GKRootWire
AI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI WorkflowsAI xAI Publishes Details on Its Grok Web CrawlerAI Why 'Human-in-the-Loop' Might Have It BackwardsDev Tools Modular Ships Mojo 1.0, Marking the Language's Production DebutAI OpenAI's Head of Ethics Exits Less Than a Year Into the JobAI Researchers Show How to Extract Hidden Reasoning from Proprietary LLM APIsAI Nvidia Debuts Nemotron 3.5 Lightning and NeMo Switchyard for Local AI Workflows
Security

Two Scattered Spider Members Plead Guilty Over TfL Cyberattack

The pair admitted their roles just as their six-week UK trial was set to begin, closing the loop on the August 2024 hack that disrupted London's transit systems.

Two men connected to the notorious Scattered Spider hacking collective have pleaded guilty in a UK court to charges tied to the August 2024 breach of Transport for London, the agency that runs the city's buses, subways, and other public transit infrastructure. The plea came unexpectedly on the very first day of what prosecutors and defense attorneys had prepared to be a lengthy, six-week courtroom battle.

Scattered Spider has built a reputation as one of the more disruptive and technically savvy cybercrime crews in recent years, known for social-engineering attacks that trick help desks and employees into handing over access credentials. The TfL incident forced the agency to shut down or restrict several internal systems, causing weeks of operational headaches even though core transit services managed to keep running.

With the guilty pleas now entered, the case moves toward sentencing rather than a drawn-out trial, sparing the court system the time and expense of hearing weeks of testimony and evidence. It also marks one of the more concrete legal outcomes so far in the ongoing effort by UK and US authorities to identify and prosecute members of the loosely organized but highly effective hacking group.

Why it matters: Scattered Spider has hit major companies and public agencies alike using low-tech social engineering rather than exotic malware, proving that human trust—not just software vulnerabilities—is often the weakest link. A successful prosecution like this sends a signal that these attacks carry real legal consequences, which may give pause to other members of the loosely affiliated group, but it's unlikely to stop the underlying tactics from spreading to copycat crews.

Sources: Krebs on Security