INSPECTING ARCHIVED INTELLIGENCE (OUTDATED VERSION).
Teen suspect in Scattered Spider hacks is extradited to US
| 2026-07-01 20:13 CRITICAL HIGH DATA BREACH LAW ENFORCEMENT
Executive Summary
AI-generated
A 19-year-old man with dual U.S. and Estonian citizenship was extradited from Finland to Chicago on July 1, 2026, to face criminal charges of participating in hacks as part of the Scattered Spider cybercrime group. The suspect, Peter Stokes, allegedly used phishing techniques involving Google Voice numbers to gain unauthorized access to a luxury-jewelry retailer's network in March 2023 and later accessed higher-level accounts using ngrok. As part of the Scattered Spider group, Stokes is accused of participating in over 100 network intrusions and collecting more than $100 million in ransom payments. The FBI alleges that Stokes used aliases "Bouquet," "Spencer," and "Jordan" to carry out these attacks, which also targeted a U.S. casino system and a federal court system.
Technical Mitigations AI-generated
• Use Google Voice numbers with caution, as they can be used for social engineering attacks.
• Implement ngrok usage restrictions and monitor its activity to prevent persistent unauthorized access.
• Regularly update Company F's authentication credentials and multifactor authentication settings.
Intelligence Metadata
Actors / Malware / CVEs / Campaigns
Scattered SpiderScattered Spider
Target & Sectors
NORDICS
NORDICS
retailretail
Incident Timeline
March 2023
Threat actors using Google Voice numbers conducted social engineering attacks on a jewelry retailer's IT help desk to gain unauthorized access.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
The U.S. government estimates that Scattered Spider has been involved with more than 100 network intrusions and collected more than $100 million in ransom payments.
financial
$100 intrusions
The U.S. government estimates that Scattered Spider has been involved with more than 100 network intrusions and collected more than $100 million in ransom payments.
financial
$8 ransom
The company did not pay the $8 million ransom, according to the FBI, but “losses due to business disruption, investigation, and mitigation were approximately $2 million, and further losses were expected.”
financial
$2 mitigation
The company did not pay the $8 million ransom, according to the FBI, but “losses due to business disruption, investigation, and mitigation were approximately $2 million, and further losses were expected.”
May 12, 2025
Threat actors using phishing compromised three Company F user accounts within approximately two to three hours.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
The FBI alleges that Stokes and possibly other Scattered Spider members stole data from the company and then demanded an $8 million ransom in cryptocurrency.
financial
$8 ransom
The FBI alleges that Stokes and possibly other Scattered Spider members stole data from the company and then demanded an $8 million ransom in cryptocurrency.
2026/07/01
A 19-year-old man with dual U.S. and Estonian citizenship was extradited from Finland to Chicago to face criminal charges of participating in hacks as part of the Scattered Spider cybercrime group.
Click on any entity below to view its context and source!
threat_actor
Scattered Spider
Teen suspect in Scattered Spider hacks is extradited to US.
A 19-year-old man with dual U.S. and Estonian citizenship was extradited from Finland to Chicago this week to face criminal charges of participating in hacks as part of the Scattered Spider cybercrime group.
Alleged members of the loosely affiliated, English-speaking Scattered Spider group have been accused or convicted in
scam operations
using
SMS phishing
; breaches of
U.S. casinos
and a federal
court system
; and a major network disruption at…
Tactical Metrics
Metrics
financial
100,000,000
Intrusions
Click for context!
The U.S. government estimates that Scattered Spider has been involved with more than 100 network intrusions and collected more than $100 million in ransom payments.
Metrics
financial
8,000,000
Ransom
The FBI alleges that Stokes and possibly other Scattered Spider members stole data from the company and then demanded an $8 million ransom in cryptocurrency.
The company did not pay the $8 million ransom, according to the FBI, but “losses due to business disruption, investigation, and mitigation were approximately $2 million, and further losses were expected.”
Metrics
financial
2,000,000
Mitigation
The company did not pay the $8 million ransom, according to the FBI, but “losses due to business disruption, investigation, and mitigation were approximately $2 million, and further losses were expected.”
Intelligence Sources
TheRecord
2026-07-01
Unpublish from Social Media?
Are you sure you want to delete this podcast video from all synchronized social networks (YouTube, Facebook, Threads)?
Important:
Due to Meta API restrictions, Instagram Reels cannot be deleted automatically via API by third-party apps.
View Profile to Delete Manually
View Profile to Delete Manually
Tactical Intelligence
Report Intelligence Issue
Podcast Options
Generate
Incident Version History
CURRENT VERSION
Last Updated: 2026-10-07T07:21
Comprehensive Tactical Telemetry
Highly Correlated Entities
3x
timeline
Temporal Reference
19-year-old
date
3x
attribution
Attributing Entity
Interpol Red Notice
authority
3x
tactic
Cyber Operation Type
Data Breach
tactic
2x
source region
Origin Country
United States
country
2x
target region
Target Country
Finland
country
2x
organisation
Identified Entity
the Department of Justice
entity
Contextual Telemetry
Context Block
6 METRICS
threat actor
APT Group
Scattered Spider
actor
industry
Targeted Sector
Government
sector
general metric
Network Intrusions
100
network intrusions
financial
Intrusions
100,000,000
intrusions
financial
Ransom
8,000,000
ransom
financial
Mitigation
2,000,000
mitigation
Click on any entity below to view its context in the main text!
Selective Unpublish
Selecciona las redes de las que quieres eliminar esta publicación. El sistema intentará borrar el post real de la API y limpiará la base de datos para que puedas volver a lanzarlo.
By navigating this website, you accept the use of strictly necessary technical cookies for session security and basic platform functionality. We do not use tracking or advertising cookies.
Read our Privacy Policy.