VYPR
breachPublished Jul 1, 2026· Updated Jul 7, 2026· 9 sources

Teen Suspect in Scattered Spider Hacks Extradited to U.S.

A 19-year-old dual citizen of the U.S. and Estonia, allegedly linked to the Scattered Spider cybercrime group, has been extradited from Finland to Chicago to face federal charges.

A 19-year-old man with dual U.S. and Estonian citizenship has been extradited from Finland to Chicago to face criminal charges for his alleged involvement in hacks as part of the Scattered Spider cybercrime group. Peter Stokes appeared in federal court in the Northern District of Illinois on Tuesday, where the Department of Justice announced the FBI's criminal complaint against him, which includes charges of conspiracy, cyber intrusion, and fraud.

The core of the complaint centers on a data breach that occurred around May 12, 2025, targeting an unnamed luxury jewelry retailer, referred to as Company F. According to the FBI, Stokes and potentially other Scattered Spider members stole data from the company and subsequently demanded an $8 million ransom in cryptocurrency. The attackers reportedly used a social engineering tactic, impersonating Company F employees to request password resets and multifactor authentication changes for three user accounts, including those of IT administrators with high-privilege access. This phishing technique allowed them to compromise these accounts within a few hours.

Scattered Spider, a loosely affiliated group of English-speaking threat actors, has been implicated in a range of illicit activities, including SMS phishing scams, breaches of U.S. casinos and a federal court system, and a significant network disruption affecting London's transport agency. The unsealed complaint also alleges that Stokes gained unauthorized access in March 2023 to the network of an online communication platform, designated as Company H.

Stokes, who allegedly operated under aliases such as "Bouquet," "Spencer," and "Jordan," was apprehended by Finnish authorities in April following an Interpol Red Notice. The Department of Justice confirmed his arrest, which had been previously reported by the Chicago Tribune. Following his court appearance, Stokes was remanded into law enforcement custody.

In the breach of the jewelry retailer, the FBI detailed how the suspects utilized Google Voice numbers to contact the IT help desk, initiating the password reset process. They then employed ngrok, a legitimate tool for developers to manage internet traffic, to establish persistent unauthorized access to the company's data center. This allowed them to exfiltrate sensitive data.

Although the jewelry retailer did not pay the $8 million ransom demand, the FBI estimates that the company incurred approximately $2 million in losses due to business disruption, investigation, and mitigation efforts, with further losses anticipated. The U.S. government estimates that Scattered Spider has been responsible for over 100 network intrusions and has collected more than $100 million in ransom payments.

This extradition highlights the ongoing international efforts to apprehend and prosecute individuals involved in sophisticated cybercrime operations. The case against Stokes is expected to shed further light on the methods and scope of Scattered Spider's activities.

The extradition of Peter Stokes, 19, from Finland to the U.S. marks a significant development in the ongoing investigation into the Scattered Spider collective. Stokes, a dual U.S.-Estonian citizen, faces federal charges including conspiracy, computer intrusion, and fraud. The Department of Justice highlighted this arrest as a success of international law enforcement cooperation, underscoring the persistent threat posed by financially motivated cybercriminals operating abroad.

The newly extradited individual is a dual US/Estonian citizen, and the charges he faces in the United States are related to his alleged membership in the Scattered Spider hacking collective. This development adds another alleged member to the group that has been linked to numerous high-profile cyberattacks, often employing SIM-swapping and social engineering tactics.

The criminal complaint details that Peter Stokes, 19, is charged with conspiracy, computer intrusion, and fraud, and is accused of membership in Scattered Spider, a group implicated in over 100 network intrusions resulting in more than $100 million in ransom payments and millions more in damages. Finnish authorities arrested Stokes in April following an Interpol Red Notice, and he was extradited to the United States last week, where he appeared in federal court in Chicago and was ordered to remain in custody.

The extradition of Peter Stokes from Finland to the U.S. marks a significant development in the ongoing efforts against the Scattered Spider cybercrime group. Stokes, a 19-year-old dual U.S.-Estonian citizen, faces federal charges including conspiracy, fraud, extortion, and computer crimes, notably an attempted $8 million shakedown of a luxury jewelry retailer. His alleged involvement with Scattered Spider, also known as Octo Tempest, highlights the group's continued targeting of U.S. companies and its reliance on social engineering tactics like help desk impersonation and credential theft.

The Justice Department has confirmed Peter Stokes, a 19-year-old dual citizen of the U.S. and Estonia, has been extradited to Chicago to face federal charges related to his alleged involvement with the Scattered Spider cybercrime group. Stokes, also known as "Bouquet," is accused of participating in multiple data theft and extortion attempts since 2022, including recent attacks on a luxury retailer and an insurance company. He was arrested in Finland with incriminating evidence while attempting to travel to Japan and has been ordered to remain in federal custody.

The article provides further details on the alleged activities of Peter Stokes, identifying him by the alias 'Bouquet' and noting his arrest in Finland while attempting to travel to Japan. It also specifies the charges he faces, including conspiracy, computer intrusion, and fraud, and details a specific incident where Stokes allegedly hacked a luxury jewelry retailer, stole data, and demanded an $8 million ransom, though no payment was ultimately made.

The arrest of Peter Stokes, an alleged Scattered Spider operator, was significantly aided by the use of a Microsoft Global Device Identifier (GDID). This persistent identifier, unique to Windows installations, allowed investigators to link Stokes's compromised online accounts and malicious activities to a specific device, thereby tracing his involvement in intrusions like the one at "Company F." The GDID's durability proved to be a critical factor in overcoming the anonymity measures employed by the threat actor.

This court filing reveals a crucial technical detail in the investigation of alleged Scattered Spider hacker Peter Stokes: the use of a persistent Windows device ID by Microsoft. This identifier, Global Device Identifier g:6755467234350028, was instrumental in linking the attackers' initial access to the retail intrusion and subsequently to Stokes' own online accounts, providing a concrete digital breadcrumb for law enforcement.

Synthesized by Vypr AI