Windows Device Identifier Helped FBI Trace and Arrest Alleged Scattered Spider Member

A Microsoft Windows device identifier, known as a Global Device Identifier (GDID), was used to link 19-year-old Peter Stokes to a string of ransomware and extortion attacks tied to the Scattered Spider hacking collective.

Stokes, a dual U.S.-Estonian citizen, allegedly operated under the aliases “Bouquet,” “Spencer,” and “Jordan,” according to a superseding criminal complaint filed in the Northern District of Illinois.

A GDID is a persistent, device-level identifier that uniquely marks a Windows installation across certain Microsoft services, remaining stable through OS updates but changing upon a fresh Windows install.

Windows Device Identifier Helped FBI

FBI Special Agent Ali Sadiq’s affidavit details how Microsoft records showed that GDID g6755467234350028 was used to set up an ngrok account a secure-tunneling tool at 19:21 UTC on May 12, 2025, the exact moment the account was created to intrude on a luxury-jewelry retailer identified as “Company F”.

Document  (Source: DOJ)
Document (Source: DOJ)

That same device later browsed the retailer’s site through a Tzulo-hosted VPN proxy server in Mount Prospect, Illinois, ending in “.168”.

Investigators then pivoted from the device identifier to real-world identity by cross-referencing IP addresses tied to the GDID against IP logs from Stokes’s Snapchat, Facebook, and Apple accounts obtained via search warrants.

On multiple dates, including sessions from Tallinn, Estonia; New York City; and Thailand, the GDID-linked device and Stokes’s personal accounts connected from identical IP addresses within hours of each other, at times corroborated by State Department travel records and hotel-branded photos he posted on Snapchat.

The May 2025 attack began with phishing calls to Company F’s IT help desk from spoofed Google Voice numbers, which tricked staff into resetting multifactor authentication for three accounts, two of which had elevated privileges.

The attackers then deployed an ngrok tunnel and tools, including Teleport.sh and Amazon S3, to exfiltrate roughly 77 gigabytes of sensitive data, including Active Directory records and employee OneDrive files, before demanding an 8-million-dollar ransom that the company refused to pay, resulting in an estimated 2 million dollars in losses.

Prosecutors allege that Scattered Spider, also tracked as Octo Tempest, UNC3944, and 0ktapus, has carried out more than 100 network intrusions generating over 100 million dollars in ransom payments, targeting sectors from insurance to critical infrastructure across the U.S. and U.K.

Evidence recovered from a seized virtual private server, dubbed “Subject Server 1,” contained exfiltrated files from at least a dozen additional victim companies along with a custom Telegram search bot and virtual Android devices loaded with Okta and Azure Authenticator apps used to defeat MFA protections.

Stokes was apprehended in Finland on April 10, 2026, while attempting to board a flight to Japan, acting on an Interpol notice tied to a December 2025 U.S. arrest warrant.

He now faces extradition on charges including conspiracy to commit computer fraud, wire fraud, and extortion under the Computer Fraud and Abuse Act.

This case underscores how device-level telemetry, historically used mainly for fraud detection, is becoming a cornerstone of cybercrime attribution when correlated with cross-platform IP and account activity.

Follow us on Google News , LinkedIn and X to Get More Instant UpdatesSet Cyberpress as a Preferred Source in Google.

Tamilselvan
Tamilselvanhttps://cyberpress.org/
Tamilselvan is an Investigative cybersecurity journalist dedicated to breaking stories on ransomware cartels, data breaches, and state-sponsored espionage.

Trending News

Related Stories