ProBackend
active vulnerability exploitation
9 hours ago9 min read

AI Cybersecurity Threats: The Human Layer Is the Weak Link

Two Scattered Spider members sentenced to 5.5 years for TfL cyberattack—exposing how AI-enhanced social engineering is the real AI cybersecurity threat.

The Price of a Click

Thalha Jubair was 18 when he started selling fake emergency data requests using hacked police email accounts. Owen Flowers was 16 when he first cracked a T-Mobile employee portal to steal MFA codes. Neither had a criminal record. Neither had ever held a job. But they had something far more valuable: access.

By the time they were arrested in September 2024, they’d helped steal over $115 million from hospitals, transit systems, and retailers across three continents. And they did it not with malware, not with zero-days, but by calling people on the phone and pretending to be IT.

Today, they’re each serving five years and six months in a UK prison. The judge didn’t sentence them for hacking. He sentenced them for being the hack.

This isn’t just a story about cybercrime. It’s about how AI-driven threat actors—real, human ones—are rewriting the rules of security. Not by writing code, but by weaponizing trust.


The TfL Breakdown: When a Transit System Became a Target

On August 31, 2024, Transport for London woke up to a nightmare. Dial-a-Ride couldn’t schedule rides. Concessionary card systems crashed. Contactless ticketing went dark. Twenty-seven thousand employees were locked out of their systems. They had to show up in person—no emails, no remote resets—to re-authenticate.

The attack didn’t just disrupt services. It shattered the illusion that public infrastructure was somehow immune.

The attackers didn’t need to breach firewalls. They didn’t need to exploit a CVE. They just needed to call a TfL helpdesk agent, say they were from corporate IT, and ask for a password reset. The agent, under pressure, complied. That one click unlocked 148 systems.

TfL lost £29 million in recovery costs. But the real cost? £56 billion—the estimated economic impact if the entire network had been shut down for a week. That’s not a ransomware number. That’s a national infrastructure number.

And it was all pulled off by two teenagers with Telegram accounts and a knack for sounding convincing.


The Scattered Spider Playbook: Social Engineering as a Service

Scattered Spider isn’t a gang. It’s a franchise.

At its core, it’s a network of young, tech-savvy operators who’ve turned social engineering into a scalable business. Jubair ran a Telegram channel called Star Chat, where he sold SIM-swapping services to anyone who could pay in Bitcoin. Flowers specialized in healthcare breaches—hacking Sutter Health and SSM Health Care while still in high school.

They didn’t need to be geniuses. They just needed to be convincing.

In 2022, Jubair led a mass SMS phishing campaign that compromised employees at LastPass, DoorDash, Mailchimp, and Signal. How? He sent texts that looked like they came from internal IT teams: "Urgent: Your MFA token expired. Click here to reset." The links led to fake login pages. The credentials went straight to his server.

This wasn’t malware. It was behavioral exploitation. And it worked because security teams still think in terms of systems, not people.

The same tactic took down Harrods, Marks & Spencer, and Co-op in mid-2025. Same playbook. Same team. Just different targets.

What’s terrifying isn’t the scale. It’s the simplicity. No exploit kits. No custom payloads. Just a phone call, a fake email, and a little charisma.


The Human Firewall: Why Security Teams Are Losing

Here’s the uncomfortable truth: the most dangerous threat actor isn’t a botnet. It’s a 19-year-old who can sound like your boss.

CISOs spend millions on EDR, SIEM, and AI-powered threat detection. But they still don’t train their staff to question a request that says, "I’m from IT, I need this now."

The NCA’s Deputy Director Paul Foster said TfL’s early cooperation was key to the conviction. That’s true. But it’s also a damning indictment. Why did it take a national crisis to get an organization to talk to law enforcement?

We’ve built walls around our networks, but left the front door wide open—and then blamed the hackers for walking through.

The truth? We didn’t fail because we lacked tools. We failed because we assumed our people were the solution, not the vulnerability.


The U.S. Connection: A Global Network, One Phone Call at a Time

Jubair’s crimes didn’t stop at London. In September 2025, the U.S. Department of Justice unsealed an indictment charging him with conspiracy to commit computer fraud, wire fraud, and money laundering across 120 breaches.

He didn’t hack a bank. He didn’t breach a cloud provider. He called a customer service rep at a university, pretended to be from the registrar’s office, and asked for a student’s login. That one call led to a cascade of compromises.

The same pattern repeats: a fake call to a helpdesk. A compromised account. A pivot to internal systems. A ransom demand.

And here’s the kicker: the U.S. has indicted at least eight other Scattered Spider members. Four were arrested in the UK. One was extradited from Finland. Another is still at large in Nigeria.

This isn’t a local crime. It’s a global, decentralized network of human agents—each one a single point of failure.


AI Cybersecurity Threats: The Real Enemy Isn’t AI

We keep talking about AI-powered cyberattacks. But the most dangerous AI threat isn’t a model writing malware. It’s a human using AI tools to become a better con artist.

Jubair used ChatGPT to refine his phishing scripts. Flowers used AI voice clones to impersonate executives. They didn’t need to be coders. They just needed to be good listeners.

