GL Assessment A.I CyberSecurity Scoring
GL Assessment
Company Information
Website:http://www.gl-assessment.co.uk
Employees number:68
Number of followers:4,527
NAICS:61
Industry Type:Education
Homepage:gl-assessment.co.uk
GL Assessment Risk Score (AI oriented)
Between 600 and 649
GL AssessmentEducation
Updated:
16/07/2026
16/07/2026
619/1000
Poor
Caa
GL Assessment Global Score (TPRM)
xxxx
GL AssessmentEducation
Score locked

GL AssessmentPoor
Current Score
619Caa (POOR)
01000
1 incidents
0 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
623
AUGUST 2026
622
JULY 2026
619
JUNE 2026
617
MAY 2026
615
APRIL 2026
612
MARCH 2026
609
FEBRUARY 2026
606
JANUARY 2026
604
DECEMBER 2025
601
NOVEMBER 2025
598
OCTOBER 2025
595
JANUARY 2024
772
Ransomware
01 Jan 2024 • GL Assessment
Marks & Spencer and SSM Health Care Corporation: Scattered Spider hackers sentenced to 5.5 years over £29 million Transport for London hack
Scattered Spider Hackers Sentenced in Landmark U.K. Cybercrime Case
511
CRITICAL-261
MARGL-1784204737
Scattered Spider Hackers Sentenced in Landmark U.K. Cybercrime Case
Two key members of the Scattered Spider cybercrime group have been sentenced to over five years in prison for their roles in the 2024 cyberattack on Transport for London (TfL), marking the largest prosecution under the U.K.’s Computer Misuse Act to date.
Thalha Jubair, 20, of East London, and Owen Flowers, 18, from Walsall, were each sentenced to five years and six months at Woolwich Crown Court on Thursday after pleading guilty to charges under Section 3ZA of the Computer Misuse Act. The pair admitted to infiltrating TfL’s network, causing widespread disruption, exposing customer data, and incurring £29 million ($39 million) in recovery costs.
The attack, which TfL managed to contain before it could cripple London’s transport network, forced 27,000 employees to reset passwords in person and rendered 148 internal systems unavailable. Critical operations were disrupted, including the Oyster card refund system, leading to delays for passengers and a temporary suspension of applications for youth travel cards.
Authorities warned that the financial impact could have been far worse had the attackers succeeded in disabling the transport network, the estimated economic damage could have reached £56 billion ($75.6 billion).
Jubair and Flowers were identified as leading figures in Scattered Spider, a transatlantic cybercriminal collective linked to high-profile attacks on airlines, retailers, insurers, and tech firms. The group is known for using social engineering, SIM-swapping, and credential theft to gain access before deploying ransomware or extortion campaigns.
The National Crime Agency (NCA) stated that arrests in September 2024 significantly disrupted Scattered Spider’s operations, with Microsoft confirming the group’s capabilities had been "materially degraded." Investigators found evidence of the attack on Flowers’ devices, including a screenshot of TfL’s infrastructure and videos allegedly showing Jubair accessing systems. The pair coordinated the intrusion via Telegram and an online workspace.
Flowers was initially arrested in September 2024 while simultaneously targeting U.S. healthcare providers SSM Health Care Corporation and Sutter Health. Both defendants faced additional legal complications Flowers for breaching bail conditions and Jubair for refusing to disclose passwords for seized devices.
The case has prompted calls for new legal measures, including proposed Cyber Crime Risk Orders, which would restrict convicted offenders’ access to technology post-release to prevent reoffending. Security officials emphasized the importance of early victim reporting, crediting TfL’s swift engagement with law enforcement for enabling the convictions.
The investigation was led by the NCA and City of London Police, with support from domestic and international agencies, including the FBI. Jubair and Flowers were also linked to suspected ransomware attacks on British retailers Marks & Spencer, the Co-op, and Harrods, though no charges have been filed in those cases.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for GL Assessment ??
What was GL Assessment's A.I Rankiteo Cyber Score in August 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in July 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in June 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in May 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in April 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in March 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in February 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in January 2026 ??
What was GL Assessment's A.I Rankiteo Cyber Score in December 2025 ??
What was GL Assessment's A.I Rankiteo Cyber Score in November 2025 ??
What was GL Assessment's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on GL Assessment's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with GL Assessment ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view GL Assessment's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?