Cybercrime
,
Fraud Management & Cybercrime
,
Social Engineering
FBI Says Peter Stokes, 19, ‘Exhibited Substantial Wealth for a Person of His Age’

A suspected member of the notorious Scattered Spider cybercrime group will stand trial in the United States following his extradition from Finland.
See Also: Experts Offer Insights from Theoretical to the Realities of AI-enabled Cybercrime
Finnish police, acting on an Interpol Red Notice, arrested 19-year-old Peter Stokes in April. He’s been charged with being a member of Scattered Spider, a prolific hacking group tied to more than 100 network intrusions that have led to ransomware attacks, data theft and data leaks. Victims have collectively paid out more than $100 million in extortion demands.
Stokes, a dual U.S.-Estonian citizen, appeared in Chicago federal court Tuesday, where a judge ordered that he remain in law enforcement custody, said the U.S. Department of Justice.
An unsealed, six-count superseding criminal complaint charges Stokes with federal criminal conspiracy, fraud, extortion and computer crimes, including an $8 million ransomware extortion attempt against a luxury jewelry retailer.
An FBI affidavit accuses Stokes of committing “multiple computer intrusions” under the banner of Scattered Spider, using the monikers “Bouquet” and “Jordan,” when he was living in Tallinn, Estonia, and the United Arab Emirates.
Researchers also track Scattered Spider as Octo Tempest, UNC3944 and 0ktapus. Analysts say the group is a loose-knit, English-speaking cybercrime collective that emerged from the online cybercrime community known as The Com. Scattered Spider, also largely comprised of adolescents, is known for its social engineering-led intrusions. The group specializes in help desk impersonation, voice phishing and fake single sign-on pages designed to steal credentials and bypass multifactor authentication.
“Scattered Spider has repeatedly targeted U.S. companies, extorting employees, inflicting millions of dollars in losses and disrupting essential operations,” said Assistant Director Brett Leatherman of the FBI Cyber Division.
Security researchers have linked the group to attacks on retailers, casinos, insurers, airlines and technology firms. The group repeatedly targets Salesforce data, cloud and virtualized environments, exfiltrates large volumes of information and uses it to extort victims. The group also previously claimed to cross over with other groups, such as ShinyHunters, which specializes in data theft and extortion, under such names as “Shiny Lapsus$ Hunters.”
Prosecutors said Stokes participated in a Scattered Spider operation that gained unauthorized access in March 2023 to the network of an “online-communication platform,” referred to as Company H.
The complaint also accuses him of participating in the May 2025 breach of an unnamed “luxury-jewelry retailer,” identified in court filings as Company F. In that attack, suspects used Google Voice numbers to place calls to the retailer’s help desk, and later used ngrok, a legitimate internet tunneling tool, to maintain persistent unauthorized access to the company’s data center. Prosecutors said the attackers stole corporate data and demanded an $8 million cryptocurrency ransom.
The FBI said the company paid no ransom, but still suffered at least $2 million in losses due to the business disruption, plus investigation and mitigation costs.
Multiple Clues
Investigators traced the ngrok use to a virtual private network proxy service IP address that they separately tied to a Microsoft device used by Stokes, which used the same IP address.
Microsoft cybersecurity researchers, in an October 2024 referral to the FBI, identified Tallinn-based Stokes as being the likely true identity of an Octo Tempest operator using the handle “Spencer” who handled malware for the group, according to the affidavit. Researchers said Spencer appeared to have participated in attacks targeting U.S. and U.K. critical infrastructure organizations, and to have been part of the group since 2022.
The FBI said images from Stokes’ Snapchat, Facebook and Apple accounts, which investigators accessed with court-granted search warrants, “also show Stokes possessing numerous watches and substantial cash, as well as apparently diamond-encrusted chains with the words “HACK THE PLANET.”
A footnote to FBI-authored affidavit adds: “‘Hack the planet!’ is a famous line from the 1995 cyberpunk film ‘Hackers’ about juvenile and young-adult computer hackers.”
The affidavit said Stokes’s posts to Snapchat “exhibited substantial wealth for a person his age, boasted about his international travel and wealth, and sent media regarding apprehended Scattered Spider members.”
An image included in the complaint, obtained from one of Stokes’ accounts, shows an image of mafiosos from the television drama “The Sopranos,” with monikers added to various characters, sent by Stokes to others on March 16, 2025. These include “Peter,” in apparent reference to Stokes himself, as well as “auth,” which is the handle for a “Co-Conspirator A,” a suspected U.S.-based member of Scattered Spider suspected of committing crimes as a juvenile, who was criminally charged after an investigation by the FBI’s Chicago Field Office. The other seven monikers on the image, presumably representing other Scattered Spider members, read: “domr,” “guts,” “Le bandit,” “Sweet bonanza,” “ralf,” “zarius” and “zeus vs hades.”
At least some of Stokes’ displayed travel – confirmed to a degree by the FBI, using Department of State travel records – likely tied to the suspect’s family. “Based on his father’s previous occupation as an executive in two major European businesses, Stokes’ family appears to be well off,” the affidavit said.
Arrests Continue
Law enforcement agencies continue to arrest suspected Scattered Spider members. This has included a juvenile, arrested in Las Vegas last September in connection with attacks against casinos. In November 2024, U.S. prosecutors unsealed an indictment charging five men – including two each in Texas and one each in Florida and North Carolina – for perpetrating Scattered Spider attacks that generated at least $27 million in cryptocurrency ransom payments. One of those defendants, Noah Michael Urban, pleaded guilty in early 2025 and received a 10-year sentence.
Another suspected Scattered Spider member, Scottish national Tyler Robert Buchanan, was arrested by Spanish police in May 2024 and extradited to the United States. He pleaded guilty in California federal court in April to wire fraud and aggravated identity theft charges.
In Britain, Scattered Spider members Thalha Jubair, 20, and Owen Flowers, 18, last week pleaded guilty to Computer Misuse Act violations, including disrupting London’s transport authority’s payment system. Flowers also admitted to conspiring to commit unauthorized acts against American healthcare firms SSM Health Care and Sutter Health. They’re due to be sentenced later this month.
Scattered Spider has been linked to further attacks in Britain, including against high street retailers Marks & Spencer and the Cooperative Group, as well as Jaguar Land Rover, although recent reporting has suggested Russian involvement in the JLR attack.
