Threats

Scattered Spider Hacker Extradited to US

July 5, 2026 12:09 · 10 min read
Scattered Spider Hacker Extradited to US

Scattered Spider Hacker Faces Charges in the US

A dual United States and Estonian citizen, 19-year-old Peter Stokes, has been extradited to the US to face charges alleging he was a member of the Scattered Spider hacking collective. Stokes, who used the online handles 'Bouquet,' 'Spencer,' and 'Jordan,' was arrested in Finland on April 10 while attempting to board a flight to Japan at Helsinki's airport.

According to court documents, Stokes was involved in at least four Scattered Spider breaches, including a March 2023 hack of an online communication platform, when he was 16 years old. The list of victims breached with the suspect's help also includes an unnamed multibillion-dollar 'luxury item retailer' in May 2025, when the hackers allegedly called the company's IT helpdesk, posing as employees, to reset credentials and gain access to administrator accounts.

Scattered Spider's Modus Operandi

Scattered Spider has been involved in over 100 network intrusions, resulting in more than $100 million in ransom payments and millions more in damages to the victims. The hacking group has repeatedly targeted US companies, extorting employees, inflicting millions of dollars in losses, and disrupting essential operations.

They are known for using a blend of social engineering, targeted multi-factor authentication (MFA) bombing (aka MFA fatigue), and SMS credential phishing attacks to steal user credentials and sensitive documents for extortion leverage after breaching their targets' networks. According to prosecutors, they commonly use the Genymobile Android emulator during their MFA attacks and have also deployed DragonForce encryptor in ransomware attacks against UK retail companies.

Victims of Scattered Spider

Scattered Spider's list of victims includes many high-profile organizations, including Caesars, MGM Resorts, Riot Games, DoorDash, Reddit, MailChimp, Twilio, Allianz Life, Transport for London (TfL), multiple UK retailers such as Co-op, Marks & Spencer (M&S), and Harrods, and, more recently, WestJet and Jaguar Land Rover (JLR).

The criminal complaint charges Peter Stokes with membership in Scattered Spider, a hacking group that has been involved in over 100 network intrusions, resulting in more than $100 million in ransom payments and millions more in damages to the victims - Assistant Attorney General A. Tysen Duva

Stokes now faces charges of fraud, conspiracy, and computer intrusion and has remained in custody after appearing in federal court in Chicago on Tuesday. The extradition of Stokes marks a significant development in the efforts to dismantle the Scattered Spider hacking collective and bring its members to justice.

As stated by Assistant Director Brett Leatherman of the FBI's Cyber Division, 'Scattered Spider has repeatedly targeted U.S. companies, extorting employees, inflicting millions of dollars in losses, and disrupting essential operations.' The FBI and other law enforcement agencies continue to investigate and disrupt the activities of Scattered Spider and other hacking groups.

Security Measures

Security teams must remain vigilant and take proactive measures to protect their networks and systems from the threat posed by Scattered Spider and other hacking groups. This includes implementing robust security measures, such as multi-factor authentication, regular security updates, and employee training programs.

According to a Picus whitepaper, security teams log 54% of successful attacks and alert on just 14%. The rest move through the environment unseen. The whitepaper shows how breach and attack simulation tests SIEM and EDR rules so threats stop slipping by detection.


Source: BleepingComputer

Source: BleepingComputer

Powered by ZeroBot

Protect your website from bots, scrapers, and automated threats.

Try ZeroBot Free