Scattered Spider Members Plead Guilty on Trial Day One as SLH Alliance Escalates
Two Scattered Spider members pleaded guilty on day one of their UK trial for the Transport for London attack. The group has since evolved into the SLH alliance. For GCC enterprises in hospitality, telecoms, and financial services, the threat is immediate and operational.

Corporate IT help desk workstation at night with an incoming authentication reset request on screen, representing the social engineering techniques used by Scattered Spider to bypass enterprise MFA through help desk impersonation
Two key members of the Scattered Spider cybercriminal group pleaded guilty on the first day of what was expected to be a six-week trial in the United Kingdom, with Thalha Jubair, 20, of East London and Owen Flowers, 18, of Walsall admitting to conspiring to commit unauthorised acts against Transport for London computer systems. The guilty pleas, reported by Krebs on Security on 25 June 2026, come as the group has simultaneously escalated its operational capabilities through a formal alliance with LAPSUS$ and ShinyHunters, creating an extortion infrastructure that security researchers describe as the most industrialised social engineering threat currently active.
What Scattered Spider Is and How It Operates
Scattered Spider, also tracked as UNC3944, Octo Tempest, and Muddled Libra, is a loosely affiliated cybercriminal group of primarily English-speaking young adults whose defining capability is not technical sophistication but social precision. The group gains initial access almost exclusively through vishing, the use of voice calls to impersonate employees or IT staff, combined with SMS phishing and SIM swapping. By calling corporate help desks, citing urgent travel scenarios or account lockouts, and providing personal data harvested from public sources or previously purchased credential dumps, the group convinces IT staff to reset passwords or bypass multi-factor authentication for accounts they do not own.
That entry vector, which produces no malware signatures, no exploit code, and no detectable network traffic until the attacker is already authenticated, allows Scattered Spider to bypass the technical defences that consume the majority of enterprise security budgets. Once inside, the group moves rapidly: Active Directory reconnaissance using ADExplorer and ADRecon, NTDS.dit extraction for bulk password hash access, creation of new virtual machines via VMware vCenter to enable persistent access, and ultimate deployment of ransomware to ESXi hypervisor infrastructure. Recent campaigns have targeted VMware ESXi specifically because encrypting the hypervisor layer simultaneously disables every virtual machine running on the host, maximising operational disruption.
The SLH Alliance and What It Means
The guilty pleas come as Scattered Spider has formalised its alliance with LAPSUS$ and ShinyHunters under the Scattered LAPSUS$ Hunters (SLH) brand. Researchers describe this as a criminal supergroup with centralised infrastructure for ransomware deployment, data leak sites, and target reconnaissance, enabling smaller and less technically capable affiliate crews to plug into proven operational capabilities. The 2025 wave of UK retail attacks against Marks and Spencer, Co-op, and Harrods was the proof-of-concept run for this model at scale. AI voice cloning is now an active, deployed capability within the SLH ecosystem, not a theoretical future tool, meaning that the already-effective vishing attack chain now benefits from voice synthesis technology that can replicate the vocal patterns of specific known individuals.
The group's total take on extortion demands exceeds $115 million across confirmed victims, and law enforcement has consistently found that arrests of individual members do not materially disrupt operations. When senior members were sentenced in 2025, the group responded by expanding its infrastructure, not contracting. Seven arrests in 2025 and 2026, including the April 2026 guilty plea of Tyler Buchanan in the United States and the current UK trial, have produced convictions but not operational degradation.
Why GCC Enterprises Are Directly Exposed
Scattered Spider's target sector list maps almost precisely onto GCC enterprise activity. The group has systematically targeted hospitality and gaming, financial services, insurance, telecommunications, business process outsourcing, technology and cloud services, retail, manufacturing, and aviation. Every one of those verticals has significant GCC representation. Dubai's hospitality and tourism sector, the Gulf's telecoms and financial services industries, and the region's growing BPO sector are all within the documented targeting scope. The group's preference for English-speaking target environments makes the GCC's multilingual, internationally staffed enterprises particularly relevant.
The BFSI sector in the Gulf faces compounded exposure because financial institutions maintain large IT support operations with authority to reset credentials and bypass authentication controls, precisely the function Scattered Spider exploits. A single help desk call producing an MFA reset for a privileged account is sufficient initial access. From there, the group's documented capability to escalate to ESXi ransomware deployment can disable an organisation's entire virtualised infrastructure within hours.
What GCC Security and IT Teams Must Do
Help desk identity verification is the primary control gap. Scattered Spider operators accurately answer standard verification questions because they source the relevant personal data in advance. Verification procedures that rely on knowledge factors available in breach databases, such as date of birth, employee ID, or last four digits of a phone number, do not constitute adequate identity assurance against this threat actor. Physical presence verification, supervisor authorisation chains for MFA resets, and callback verification to numbers on record are the procedural controls that close this specific gap.
Organisations should deploy phishing-resistant MFA using hardware tokens or passkeys on all privileged accounts. Conducting internal vishing simulations specifically replicating the Scattered Spider methodology against IT help desk staff is not optional for organisations in the documented target sectors. Monitoring Microsoft Entra ID, SSO, and VDI logs for anomalous authentication patterns, unexpected virtual machine creation in vCenter environments, and new SSH keys or API tokens on administrative accounts should be part of the standard detection programme across every GCC enterprise in the group's target industries.
Omar Al-Hakeem
Senior Cyber Threat Analyst | MENA RegionOmar Al-Hakeem is a cybersecurity researcher specializing in threat intelligence, ransomware trends, and nation-state activity across the Middle East and North Africa. With over 12 years of experience in SOC operations and incident response, he provides deep technical breakdowns of emerging attacks and regional cyber risks. At MENA Cyber Wire, Omar focuses on real-world threat analysis and actionable defense strategies for enterprises and startups.