AIO APEX

Scattered Spider Suspect Extradited From Finland to Face US Hacking Charges

The Record
Share:
Scattered Spider Suspect Extradited From Finland to Face US Hacking Charges

A 19-year-old dual U.S.-Estonian citizen has been extradited from Finland to Chicago to face federal charges of conspiracy, computer intrusion, and fraud for his alleged membership in Scattered Spider, the hacking collective blamed for more than 100 network intrusions and over $100 million in ransom payments since 2022. The Department of Justice announced the extradition on July 1, following Peter Stokes's arrest by Finnish authorities in April 2025 under an Interpol Red Notice.

Scattered Spider is not a conventional hacking group with centralized leadership. It is a loosely affiliated, English-speaking collective — sometimes described by researchers as "the Com" — that specializes in social engineering rather than technical exploits. Members impersonate employees to trick IT help desks into resetting multi-factor authentication and passwords, giving them direct access to corporate networks without needing to break any encryption or exploit software vulnerabilities. The group first drew wide public attention in September 2023 when it breached and locked down the networks of Caesars Entertainment and MGM Resorts International, forcing MGM properties to run without their reservation and payment systems for over a week.

According to the criminal complaint, Stokes — who allegedly used the aliases "Bouquet," "Spencer," and "Jordan" — is accused of unauthorized access to an online communications platform in March 2023 and involvement in a May 2025 breach of a luxury jewelry retailer. In that incident, prosecutors say attackers impersonated employees and requested credential resets through phishing, compromising three accounts, including two IT administrator accounts, within two to three hours. The attackers reportedly used Google Voice numbers and the ngrok tunneling tool to maintain persistent access to internal systems. The retailer refused to pay the attackers' $8 million ransom demand but sustained roughly $2 million in losses from the incident.

The extradition is a notable escalation in law enforcement's pursuit of Scattered Spider, whose members are believed to be scattered across the US and UK and largely composed of teenagers and young adults recruited through gaming and cybercrime forums. Beyond the casino breaches, the group has been linked to intrusions at the US federal court system and disruptions at Transport for London. The FBI and UK's National Crime Agency have run a coordinated, multi-year investigation into the network, with several other alleged members previously arrested in the UK and US.

Security researchers who track the group note that its low-tech, social-engineering-first methodology makes it particularly difficult for enterprises to defend against with traditional security tooling. Rather than exploiting a software vulnerability that can be patched, Scattered Spider exploits organizational trust — a help desk employee following procedure, an IT administrator granting a routine password reset. Companies that have hardened their technical perimeter can still be compromised in hours if their identity verification processes for account recovery are not equally rigorous.

For enterprises, the case is a reminder that phishing-resistant multi-factor authentication and strict identity-verification protocols for help desk password resets remain among the most effective defenses against this style of attack — considerably more effective than most endpoint or network-layer security investments against a group whose primary attack surface is human trust rather than code.

Stokes made his initial court appearance in Chicago's Northern District of Illinois federal court and remains in law enforcement custody pending further proceedings. If convicted on the conspiracy, computer intrusion, and fraud charges, he faces significant federal prison time, though sentencing guidelines have not yet been detailed in court filings.

As first reported by The Record and confirmed via Department of Justice statements, the case underscores the international law enforcement coordination increasingly required to pursue cybercrime groups whose members operate across multiple jurisdictions.

Originally reported by The Record. Read the original article for additional details.

View original source
Share: