netflow may have played a role, but that is purely speculation based upon some of the evidence relating to the infrastructure that Flowers operated.


The server infrastructure

Flowers and Jubair faced multiple counts. The first related to TFL, while later counts related to two US healthcare providers.

A server referred to in court as the “B59 attack server” (The B59 name apparently came from its serial number) was a common factor across all of these incidents.

My understanding was that this server, hosted by Cherry Servers, was involved in the TFL attack - including accessing the third-party operated server - as well as the attacks against the two US healthcare providers. It was also seen connecting to Russian Market.

I don't know whether that connection was identified during the attacks or only later through forensic analysis, but my suspicion is that the infrastructure was already known about by the NCA.

What struck me was how much of the activity appeared to centre around one piece of infrastructure.

The same server was connected to multiple attacks, was used to interact with the marketplace where credentials were obtained, and appears to have acted as a central point from which activity was conducted.

This is the sort of thing that makes infrastructure intelligence interesting.

The individual victim environments may look completely separate. The activity inside each one may look different.

But sometimes the infrastructure connecting them joins it all together.

Throughout their activities, Flowers and Jubair communicated using Telegram. The court also heard about Telegram accounts which became inactive following the arrests, suggesting that they may have been operated by one of the defendants.


Choosing victims

One thing I don't remember being discussed was why these particular victims were selected.

The early evidence apparently acknowledged that it was not known how long some of the attacks had been planned.

For TFL, my interpretation was that the compromise of the third-party system led to an interest in TFL.

How that third-party system was initially compromised, and by whom, was not discussed.

The US healthcare providers offered a slightly more interesting insight.

When Flowers was arrested, he was in the middle of attacking one of the healthcare providers while also discussing the next potential victim.

There was some discussion about “getting a well-known store”, as one of the barristers put it (I will speculate no further on this one!).

However, Flowers was particularly interested in the second healthcare provider.

He had just obtained credentials for it and had already contacted someone to carry out the social engineering (vishing) component of the attack (presumably to reset MFA).

This is interesting because there are different categories of adversary.

Some attackers mass-target organisations in the hope of getting a foothold somewhere - they don't care who they hit, they are just after a victim - they may then use that access themselves or sell it onwards.

From everything I heard, Flowers did not appear to fit into that category.

Instead, he appeared to be looking to leverage access or credentials that someone else had already obtained.

In other words, he was a customer of initial access brokers.

He also appeared to be selective.

He was looking at what access was available to him and then choosing which victims to pursue.

That is a very different model from simply scanning the internet and attacking whatever happens to be vulnerable.

While he was in prison, analysis of the laptop he was using apparently showed an interest in organisations including the Crown Prosecution Service and Serco, which plays a prominent role in the UK prison service.

There was no suggestion that he had actually attacked either organisation. The prosecution had simply highlighted his interest in them.

Both Flowers and Jubair also appeared to be well aware that what they were doing was criminal.

Chat logs reportedly showed Jubair talking about having hacked an FBI agent in order to find out what information they had about him.

That, perhaps, tells you something about their mindset.


My main takeaway

I found the whole experience genuinely fascinating.

It is extremely rare for incidents like this to result in a prosecution.

The fact that this one did is a testament to what must have been a huge amount of work by law enforcement and the victims.

Having seen the size of the evidence bundles that the prosecution and defence were working from, I am sure that the morning I spent in court merely scratched the surface of the work that went into the case.

My main takeaway was the importance of harvested credentials.

Not just as one possible route into an organisation, but as something that appeared to shape the entire way these attacks played out.

It is easy, when we are hearing about new vulnerabilities and mass exploitation on an almost daily basis, to focus on attack surface, vulnerabilities, unpatched systems, the latest AI hype etc. But sometimes, “just logging in” is the easiest way in. And what this case has shown is that this is the way at least some of the operators of one of the most notorious and feared hacker collectives operate.

Even if MFA prevents the immediate use of a stolen password, where does that move the weakest link?

If the answer is the service desk, then how do you secure the service desk?

If the answer is account recovery, how do you secure account recovery?

If the answer is an identity provider, how do you detect and respond to suspicious activity there?

The more I think about the attacks described in court, the more I come back to that initial point:

The credentials were often already out there.

The attackers were not necessarily breaking in through a vulnerability.

They were finding credentials that someone else had stolen, overcoming the controls that stood between those credentials and the target environment, and then working from there.

That is something that will increasingly influence how I think about the defences we build.


A final note

Because recording court proceedings is not permitted in UK courts, this is based entirely on my handwritten notes and my recollection of what was said.

I have inevitably forgotten some details, and I may have misunderstood or misinterpreted others.

If you have additional insights or corrections relevant to this post, I would be very happy to hear them. You can email me at info[@]lab539.com.

And, shameless plug, AiTM Feed subscribers have access to our extensive infostealer database, which they can use to check their exposure.


What I Learned from Sitting in on a Scattered Spider Sentencing
John Fitzpatrick 24 July 2026
Share this post
Archive
When DMCA Comes Knocking - Part 2: The Sign-in Window That Isn't
Delving into a polished BiTB instance