Landmark TfL Cyberattack Spurs Calls for New Powers to Curb Digital Offending
Published on 07/21/2026 at 08:18 | Redaktion boerse-global.de
The sentencing of two young men over the largest cyberattack ever prosecuted in the UK has intensified pressure on the government to fast-track new legal powers designed to prevent similar breaches before they happen. Law enforcement agencies argue the case exposes critical gaps in the current system, particularly when it comes to managing technically skilled offenders before they cause widespread harm.
£39 Million in Damages and a Drive for Notoriety
Owen Flowers, 19, and Thalha Jubair, 20, were each handed five-and-a-half-year prison sentences for their roles in the hack of Transport for London (TfL) between late August and early September 2024. The breach caused an estimated £29 million in direct damages and a further £10 million in lost revenue.
The attack disabled 148 systems, including the Dial-a-Ride service and multiple mobile applications, and forced roughly 27,000 employees to reset their passwords. Investigators believe between 7 million and 10 million individuals were affected.
Prosecutors brought the case under Section 3ZA of the Computer Misuse Act and noted that the primary motivation was not financial gain but a desire for notoriety within the cybercrime community. The investigation involved international cooperation with the FBI, Europol, and the Australian Federal Police.
The Call for "Digital Prisons"
In the wake of the convictions, the National Crime Agency (NCA) and the City of London Police have renewed their push for Cybercrime Risk Orders (CCROs). These orders, formally announced in May 2026, are designed as a proactive tool to manage high-risk offenders by imposing strict limitations on their access to specific devices, platforms, and technical tools.
City of London Police Commander Ollie Shaw has described the proposed measures as creating "digital prisons" — a framework that would allow authorities to intervene earlier and monitor offenders long-term, particularly younger individuals who may develop sophisticated technical skills before they reach adulthood.
Proponents argue that CCROs would fill a legislative gap, offering a model similar to existing risk-order frameworks used for other types of high-risk criminal behaviour. However, some industry experts have questioned the technical feasibility of enforcing such restrictions against highly skilled individuals who may find ways to circumvent digital bans.
Timeline and Growing Cyber Threat
The rollout of CCROs is currently scheduled for late 2027 or early 2028. The push comes amid a sharp rise in cyber threats across the UK. Data from 2025 showed a significant increase in ransomware victims, with 7,831 reported cases compared to roughly 1,600 the previous year.
The government is also considering further measures, including potential bans on ransomware payments for organisations managing critical national infrastructure. The National Risk Register has been expanded to include specific threats related to data infrastructure and AI-accelerated cyberattacks.
While the sentencing of Flowers and Jubair marks a milestone for UK justice, authorities stress that the scale of the TfL incident — which could have resulted in costs exceeding £50 billion had the entire transport network failed — demands a shift from reactive prosecution to more robust, preventive digital oversight.
Disclaimer regarding our articles: No investment advice, no buy or sell recommendation. Information on prices, companies, and markets is provided without guarantee; changes are possible at any time. Stock market transactions can lead to substantial losses. Our articles are created and reviewed in whole or in part automatically with the support of AI.
