Police Chiefs Cite TfL Hack to Push for Cybercrime Orders

▼ Summary
– Two young men, Owen Flowers and Thalha Jubair, were sentenced to five and a half years in prison for the 2024 Transport for London (TfL) hack, the UK’s largest cybercrime prosecution.
– Senior police officers argue the case supports the need for Cybercrime Risk Orders (CCROs), proposed civil measures to restrict suspected cybercriminals’ behavior before prosecution.
– The TfL hack cost an estimated £29m in damages and £10m in lost income, affecting between seven and 10 million people.
– Police say CCROs would have allowed earlier arrest of Flowers, who was 17 at arrest and breached bail, addressing gaps in current powers for underage offenders.
– City of London Police advocate for “digital prisons” to restrict offenders’ access to digital tools, while a consultant warns CCROs may be ineffective without skilled supervision.
Senior law enforcement officials are using the recent sentencing of two young men linked to the 2024 Transport for London (TfL) cyber-attack to make a strong case for introducing Cybercrime Risk Orders (CCROs) in the UK. The case, they argue, reveals critical gaps in existing legal powers, particularly when dealing with underage and high-risk offenders.
Owen Flowers, 19, and Thalha Jubair, 20, each received five-and-a-half-year prison sentences for carrying out unauthorised acts against TfL under Section 3ZA of the Computer Misuse Act (CMA) 1990. Both individuals are believed to be connected to Scattered Spider, a cybercriminal group responsible for major attacks in recent years, including incidents at Marks & Spencer and Co-op in 2025.
Following the sentencing at Woolwich Crown Court on July 16, Paul Foster, deputy director of the UK National Crime Agency (NCA) and head of its National Cyber Crime Unit, called the case “the largest cybercrime prosecution ever brought before the UK courts.” He described Scattered Spider as “the most significant cybercrime threat to the UK in recent years,” adding that any disruption to the group’s activity benefits national security. The attack cost TfL an estimated £29 million ($38 million) in damages and £10 million ($13.5 million) in lost income, affecting between seven and 10 million people across the UK.
Foster highlighted the “nearly two years of painstaking work” required by the NCA, the Crown Prosecution Service (CPS), the City of London Police, the FBI, Europol, and the Australian Federal Police. He noted that this investigation surpassed even the Lockbit ransomware takedown in 2024 in terms of complexity. The conviction of Flowers and Jubair is only the second under Section 3ZA of the CMA, which applies when an unauthorised act creates a significant risk of serious damage. The first conviction under this section involved a GCHQ employee who received a six-year sentence, but Foster said no meaningful comparison could be drawn between the two cases.
Foster argued that two major challenges during the TfL investigation were Flowers’ age (17 at the time of arrest) and the fact that he breached bail twice, once in October 2024 and again in May 2025. This is where Cybercrime Risk Orders, proposed during the May 2026 King’s speech and expected to be introduced in late 2027 or early 2028, become critical. “Complex cybercrime investigations can take many months, and during that time high-risk offenders, including those under 18, may continue to pose a significant risk of causing harm,” Foster explained. He noted that existing legal tools, such as serious crime prevention orders, do not apply to underage offenders, and some computer misuse offenses do not meet the serious crime criteria, leaving a gap in risk management.
CCROs are civil preventive measures designed to manage the behavior of individuals suspected of or convicted of cybercrimes. They would create a form of “digital prison” to disrupt illicit activities before further attacks occur, potentially allowing authorities to impose restrictions even before prosecution thresholds are met. Foster said CCROs “would have allowed us to arrest Flowers sooner” by acting on information from US or Australian partners. “The proposed CCROs would provide law enforcement with a proportionate preventative tool, similar in principle to sexual risk orders, to impose conditions that help protect the public and businesses while an investigation continues,” he said. Any breach of these conditions could result in criminal sanctions, including imprisonment, regardless of whether the underlying investigation has concluded.
However, Adam Pilton, a UK-based cybersecurity consultant and advisor, expressed caution. While he supports lowering barriers to prosecution and updating offenses to reflect modern cybercrime, he questioned the effectiveness of CCROs. “The people subject to these proposed CCROs are going to be highly skilled and capable of tricking most officers, effectively hiding their illegal activity. Unless the people checking compliance have genuine technical capability, these orders won’t be able to achieve what they promise,” he warned. “Before they come into force, we must think very carefully about what we’re trying to achieve and whether it will actually work.”
Ollie Shaw, Commander at the City of London Police, also welcomed the introduction of CCROs during a pre-sentencing briefing. “It’s increasingly apparent that traditional mechanisms for controlling offenders who work in a physical environment, like robbers or mobile phone thieves, are simply less effective for cyber offenders,” he said. Shaw advocated for the creation of “digital prisons” to better control damaging behavior, noting that traditional orders often impose physical restrictions that are easily bypassed with digital tools. He argued that restricting offenders’ access to digital tools and platforms, enforced in partnership with tech providers, with monitoring of account usage and device limits, would be essential. He acknowledged practical enforcement challenges, particularly around keeping digital devices out of prisons, but insisted that “these risk orders will need to be brought to life by guidance from policing and other parts of law enforcement and will need to be very restrictive in order to protect individuals.”
Pilton, however, dismissed the term “digital prison” as “headline-grabbing marketing terminology for a CCRO.” He argued, “There will be no digital prison. Anyone who’s determined to bypass these orders will do so, whether by tricking supervising officers or simply being more technically advanced. Restrictions can and will help manage risk, but only skilled supervision makes them meaningful.”
The legislation to reform the Computer Misuse Act is expected to be introduced in Parliament later this year as part of a broader national security package.
(Source: Infosecurity Magazine)
