breach
Windows Device ID Allegedly Outs Scattered Spider Suspect
2026-07-09

U.S. prosecutors say they traced an alleged Scattered Spider member to a break-in at a luxury jewellery retailer using something most people have never heard of: a persistent Windows device ID that survives operating system updates but not a full reinstall.
Microsoft's records tied that identifier first to the account attackers used to hold onto access during a May 2025 intrusion, then to Snapchat, Apple and Facebook accounts prosecutors link to Peter Stokes, a 19-year-old dual U.S.-Estonian citizen who went online as "Bouquet."
A phone call, three accounts, 77 gigabytes
The break-in itself was almost boring. Between 12 and 15 May, attackers rang the retailer's IT help desk from Google Voice numbers, posed as locked-out staff, and talked support into resetting passwords and the phones tied to multifactor authentication. Within hours they had three accounts, two of them IT admins.
They installed ngrok and Teleport for tunnelling, shovelled 77 gigabytes into Amazon cloud storage, and tried to detonate ransomware. Security caught the last part and kicked them out. The attackers still fired off a ransom email demanding $8 million, with the immortal subject line "IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY." The company refused and ate roughly $2 million in cleanup.
The ID that kept surfacing
The device Stokes allegedly used to sign up for ngrok kept turning up on the same IP addresses, at the same times, as his personal social accounts. Tallinn in June 2024. New York in November. Thailand in February 2025. State Department travel records lined up neatly.
His Snapchat, meanwhile, was busy. Prosecutors describe photos of cash, watches, and diamond chains reading "HACK THE PLANET," plus a shot of an Estonian police station and a taunt that the feds had let him slip. Finnish police stopped him at Helsinki airport on his way to Japan and seized two 2TB hard drives.
The gang that isn't a gang
What makes the case awkward for law enforcement is what Group-IB argues in separate research: Scattered Spider isn't really a gang. It's a scene, dozens of small cells of five or fewer, sharing tools and chat rooms rather than answering to anyone.
Arresting individuals, and there have been several recently, from Tyler Buchanan to Noah Urban to the pair behind the Transport for London hack, doesn't dent the shared playbook. Which is why those two hard drives may end up mattering more than the conviction, if they lead anywhere useful.
Where it actually went wrong
The entry point in this case wasn't a clever exploit. It was a help desk willing to reset credentials and MFA devices on the strength of a phone call.
Phishing-resistant MFA is worth the effort. It counts for nothing if support staff can undo it in ninety seconds without verifying who they're talking to. Every organisation running an IT help desk has the same weak spot, and Scattered Spider have built an entire scene around exploiting it.