Eleven days ago, Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five years and six months for the Transport for London attack that took down more than 140 systems and cost £29 million. The National Crime Agency called it the largest cybercrime prosecution ever brought before UK courts, and Paul Foster of the NCA’s National Cyber Crime Unit said the investigation had “severely disrupted” what he described as “the most significant cybercrime threat to the U.K. in recent years.”
Three days ago, we published the first of two pieces on ShinyHunters claiming 30 million records and over a million Social Security numbers from Abbott’s cancer diagnostics arm — taken, as usual, by phoning an employee.
Both statements are accurate. Law enforcement is winning against one class of adversary and losing to another, and the difference is not about competence on either side. It is structural.
The Scoreboard Is Genuinely Good
Take the year’s law enforcement record on its own terms and it is the best on record:
The TfL prosecution closed. Flowers and Jubair, 16 and 18 at the time of the 2024 attack, jailed for five and a half years each. Flowers additionally admitted conspiring to attack US healthcare systems.
Extradition worked. Peter Stokes, 19, a dual US-Estonian citizen known as “Bouquet,” was arrested in Finland in April on an Interpol Red Notice while boarding a flight to Japan — with two 2TB hard drives in his luggage — extradited to the US in late June, and held in custody after appearing in Chicago federal court on June 30. Prosecutors allege his first intrusion came at 16, and that a May 2025 breach of a luxury jewelry retailer came with an $8 million cryptocurrency demand the retailer refused, spending at least $2 million on cleanup instead.
The infrastructure layer got hit. The Media Land / ML Cloud bulletproof hosting indictment went after the service providers rather than the operators — three Russian nationals and two companies, more than $62 million in victim losses.
The hacktivist support network got hit. Spain’s arrest of an alleged Cyber Army of Russia Reborn facilitator under Operation Riptide came from an FBI tip and ended with seized crypto wallets — targeting the logistics man, not the intruder.
Volume operations scaled. Interpol’s Operation Ramz and Operation First Light produced hundreds of arrests across fraud and scam networks.
Even the DPRK is arresting hackers. Pyongyang raided a safe house and detained its own former cyber operators for looting two state banks.
That is a functioning enforcement apparatus: extradition treaties honored, financial infrastructure targeted, sentences that carry real deterrent weight, and international coordination that works on a timescale of months rather than years.
Why It Hasn’t Slowed Anything Down
Now look at what happened to the actual breach rate.
ShinyHunters ran a continuous 2026 campaign through Carnival, Cushman & Wakefield, Charter/Spectrum, Instructure, DentaQuest, the Council of Europe, Nottingham University, Medtronic, Moody Bible Institute, and now Abbott. Not one of those campaigns was interrupted by an arrest.
Three structural reasons explain the gap.
Jurisdiction decides everything. Flowers, Jubair, and Stokes were arrestable because they lived in the UK, or held US citizenship, or travelled through a country with a functioning extradition relationship. Scattered Spider was an English-speaking, Western-resident collective — that is precisely why it was prosecutable. Actors operating from non-cooperating jurisdictions face indictment, not custody. The Media Land defendants were charged; charging is not the same as catching.
Brands are not organizations. “ShinyHunters” is a reputation and a leak site, not a payroll. The name has been used by successive, overlapping crews for years. Arresting participants removes hands, not the entity — the infrastructure, the extortion brand, and the affiliate relationships survive and re-staff.
The technique needs no infrastructure to seize. Voice phishing a help desk requires a phone and a plausible voice. There is no botnet to sinkhole, no C2 to seize, no bulletproof host to indict. The Abbott intrusion reportedly began with vishing calls to employees in mid-June that yielded a Microsoft Entra SSO account. You cannot take down a phone call.
What Enforcement Did Change
None of this makes the arrests theatre. Three effects are real.
Sentences reset the risk calculus for Western teenagers. The Com’s recruitment pitch has always run on the assumption that nothing serious happens to minors and young adults doing this from a bedroom. Five and a half years, at ages 18 and 20, is a direct rebuttal — and it was widely read in exactly the communities it was aimed at. Stokes’ pre-trial detention reinforces it: an alleged 16-year-old first offence produced federal custody at 19.
Infrastructure indictments raise operating costs. Bulletproof hosting takedowns don’t stop crime, but they push operators onto more expensive, less reliable, more surveilled services. That is friction, and friction compounds.
Attribution improved measurably. Windows GDID telemetry unmasking Stokes is a case study in how much identifying material modern endpoints leak. Operators who came up assuming a VPN was sufficient are being identified by artifacts they did not know existed.
The Uncomfortable Conclusion
Enforcement scales linearly. Investigations take years, extradition takes months, prosecutions take dedicated specialist units, and every case consumes finite resources. The NCA’s TfL investigation was, by its own account, the largest cybercrime case in UK history — and it produced two convictions.
Intrusion scales exponentially. One vished credential yields a claimed 30 million records. The same phone script works against the next Fortune 100 company, and the one after that, at a marginal cost of roughly zero.
No arrest rate closes that gap. The gap closes when the phone call stops working — when help desks verify identity through something other than confidence and a plausible story, when SSO accounts require phishing-resistant authenticators, when a stolen session cannot be replayed from an unmanaged device, and when acquisitions get integrated into the parent’s identity controls before the legacy database becomes someone else’s payday.
Law enforcement had an extraordinary year. It did not, and could not, make anyone safer this quarter. That part is still on defenders.
Further reading
- Scattered Spider’s TfL hackers jailed: five and a half years each
- Peter Stokes, “Bouquet,” arrested in Finland
- Media Land bulletproof hosting indictment: $62 million in victim losses
- Spain arrests Cyber Army of Russia Reborn facilitator in Operation Riptide
- ShinyHunters’ enterprise Salesforce vishing campaign



