Windows 11 identifier code used to track Scattered Spider perp after Microsoft shared info with FBI — 19-year-old US-Estonian hacker arrested over alleged ties to infamous extortion group

Hacker?
(Image credit: Getty Images)

The Department of Justice, with the help of the FBI and Finland's National Bureau of Investigation, has arrested a teenager it says is part of Scattered Spider. 19-year-old Peter Stokes is a dual U.S.-Estonian citizen who was trying to board a flight to Japan from Helsinki, when law enforcement caught up with him. Microsoft's GDID also played a part in the Stokes being apprehended. The accused is now awaiting trial, having been charged with conspiracy, cyber intrusion, and fraud.

Scattered Spider is one of the biggest cybercrime syndicates on the planet, having extorted over $100 million in ransom payments, according to the DOJ. The group also operates under the names Octo Tempest, UNC3944, and Oktapus, and is renowned for its social engineering tactics. As such, the main criminal complaint against Stokes stems from a May 2025 attack on a luxury jewelry dealer based in the United States.

The attackers apparently called the company's IT helpdesk using Google Voice, posing as employees. They were able to convince the help desk into resetting their credentials, which allowed them to infiltrate three accounts, two of which had admin privileges. From there, the group, allegedly including Stokes, stole important data and held the jeweler at ransom, demanding an $8 million payment in crypto.

Latest Videos From

The company ultimately regained access to their infrastructure and avoided paying the ransom, but the operational disruption still caused a purported $2 million in losses. This served as the spark that led to Stokes' eventual arrest in Helsinki, as the prosecutors slowly followed the paper and digital trail laid by the attackers. Microsoft played a key role in the process by providing GDID data to the FBI to help them apprehend the alleged criminal.

GDID stands for Global Device Identifier; it's a unique identifier assigned to every Windows install that tracks device-specific telemetry. It's the reason why sometimes changing a major component in your PC can revoke your Windows license. Anyhow, the court documents from the case reveal that Stokes used Windows, from which investigators were able to link his physical hardware to specific internet activity and locations.

From what we can tell, GDID pretty much had a comprehensive report on Stokes ready before the prosecution even built its case and it was only a matter of connecting the dots. Stokes' web activity, videogame history, IP addresses, tool usage (including Ngrok), Azure status, and more were logged with timestamps, and were provided to the investigators by Microsoft.

Of course, this raises questions over just how granular and potentially invasive Microsoft's telemetry can be. In this case, it was used to arrest an alleged hacker, but what if someone else, someone with malign intentions, were to get access to all this data instead? Tech-savvy consumers have complained about Windows' excessive telemetry for a long time; the whole debloating culture is a byproduct of this precedent, but GDID is not something you can remove or disable with the click of a button.

Nevertheless, Stokes was carrying two hard drives full of incriminating evidence with him when boarding his flight to Japan, so that helped, too. His real identity has actually been known since 2024, but since he was a minor living across Estonia and the UAE at the time, he could only be monitored until the time was right. Following the arrest, Stokes was extradited to the U.S., where he appeared in front of a federal court in Chicago for the first time on June 30, 2026, and he remains in custody.

Google Preferred Source

Follow Tom's Hardware on Google News, or add us as a preferred source, to get our latest news, analysis, & reviews in your feeds.

Hassam Nasir
Contributing Writer

Hassam Nasir is a die-hard hardware enthusiast with years of experience as a tech editor and writer, focusing on detailed CPU comparisons and general hardware news. When he’s not working, you’ll find him bending tubes for his ever-evolving custom water-loop gaming rig or benchmarking the latest CPUs and GPUs just for fun.

  • hotaru251
    just more reasons to run customized OS's that disable most of that telemetry or use 3rd party stuff to disable it (and redo it after every update in event it turns it back on)
    Reply
  • TechieTwo
    Welcome to the U.S. Mr. Stokes. Have a nice stay.
    Reply
  • alrighty_then
    Cyber criminals are just leeches, making life harder for grandma, your local bank, hospitals, and any other target they can trick. Glad telemetry helped with the takedown.
    Reply
  • 80251
    If you're a hacker, make sure you use Linux.
    Reply
  • ezst036
    No OS should even be possible to do this.

    I like the guys who support this kind of thing then get bent out of shape that they find out later that they got spied on themselves. Why are you complaining, you got exactly what you asked for.
    Reply
  • Pierce2623
    hotaru251 said:
    just more reasons to run customized OS's that disable most of that telemetry or use 3rd party stuff to disable it (and redo it after every update in event it turns it back on)
    I used to think that way. Then as an adult I realized that mining my data is honestly not infringing my rights and as long as i practice halfway decent digital hygiene and don’t use the internet as my own personal theft tool then I don’t have much to worry about.
    Reply
  • hotaru251
    Pierce2623 said:
    Then as an adult I realized that mining my data is honestly not infringing my rights
    You paid for a product. You are unable to say "no". That is infringing your privacy rights.


    Pierce2623 said:
    and as long as i practice halfway decent digital hygiene and don’t use the internet as my own personal theft tool then I don’t have much to worry about.
    except it is.
    Look at FLOCK as example...sure, if you obey rules should be fine right?

    Wrong. The data is collected regardless and can end up in hands of people who dont like you. (i.e. the cops who have used it for spying/stalking people they like or ex's)

    Data protection is not secure enough to have the mindset of "i'll be fine im not a criminal"
    Reply
  • Pierce2623
    ezst036 said:
    No OS should even be possible to do this.

    I like the guys who support this kind of thing then get bent out of shape that they find out later that they got spied on themselves. Why are you complaining, you got exactly what you asked for.
    And the people complaining about it, like you, ate the samy
    hotaru251 said:
    You paid for a product. You are unable to say "no". That is infringing your privacy rights.



    except it is.
    Look at FLOCK as example...sure, if you obey rules should be fine right?

    Wrong. The data is collected regardless and can end up in hands of people who dont like you. (i.e. the cops who have used it for spying/stalking people they like or ex's)

    Data protection is not secure enough to have the mindset of "i'll be fine im not a criminal"
    You’re ignoring the fact that Dell or HP selling a bunch of meaningless data means they don’t have to push margins on their products as hard to satisfy shareholders. You may say “it doesn’t work that way” but, it actually does. I worked in procurement for a cloud storage company and we started selling some fairly innocuous data because it allowed us to give a good discount on the first three months of our service. Then because we were able to give such a good initial discount, we were able to slightly increase the standard price a small amount. That, in turn, allowed us to procure a large amount of Gen4 U.2 drives and offer a new lower latency tier of storage. So overall, selling a small amount of innocuous data that didn’t amount to much more than connecting names with general locations allowed our company to offer a much better product overall
    Reply
  • Jaywood99
    Can some one explain what GDID stands for Global Device Identifier is ?

    Is there not millions of computers out there with same motherboard and SSD? Same make and model.
    Reply
  • USAFRet
    Jaywood99 said:
    Can some one explain what GDID stands for Global Device Identifier is ?

    Is there not millions of computers out there with same motherboard and SSD? Same make and model.
    Every part has a unique Serial Number.
    Same part number, different serial numbers.

    Much like the VIN for your car.

    A combination of motherboard serial number + drive serial number + browser + browser plugins + yadda yadda yadda....your system is unique.
    Reply