← Back to Library

The teenage millionaire hacker from tower hamlets who took down TfL

The true story behind London's worst cyberattack isn't about a lone genius in a hoodie; it's about a teenager whose downfall came from a simple craving for takeaway food. Michael Macleod's reporting peels back the layers of the Scattered Spider gang to reveal how a 20-year-old from Tower Hamlets paralyzed a major transport network not through code, but by failing to separate his criminal infrastructure from his daily life. This piece matters because it exposes the terrifying reality that modern cybercrime is often driven by social engineering and youthful recklessness rather than sophisticated state-level weaponry.

The Human Error Behind the Chaos

Macleod anchors the narrative in a strikingly mundane detail: the moment of arrest wasn't triggered by a digital forensics breakthrough, but by a food delivery order. "It was the takeaway order to his family's Tower Hamlets flat that proved to be Thalha Jubair's undoing," Macleod writes, illustrating how the defendant's attempt to use a cryptocurrency wallet for a simple lunch purchase linked him directly to millions in stolen ransom funds. This framing is effective because it demystifies the "cyber mastermind" archetype, replacing it with a portrait of human error that feels both relatable and catastrophic.

The teenage millionaire hacker from tower hamlets who took down TfL

The author details how Jubair, despite using amnesiac operating systems and virtual private networks to mask his tracks, made the fatal mistake of buying gift vouchers for an unnamed food delivery service from the same server used to store illicit Bitcoin. "This was one of the clues which led to Jubair's arrest," Macleod notes, highlighting a critical vulnerability in the operational security of even high-profile criminal groups. The argument here is that the digital and physical worlds are inextricably linked; a hacker cannot exist entirely in the ether if they still need to eat.

"He kept to himself... You wouldn't see him in the park."

Macleod contrasts this digital disruption with Jubair's quiet, unassuming presence in his neighborhood, noting that neighbors were largely unaware of the chaos emanating from the 22-storey tower block where he lived. This juxtaposition serves to underscore the invisibility of modern cyber threats; they often originate from ordinary domestic spaces rather than shadowy server rooms. However, one might argue that focusing too heavily on the "ordinary" nature of the hacker risks underestimating the technical sophistication required to coordinate with a group like Scattered Spider, which has targeted major retailers and infrastructure globally.

The Mechanics of Social Engineering

The piece excels in explaining how Jubair moved from gaming platforms to high-stakes fraud without writing complex code. Macleod explains that Jubair's primary tool was "SIM-swapping," a technique where an individual's mobile number is redirected to a hacker, allowing them to intercept authentication codes. "It's common [for hackers] to be recruited in their early teens on gaming platforms like Minecraft and Roblox," cyber security reporter Brian Krebs tells the author, tracing the pipeline from childhood play to criminal enterprise. This context is vital for understanding the demographic shift in cybercrime, where young offenders leverage social manipulation over technical brute force.

The coverage details how Jubair allegedly ran a Telegram channel called Star Chat, selling these services and targeting employees at major US phone networks like T-Mobile. Macleod writes that "over seven months in 2022, Star Chat gained access to T-Mobile over 70 times," demonstrating the scale of the operation. The author effectively uses these specific numbers to convey the systematic nature of the attacks, moving beyond the idea of a lone wolf to a coordinated criminal ecosystem.

"Parents know I simswap. So, if they see [that] they think I'm hacking."

This quote from Jubair's internal messages reveals a chilling awareness of his dual life and the lengths he went to hide his activities from his family. Macleod uses this to illustrate the psychological compartmentalization required for such crimes, yet also points out the fatal flaw: the inability to fully disconnect the criminal enterprise from personal identity. The article suggests that while Jubair was clever enough to evade detection for a time, his reliance on social engineering left a trail of human interactions that digital encryption could not hide.

Institutional Vulnerability and Recidivism

The reporting shifts to the impact on London's infrastructure, painting a grim picture of the aftermath. "One TfL executive described the behind-the-scenes situation... as 'an utter shitshow'," Macleod quotes, capturing the sheer disorganization that ensued when hundreds of thousands of travel card holders were affected and booking systems for disabled passengers were shut down. This is not just a technical failure; it is a humanitarian one, leaving vulnerable populations stranded. The author notes that Sadiq Khan later admitted some passengers would never be refunded, highlighting the long-term financial and social costs of the attack.