The real AI cybersecurity threat? The belief that automation will fix human error.

We’ve outsourced our security to tools, while our people remain untrained, overworked, and under-supported. And the attackers? They’ve trained their people to exploit that.

This isn’t a problem of technology. It’s a problem of culture.


The Aftermath: What Happens When the Kids Go to Prison

Jubair and Flowers will be out in about four years. What happens then?

There’s a quiet industry in the UK and U.S. that hires ex-hackers—not to write code, but to test code. They’re called red teamers. Pen testers. Social engineers.

Some say they’ll end up working for GCHQ or a Fortune 500 security team. Others say they’ll go back to crime. Both are right.

Because here’s the real lesson: the system didn’t break because these kids were evil. It broke because no one gave them a better way to use their skills.

They didn’t need more jail time. They needed a mentor. A lab. A path.

The question isn’t whether we can catch the next Scattered Spider. It’s whether we’re willing to give them a reason not to become the next one.

The Price of a Click

We keep talking about AI-powered malware. Autonomous agents. LLM-driven exploits. But the most dangerous threat on the network right now isn’t a bot. It’s a person.

Thalha Jubair and Owen Flowers didn’t write a single line of malicious code. They didn’t find a zero-day. They didn’t deploy a ransomware payload. They called people. They lied. And they got what they wanted.

That’s the new AI cybersecurity threat: not artificial intelligence, but artificial trust.

The attackers used tools—Telegram, ChatGPT, AI voice cloning—to refine their social engineering. But the core exploit? Human psychology. The belief that someone from IT is calling to help.

Security teams spend billions on AI tools that detect anomalies in network traffic. But they still don’t train their staff to question a request that says, "I’m from corporate, I need your password."

This isn’t a failure of technology. It’s a failure of culture.

We’ve built firewalls around our systems, but left our people exposed. And the attackers? They’ve trained themselves to exploit that.

The real AI cybersecurity threat isn’t the model. It’s the person who believes the model can protect them.

The Real AI Cybersecurity Threat: Trust, Not Technology

We’ve spent a decade building AI-powered firewalls, endpoint detection tools, and threat intelligence platforms. And yet, the most devastating breaches still start with a phone call.

Jubair didn’t need to crack a firewall. He didn’t need a zero-day. He just needed to sound like a colleague. He used ChatGPT to polish his scripts, AI voice cloning to mimic executives, and Telegram to coordinate. But the exploit? That was human.

Security teams still treat people as the last line of defense—as if training is a checkbox, not a culture. They invest in tools that detect anomalies, but not in people who can question them.

This isn’t a failure of AI. It’s a failure of imagination.

We built a world where machines are expected to be flawless, but humans are expected to be perfect under pressure. We train engineers to patch CVEs, but never to spot a lie.

And the attackers? They’ve trained themselves to exploit that gap.


The Franchise of Fear

Scattered Spider isn’t a gang. It’s a franchise.

Jubair ran Star Chat, a Telegram channel where he sold SIM-swapping services to anyone who could pay in Bitcoin. Flowers hacked healthcare systems using fake helpdesk calls. Neither had a degree. Neither had a background in cybersecurity.

They had something better: charisma.

In 2022, Jubair led a mass SMS phishing campaign that compromised employees at LastPass, DoorDash, Mailchimp, and Signal. The message? "Urgent: Your MFA token expired. Click here to reset." The link? A fake login page. The result? Credentials harvested, accounts breached, systems compromised.

No malware. No ransomware. Just a text message and a lie.

The same tactic took down Harrods, Marks & Spencer, and Co-op in mid-2025. Same playbook. Same team. Just different targets.

What’s terrifying isn’t the scale. It’s the simplicity. No exploit kits. No custom payloads. Just a phone call, a fake email, and a little charisma.


The Global Web: One Phone Call, 120 Breaches

Jubair’s crimes didn’t stop at London.

In September 2025, the U.S. Department of Justice unsealed an indictment charging him with conspiracy to commit computer fraud, wire fraud, and money laundering across 120 breaches. The victims? Hospitals, universities, courts, transit agencies.

He didn’t hack a cloud provider. He didn’t breach a database. He called a customer service rep at a university, pretended to be from the registrar’s office, and asked for a student’s login. That one call led to a cascade of compromises.

The pattern repeats: fake call. Compromised account. Pivot to internal systems. Ransom demand.

And here’s the kicker: the U.S. has indicted at least eight other Scattered Spider members. Four were arrested in the UK. One was extradited from Finland. Another is still at large in Nigeria.

This isn’t a local crime. It’s a global, decentralized network of human agents—each one a single point of failure.


The Paradox of AI Cybersecurity

We keep calling these "AI cybersecurity threats." But the real threat isn’t AI.

It’s the belief that AI can protect us from ourselves.

We’ve outsourced our security to tools, while our people remain untrained, overworked, and under-supported. And the attackers? They’ve trained their people to exploit that.

The real AI cybersecurity threat? The belief that automation will fix human error.

We’ve built a world where machines are expected to be flawless, but humans are expected to be perfect under pressure. We train engineers to patch CVEs, but never to spot a lie.

And the attackers? They’ve trained themselves to exploit that gap.

More blogs