Pour garantir la meilleure expérience de navigation, veuillez activer JavaScript dans votre navigateur web. Sans cela, de nombreuses fonctionnalités du site seront inaccessibles.


Tests totaux:
485,773,462
737,046
130,956

Scattered Spider Hackers Jailed For TfL Cyber-Attack

23 juillet 2026

Read also: Germany, US dismantle Kratos phishing service behind nearly 15K campaigns monthly, a man arrested for uploading malware games to Steam, and more.

Vues: 1.7k Temps de lecture:3 min.

Scattered Spider Hackers Jailed For TfL Cyber-Attack

Scattered Spider hackers jailed for TfL cyber-attack

Two members of the Scattered Spider hacking group have been sentenced to five and a half years in prison for the 2024 cyber-attack on Transport for London (TfL).

Thalha Jubair, 20, and Owen Flowers, 18, admitted breaking into TfL's network. The attack disrupted services, exposed customer data, and cost TfL about £29 million to recover.

As a result of the attack, around 27,000 employees had to reset their passwords in person, and 148 internal systems were affected. Some Oyster card refunds were delayed, and new Oyster photocard applications for children were temporarily paused.

The National Crime Agency said the damage could have been much worse if the hackers had shut down London's transport system, with losses estimated at up to £56 billion.

Officials said Jubair and Flowers were leading members of the Scattered Spider cybercrime group, which has been linked to attacks on businesses in the UK and the United States.

German and US authorities dismantle the Kratos phishing platform

Authorities in Germany and the United States have taken down Kratos, a phishing-as-a-service (PhaaS) platform used by cybercriminals worldwide.

As part of the operation, authorities seized more than 200 servers and arrested the platform’s operator in Indonesia. Authorities estimate the administrator earned at least €300,000 ($342,000) in subscription fees from the service since 2024.

The investigation was led by Germany's Federal Criminal Police Office (BKA) and the Frankfurt Prosecutor General's Office, with assistance from US law enforcement.

According to the BKA, Kratos was one of the most widely used phishing services, with victims identified in 35 countries, mainly across Europe and the United States. Authorities believe more than 1,800 criminals used the platform to launch about 15,000 phishing campaigns every month.

The service allowed users to create fake Microsoft login pages designed to steal email addresses and passwords. Stolen accounts were then used in other cybercrime schemes, including business email compromise (BEC), data theft, account takeovers, and phishing attacks against victims' contacts.

21-year-old arrested for uploading malware games to Steam

The FBI has arrested a 21-year-old man from Florida, the US, for allegedly uploading fake games to Steam that installed malware on players' computers.

Prosecutors say Zyaire Wilkins and several unnamed partners published games, including BlockBlasters, Dashverse, Lampy, Lunara, and PirateFi, over the past two years. The games installed malware that stole passwords, personal information, and cryptocurrency.

Authorities say the malware infected around 8,000 computers and led to the theft of at least $220,000 from about 80 cryptocurrency wallets. The games were reportedly promoted on Discord, LinkedIn, and Telegram.

The FBI said it traced cryptocurrency used to buy gift cards, including Uber Eats gift cards linked to an account that made deliveries to Wilkins' home. Agents later searched his house and seized electronic devices and digital wallets. According to the complaint, Wilkins refused to answer investigators' questions.

Newsletter ImmuniWeb

Recevez Cybercrime Weekly, des invitations à nos événements et webinaires, directement dans votre boîte de réception:


Privé et confidentielVos données resteront privées et confidentielles.

The US seizes over 1,000 illegal sports streaming websites

The US Justice Department has seized more than 1,000 websites and blocked 1,970 domains that were illegally streaming FIFA World Cup 2026 matches.

The action was part of Operation Offsides, an international effort led by US law enforcement with support from FIFA, the Alliance for Creativity and Entertainment (ACE), and entertainment companies. Authorities worked with partners in 54 countries to identify and shut down the illegal websites.

Officials also carried out Operation Red Card, which targeted piracy networks in several Latin American countries. During the second phase of the operation in Colombia, police arrested four members of the Los Ciberinfiltrados cybercrime group, accused of selling pirated streaming services since at least 2024.

In a June crackdown, Mexican authorities shut down 44 domains linked to the PirloTV streaming platform and a large sports piracy network. The affected websites attracted more than 950 million visits each year.

In a separate announcement, the US authorities said that they seized more than $25 million in cryptocurrency linked to cryptocurrency investment schemes. As part of the investigations, police identified multiple laundering networks and thousands of victims worldwide.

ImmuniWeb peut vous aider à prévenir les violations de données et à respecter les exigences réglementaires.

Pakistan nabs a cybercrime gang targeting foreign embassies

Pakistan's National Cyber Crime Investigation Agency (NCCIA) has reportedly arrested 12 members of a cybercrime gang accused of hacking the contact numbers and data of several foreign embassies, including those of Saudi Arabia, Germany, and Italy.

The group had been active since 2019 and targeted both Pakistani and foreign nationals through online scams.

According to officials, the gang hacked embassy contact numbers and redirected calls to numbers controlled by the suspects. During the raids, police officers recovered fake appointment letters, mobile phones, and other digital evidence.

Authorities said the suspects created fake embassy websites that copied the online systems of diplomatic missions to trick victims. The gang also hired people with different language skills to help carry out the scams. A Singapore police uniform was among the items recovered during the operation.

Prochaines étapes:

Parlez à un expert