Cybercrime

Alleged Scattered Spider Hacker Extradited to US

Prosecutors say 19-year-old Peter Stokes was a member of Scattered Spider, the hacking group linked to more than 100 network intrusions and over $100 million in ransom payments.

Scattered Spider

A dual US-Estonian citizen was extradited to the US to face charges for his alleged involvement in the activities of the infamous hacking group Scattered Spider.

The individual, Peter Stokes, 19, also known as ‘Bouquet’, was arrested in Finland in April while boarding a flight to Japan. He was indicted with counts of conspiracy, computer intrusion, and fraud.

In May 2025, together with other co-conspirators, Stokes allegedly hacked a luxury jewelry retailer’s computer system, stole data from it, and demanded an $8 million ransom in cryptocurrency from the victim.

While the retailer managed to evict the hackers from its network and no ransom was paid, the attack led to business disruption, which, together with the investigation and mitigation actions, caused at least $2 million in losses.

Also tracked as 0ktapus, Muddled Libra, Octo Tempest, Starfraud, Scatter Swine, and UNC3944, Scattered Spider is believed to have hacked at least 100 organizations and to have received over $100 million in ransom payments from its victims.

The group is known for its widespread 2025 Salesforce hacking campaign and for the 0ktapus campaign, which hit over 130 organizations in 2022.

Advertisement. Scroll to continue reading.

Over the past several years, authorities charged, arrested, and sentenced multiple alleged members of the hacking group. In April this year, UK national Tyler Robert Buchanan pleaded guilty in the US for his role in the Scattered Spider operations.

In September last year, after making the headlines for high-profile attacks against the retail, insurance, and aviation industries, Scattered Spider announced its retirement.

Related: Third DraftKings Hacker Sentenced to 18 Months in Prison

Related: Admins of Bulletproof Hosting Service Used by Russian Hackers Arrested in Netherlands

Related: Canadian Man Arrested for Operating Kimwolf Botnet

Related: Karakurt Ransomware Negotiator Sentenced to Prison

Related Content

Data Breaches

Hackers were detected on Analog Devices systems in June, and an investigation found that they stole files.

Data Breaches

Ernst & Young previously confirmed that personal and financial information was stolen from a third-party management platform.

Ransomware

The critical unsafe deserialization flaw allows attackers to execute arbitrary code remotely, without authentication.

Data Breaches

The Anubis cybercrime group has taken credit for the attack and is threatening to leak data.

Data Breaches

The PEAR ransomware group claimed to have stolen 3 TB of information from the medical business management company.

Data Breaches

A hacker claims to have stolen the information of 2 million Origin Energy customers and is threatening to leak it. 

Data Breaches

The Anubis ransomware group claims to have stolen 1 TB of confidential data from the Coca-Cola subsidiary.

Data Breaches

Hackers exfiltrated personal, financial, and health information from the company’s Oracle EBS instance in August 2025.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version