Macleod also addresses the disturbing timeline of Jubair's criminal career, noting he was sentenced to an 18-month youth rehabilitation order in December 2023 for previous offenses, including hacking into Rockstar Games as part of the Lapsus$ group. "The puzzle is that Jubair 'embarked on this further round of hacks' after sitting through proceedings," Professor Peter Sommer tells the author. This raises a critical question about the efficacy of current rehabilitation measures for young cybercriminals. The article implies that the threat from English-speaking countries is growing, as Paul Foster of the National Crime Agency warns, but it stops short of proposing concrete policy solutions to prevent recidivism among this specific demographic.

"Even his neighbours didn't know what was going on."

This observation by a resident drives home the isolation of Jubair's world and the failure of community awareness to detect such high-level criminal activity. Macleod argues that this invisibility is part of the problem; the very anonymity that allows these hackers to operate also prevents early intervention. Critics might note that the article focuses heavily on the individual's psychology while giving less weight to the systemic failures in corporate cybersecurity that allowed a single compromised employee account to bring down an entire transport network.

Bottom Line

Macleod delivers a compelling narrative that humanizes a complex cyber threat, proving that the most sophisticated attacks often hinge on the simplest human errors. The strongest part of this argument is its refusal to glorify the hacker, instead presenting a cautionary tale about the collision of digital ambition and physical reality. Its biggest vulnerability lies in not fully exploring how institutions like TfL can better protect themselves against social engineering, leaving readers with a vivid picture of the problem but fewer tools for prevention.

Deep Dives

Explore these related deep dives:

  • Scattered Spider

    While the article names this cybercrime group, a deep dive reveals its unique operational model of recruiting teenage hackers via Discord to exploit human psychology rather than just technical vulnerabilities.

  • Computer Misuse Act 1990

    Understanding this specific UK legislation is crucial because its age and lack of provisions for modern ransomware tactics directly influenced the prosecution's strategy and the £39m damage assessment in Jubair's case.

  • Limbus Company

    The article mentions Jubair used these to cover his tracks, but exploring this concept explains how booting from volatile memory allowed him to erase forensic evidence instantly after each attack session.

Sources

The teenage millionaire hacker from tower hamlets who took down TfL

by Michael Macleod · London Centric · Read full article

It was the takeaway order to his family’s Tower Hamlets flat that proved to be Thalha Jubair’s undoing.

Last month the young Londoner pleaded guilty to taking down Transport for London’s computer systems in one of the worst cyberattacks in British history, an event which brought months of chaos to the capital’s transport network in late 2024.

Jubair thought he had covered his tracks through an elaborate system of amnesiac operating systems and virtual private networks. These not only allowed him to cause mass chaos in his home city of London but also allegedly enabled him to extort tens of millions of dollars in ransom payments from US companies.

Then he got hungry.

According to US prosecutors, the then-teenage Jubair made the mistake of deciding to order a takeaway. To do this, he bought gift vouchers for an unnamed food delivery service using a cryptocurrency wallet. This wallet hosted on the same server he and his fellow hackers allegedly used to store tens of millions of dollars worth of Bitcoin they’d taken in ransoms paid by major US companies.

Jubair then had the takeaways delivered to the flat where he lived with his parents, which is located in a high-rise block next to a Met Police call handling centre near Bow Road tube station in east London.

This was one of the clues which led to Jubair’s arrest last September, after a major investigation by the National Crime Agency, City of London Police, and the FBI. He was charged with committing unauthorised acts against TfL under the Computer Misuse Act, causing at least £39m in damage to TfL and months of disruption to the capital’s transport network. London Centric was in Woolwich Crown Court last month as the unassuming 20-year-old, who appeared awkward in glasses and a badly fitting grey suit, unexpectedly changed his plea to guilty at the last minute, alongside his Walsall-based co-defendant Owen Flowers.

So who is the TfL hacker? By attending court appearances, reviewing Telegram messages, and interviewing cybersecurity experts, London Centric has pieced together Jubair’s journey from a Roblox-playing east London child to a criminal mastermind who allegedly extorted tens of millions of pounds from his bedroom as part of the Scattered Spider cybergang.

His is the story of a very modern London adolescence.

The flight risk who took down a transport system

It was by compromising the account of a single employee that Jubair ...