Itnews.Au Microsoft Device ID Used to Track Scattered Spider Hacker
Article Content
- •Peter Stokes was arrested for his involvement with the Scattered Spider hacking group.
- •Microsoft's Global Device ID was crucial in linking Stokes to his alleged crimes.
- •The case highlights concerns over user privacy and potential surveillance via device identifiers.
Peter Stokes, a 19-year-old hacker, was arrested in Finland on April 10, 2026, for allegedly being part of the Scattered Spider hacking group. The FBI linked him to a US$8 million ransom demand against a luxury retailer using a Microsoft Global Device ID (GDID). Despite using a VPN, Stokes' GDID was identified through Microsoft telemetry and ngrok access records. The FBI's investigation revealed that Stokes' GDID was associated with multiple IP addresses across different countries, corroborated by Snapchat and Apple account access logs. Stokes faces six charges, including conspiracy and extortion, as part of a broader crackdown on the Scattered Spider group, which has been linked to over 100 attacks and more than US$100 million in extortion. The case raises concerns about user privacy and the potential for abuse of device tracking technologies.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (23)
Following this threat?
Track Scattered Spider in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Social Engineering Attacks Exploit Help Desks Amid AI Advances Recent social engineering attacks have targeted help desk operations, leading to significant breaches. Notable incidents include the Las Vegas casino breaches in 2023, where attackers used vishing to manipulate staff into resetting passwords, resulting in a $100 million loss for MGM Resorts. In August 2026, the Brinks…
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…