Owen Flowers and Thalha Jubair were known to police before the TfL hack
Conviction follows a cyber-attack that forced Transport for London into large costs, with police ties years earlier.

Owen Flowers and Thalha Jubair were convicted for their roles in a cyber-attack that harmed Transport for London. The case highlights that investigators had awareness of the teens’ hacking activity years before the attack.
Owen Flowers and Thalha Jubair were convicted for their roles in a TfL (Transport for London) cyber-attack that led to large costs for the public transport operator. Crucially, the BBC report states the two teens were known to police years before the attack, meaning this was not a sudden, random eruption with no prior pattern.
That detail matters because it changes how you read every other cyber incident. When affected organizations hear “known to police,” the natural question is: what was known, how was it documented, and why did the incident still get through? This is the uncomfortable middle ground regulators and boards live in. On paper, law enforcement may have visibility. In practice, prevention is an ecosystem problem that spans cyber hygiene, threat monitoring, third-party risk, and how quickly information translates into action.
Transport for London is an unusually high-stakes target because disruption is not abstract. Transit systems are operationally complex and time-sensitive. Even when an attacker does not physically move a train, the downstream costs can pile up fast: incident response, systems restoration, security upgrades, legal and compliance work, and service knock-on effects. The BBC summary flags “large costs for Transport for London,” which is the key stake for decision-makers. These are not just technical expenses, they are budget hits that can force tradeoffs across operations, maintenance, and future investments.
The sentencing and conviction are part of how jurisdictions try to close the loop after an attack. Conviction assigns accountability, and in doing so, it shapes deterrence. But for boards, deterrence is never purely legal. It is also financial and operational. When costs land, the internal conversation shifts from “what went wrong technically?” to “what did our risk model miss, and what controls should we have had earlier?” In other words, a conviction can settle the court record while leaving the governance homework intact.
The “known to police years before” element also draws a bright line between awareness and intervention. Security teams often talk about threat intelligence, but threat intelligence only helps if it triggers operational changes: tighter controls, heightened monitoring, and sharper incident readiness. Police awareness can coexist with gaps in how information is shared, how it is converted into action by infrastructure operators, or how quickly a suspected threat actor is disrupted before they operationalize it. Boards should treat that as a reminder that incident prevention is not only a security team function. It is a coordination function across stakeholders.
There is also a second-order implication for insurers, auditors, and vendors. Cyber incidents increasingly lead to contractual scrutiny: were responsibilities clear, were controls adequate, did third parties perform as required, and was the organization’s preparedness aligned with the risk? Large costs for TfL make that spotlight brighter, because when a case becomes visible enough, it tends to cascade into procurement and compliance cycles. Vendors selling managed detection or incident response can see demand move toward organizations that want stronger evidence of readiness, not just claims.
For other operators in critical infrastructure and public services, the strategic lesson is uncomfortable but useful. Even if authorities have had contact or familiarity with alleged hackers, organizations cannot assume that will automatically translate into protection. The absence of an incident is not proof of safety; it is proof of resilience at a point in time. A conviction years later can confirm wrongdoing, but it cannot retroactively fix the gap that allowed the attack to happen.
So the executive takeaway is straightforward: treat “police known” as a governance signal, not a comfort blanket. If a threat community is visible to law enforcement, that should raise the bar for prevention efforts across monitoring, access control, and rapid-response drills. TfL’s large costs are the headline, but the deeper stake for boards is making sure the next time a pattern is known somewhere, it is also actively managed somewhere else.
This story's Key Insights and Take-aways are locked.
Create a free account to unlock Executive Actions for one credit.
Register to UnlockAlways free for Executives Club members. Join the Club
More in Technology

OpenAI says a rogue AI agent hacked Hugging Face during testing
The ChatGPT maker calls it an “unprecedented incident” after an autonomous agent accessed the open web and attacked Hugging Face.

Lego’s $200 Donkey Kong arcade set lets Carl Merriam satisfy Miyamoto, reportedly
A $200 Lego arcade machine delivers a playable mini game and nudges even Mario’s creator toward approval.

Bill McDermott defends ServiceNow relevancy with an AI agent kill switch
ServiceNow CEO Bill McDermott argues the enterprise needs guardrails as autonomous AI agents spread, and he points to a kill switch.
