"This is without doubt the biggest, most complex and most challenging investigation that we’ve ever conducted," said Paul Foster, deputy director of the National Crime Agency, summing up an inquiry that ended with two men jailed and renewed calls for new UK powers to manage cyber risk.
Paul Foster and the National Crime Agency’s assessment
At a pre-sentencing briefing and following a hearing at Woolwich Crown Court on July 16, Paul Foster described the Transport for London (TfL) hack prosecution as “the largest cybercrime prosecution ever brought before the UK courts.” Foster said the investigation took “nearly two years of painstaking work” by the NCA, the Crown Prosecution Service and partners including the City of London Police, the FBI, Europol and the Australian Federal Police. He flagged the group Scattered Spider as “the most significant cybercrime threat to the UK in recent years” and welcomed any disruption of its activity.
The defendants and the Section 3ZA conviction
Owen Flowers, 19, and Thalha Jubair, 20, were each sentenced to five and a half years in prison after being convicted under Section 3ZA of the Computer Misuse Act 1990 for making unauthorised acts against TfL. The attack is estimated to have cost TfL £29m in damages and a further £10m in lost income, and to have disrupted the lives of between seven and ten million people across the UK. Both men are believed to be part of Scattered Spider; that group has also been linked in the source material to the Marks & Spencer and Co-op incidents in 2025.
Cybercrime Risk Orders: the proposed tool and the claimed benefits
Proposed by government in May 2026 as part of planned Computer Misuse Act reforms, Cybercrime Risk Orders (CCROs) are described in the source as civil preventive measures intended to manage the behaviour of suspected or convicted cyber-offenders by creating a form of “digital prison.” Foster argued CCROs would allow authorities to impose restrictions on individuals considered to pose an ongoing cyber threat even before prosecution thresholds are met. He told reporters CCROs “would have allowed us to arrest Flowers sooner” by enabling action on information shared by US or Australian partners and compared them in principle to sexual risk orders — civil orders with conditions that can be monitored and breach of which can lead to criminal sanctions.
City of London Police on “digital prisons” and enforcement
Ollie Shaw, a Commander at the City of London Police, welcomed the CCRO concept and argued that traditional mechanisms for controlling physical offenders are less effective for cyber offenders. Shaw advocated for “digital prisons” that restrict access to the digital tools and platforms needed to reoffend, enforced in partnership with tech providers and allowing monitoring of account usage and device limits. He acknowledged practical enforcement challenges, for example keeping digital devices out of prisons, and said the orders would need strong operational guidance to be effective.
Critique from Adam Pilton: capability and realism
Adam Pilton, a UK-based cybersecurity consultant cited in the briefing, cautioned that CCROs risk being ineffectual unless supervising officers have genuine technical capability. He warned the people targeted by these orders will be “highly skilled and capable of tricking most officers” and said “restrictions can and will help manage risk, but only skilled supervision makes them meaningful.” Pilton also criticized the term “digital prison” as “headline-grabbing marketing terminology for a CCRO,” arguing that determined offenders will find ways to bypass orders.
What this means for the NCA, the City of London Police, and tech providers
- NCA: The agency is pressing for a preventive tool it says would fill gaps created by offenders’ ages and by existing measures that do not apply to under-18s or to some computer misuse offences; it frames CCROs as necessary to act on international intelligence sooner.
- City of London Police: Sees operational benefit in enforceable restrictions tied to digital accounts and devices but cautions that effective implementation will require partnerships with tech providers and detailed operational guidance to overcome practical challenges.
- Tech providers and supervisors: Will be asked to help enforce monitoring and device/account limits; critics in the source warn that without skilled technical supervision these arrangements may not prevent determined offenders from evading controls.
The legislative path is already signposted in the material: reform of the Computer Misuse Act is expected to be introduced in Parliament later this year as part of a broader national security package, and CCROs are due to be introduced in late 2027 or early 2028. The TfL prosecution — a conviction only the second under the most serious Section 3ZA of the Act — has crystallised both the appetite for new civil preventive powers and the practical questions about whether policing capacity and industry cooperation will be sufficient to make a “digital prison” more than a slogan.
Original story: https://www.infosecurity-magazine.com/news/police-chiefs-tfl-cybercrime-risk/




