GKRootWire
Cloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping AgentsCloud & Sysadmin Microsoft Confirms Preview Update Wipes Out Desktop SettingsAI Nvidia to Acquire Hugging Face for $12.9 BillionDev Tools A Deep Dive Into Intrusive Linked ListsGadgets DJI's Romo 2 Robovac Adds Local-Only Mode After Privacy ScareAI Nvidia Reportedly Moves to Acquire Hugging FaceAI Anthropic Launches Claude Tools for AI Shopping Agents
Security

Two Scattered Spider Members Plead Guilty Over TfL Cyberattack

The pair admitted their roles just as their six-week UK trial was set to begin, closing the loop on the August 2024 hack that disrupted London's transit systems.

Two men connected to the notorious Scattered Spider hacking collective have pleaded guilty in a UK court to charges tied to the August 2024 breach of Transport for London, the agency that runs the city's buses, subways, and other public transit infrastructure. The plea came unexpectedly on the very first day of what prosecutors and defense attorneys had prepared to be a lengthy, six-week courtroom battle.

Scattered Spider has built a reputation as one of the more disruptive and technically savvy cybercrime crews in recent years, known for social-engineering attacks that trick help desks and employees into handing over access credentials. The TfL incident forced the agency to shut down or restrict several internal systems, causing weeks of operational headaches even though core transit services managed to keep running.

With the guilty pleas now entered, the case moves toward sentencing rather than a drawn-out trial, sparing the court system the time and expense of hearing weeks of testimony and evidence. It also marks one of the more concrete legal outcomes so far in the ongoing effort by UK and US authorities to identify and prosecute members of the loosely organized but highly effective hacking group.

Why it matters: Scattered Spider has hit major companies and public agencies alike using low-tech social engineering rather than exotic malware, proving that human trust—not just software vulnerabilities—is often the weakest link. A successful prosecution like this sends a signal that these attacks carry real legal consequences, which may give pause to other members of the loosely affiliated group, but it's unlikely to stop the underlying tactics from spreading to copycat crews.

Sources: Krebs on Security