HomeRisk ManagementsPolice Chiefs Reference TfL Hack to Advocate for Cybercrime Risk Orders

Police Chiefs Reference TfL Hack to Advocate for Cybercrime Risk Orders

Published on

spot_img

Following the recent sentencing of two young men for the significant 2024 hack of Transport for London (TfL), senior police officials in the UK have underscored the need for enhanced legal powers, particularly advocating for Cybercrime Risk Orders (CCROs). The case has reignited discussions about the adequacy of current legal frameworks in addressing the evolving landscape of cybercrime.

Owen Flowers, aged 19, and Thalha Jubair, 20, received prison sentences of five and a half years each after being found guilty of unlawful actions against TfL, in violation of Section 3ZA of the UK’s Computer Misuse Act (CMA) of 1990. Authorities believe both individuals are associated with a notorious cybercriminal group called Scattered Spider, which has been implicated in significant cyber-attacks over recent years, including incidents targeting major businesses like Marks & Spencer and Co-op in 2025.

Paul Foster, deputy director of the UK National Crime Agency (NCA) and head of its National Cyber Crime Unit, articulated the gravity of the situation during a briefing, proclaiming the case as “the largest cybercrime prosecution ever brought before the UK courts.” Estimates indicate the TfL hack incurred damages around £29 million (approximately $38 million) and resulted in £10 million (roughly $13.5 million) in lost revenue. The attack adversely affected the daily lives of between seven and ten million individuals across the UK.

Foster emphasized the extensive and complex nature of the investigations, which spanned nearly two years and involved collaboration among several law enforcement agencies, including the Crown Prosecution Service (CPS), City of London Police, the FBI, Europol, and the Australian Federal Police. This collaborative effort exemplifies the international dimension of modern cybercrime and the challenges law enforcement faces in addressing it. During his address before the sentencing, Foster highlighted that this investigation exceeded even the intricate nature of Operation Cronos, the takedown of the Lockbit ransomware group in 2024.

The conviction of Flowers and Jubair marks only the second instance where Section 3ZA of the CMA was applied. Foster conveyed the seriousness of this section, which addresses unauthorized acts that have the potential to cause significant damage, noting that intent or recklessness regarding potential harm is a critical element of this clause. The first conviction under this particular provision involved a Government Communications Headquarters (GCHQ) employee who was sentenced to six years in prison.

Foster pointed out notable complexities in the case, including Flowers’s young age—he was just 17 at the time of his arrest—and his subsequent breaches of bail on two occasions. This highlights a significant gap in existing legal powers, particularly regarding those under 18 who engage in cybercrime. He articulated how these gaps hinder law enforcement’s ability to manage high-risk offenders effectively, arguing for the urgent implementation of proposed Cybercrime Risk Orders.

Introduced during the King’s speech in May 2026, these CCROs represent a proactive approach to cybercrime prevention. They intend to serve as a civil remedy to enable authorities to manage the behaviors of individuals suspected of or convicted for cyber offenses. Essentially, they could create a form of “digital prison,” pre-emptively disrupting illicit activities and allowing for earlier arrests of potential offenders before formal prosecution thresholds are met.

Foster elaborated on the advantages of these orders, mentioning that they could have facilitated an earlier arrest of Flowers by acting on intelligence from international partners. He likened the proposed CCROs to sexual risk orders, arguing they would offer law enforcement a necessary tool to impose conditions that protect the public and businesses during ongoing investigations. With active monitoring, violations would result in criminal sanctions that could include imprisonment, irrespective of the completion of the underlying investigation.

However, not all experts in cybersecurity share a consensus on the proposed reforms. Adam Pilton, a UK-based cybersecurity consultant, expressed skepticism about the effectiveness of CCROs, suggesting that individuals subject to these orders might possess sophisticated skills to evade detection and compliance checks, thus rendering the orders ineffective. He emphasized the necessity for genuine technical capability among officers monitoring compliance to ensure meaningful enforcement.

Meanwhile, Ollie Shaw, a Commander at the City of London Police, echoed support for the introduction of CCROs, asserting that conventional mechanisms for managing offenders are inadequate for those engaged in cybercrime. He proposed the establishment of digital prisons to control and monitor the actions of offenders like Flowers and Jubair more effectively. Shaw criticized existing measures, suggesting that they focus too heavily on physical restrictions while cybercriminals can operate from anywhere with digital access.

In contrast, Pilton criticized the term “digital prison,” labeling it as sensationalist marketing for a promising yet potentially flawed CCRO initiative. He cautioned that any cybersecurity framework needs to be critically assessed for its intended outcomes, arguing for careful consideration of practical applications.

As legislative discussions surrounding the reform of the CMA progress—anticipated to be introduced in Parliament as part of broader national security initiatives—law enforcement agencies continue to grapple with the challenges posed by digital offenders. The call for CCROs illustrates an urgent need to adapt legal mechanisms to meet the realities of modern cybercrime, while simultaneously ensuring that new measures effectively balance prevention and individual rights.

Source link

Latest articles

Russian Hacker Transforms Jailbroken Claude into Penetration Testing Platform

Rapid Evolution of Cybercrime: From Tutorial to Commercial Product In a remarkable instance of the...

Cyber Briefing – July 21, 2026 – CyberMaterial

Cybersecurity Updates: Recent Threats and Policies Recent developments in cybersecurity are raising alarms across various...

US Transfers AI Governance Responsibilities to Others

US Government Lags Behind in AI Governance as China and Major Tech Firms Advance As...

CISA Warns of Targeted Attacks by Russian FSB Hackers on Critical Infrastructure Routers

The Cybersecurity Threat Landscape: Addressing Vulnerabilities and Protecting Critical Infrastructure The Russian Federal Security Service...

More like this

Russian Hacker Transforms Jailbroken Claude into Penetration Testing Platform

Rapid Evolution of Cybercrime: From Tutorial to Commercial Product In a remarkable instance of the...

Cyber Briefing – July 21, 2026 – CyberMaterial

Cybersecurity Updates: Recent Threats and Policies Recent developments in cybersecurity are raising alarms across various...

US Transfers AI Governance Responsibilities to Others

US Government Lags Behind in AI Governance as China and Major Tech Firms Advance As...