HomeSecurityFinland: Arrest of teenager alleged to be a hacker of the Scattered Spider group

Finland: Arrest of teenager alleged to be a hacker from the Scattered Spider group

The 19-year-old suspect – who reportedly went by the alias “Bouquet” – is accused of being an active member of the cybercrime group Scattered Spider. An important lesson for all: If you don’t want to attract attention as a cybercriminal, don’t show off your diamond necklace with the inscription “HACK THE PLANET” on Snapchat, or pose like a crime boss from The Sopranos while the FBI is allegedly closing in on you.

See also: Scattered Spider: Leading member pleads guilty

Scattered Spider

That's the picture US prosecutors have formed of a teenager who was arrested earlier this month at Helsinki airport while trying to board a flight to Tokyo.

The 19-year-old suspect – who reportedly used the alias “Bouquet” – is accused of being an active member of the Scattered Spider and now faces charges of wire fraud, conspiracy and computer intrusion, based on a six-count federal complaint secretly filed in Chicago last December and recently obtained by the Chicago Tribune. The US is seeking his extradition.

Prosecutors allege that the teenage suspect participated in at least four Scattered Spider attacks, with the first taking place in March 2023 – just a few months after his 16th birthday. This first attack used a classic social engineering tactic to reset an employee’s 2FA protection, after which the attackers allegedly obtained sensitive employee data.

A subsequent attack allegedly took place in May 2025, when the group targeted a “multi-millionaire luxury goods retailer” by calling its IT support department and impersonating staff to request password resets. Within hours, prosecutors say they had compromised two privileged administrator accounts and extracted 100GB of corporate data.

The next email reportedly had the subject line “IMPORTANT: WE STOLE YOUR DATA, CONTACT US IMMEDIATELY” and demanded a ransom of US$8 million. The merchant reportedly refused to pay, although recovery costs reportedly exceeded US$2 million. Although the documents do not name the victim, the timing matches attacks on British retailers Marks & Spencer and Harrods.

See also: Cognizant TriZetto: Data breach affects 3.4 million patients

Finland: Arrest of teenager alleged to be a hacker from the Scattered Spider group

It is alleged that “Bouquet” helped investigators build the case against him by flaunting his wealth. Court documents describe trips between Dubai, Thailand, Mexico and New York, along with Snapchat photos of cash, watches and the aforementioned “HACK THE PLANET” diamond necklace.

The complaint also alleges that the Scattered Spider group was taunting law enforcement, with a screenshot from 2024 showing failed login attempts with the caption “F*** off, FBI.”

Scattered Spider is a loosely organized English-speaking collective of teenagers and young adults that became notorious after the 2023 attacks on MGM Resorts and Caesars Entertainment.

Their attack methodology avoids complex zero-day vulnerabilities, having discovered that it's simpler to make a phone call to IT support and convince someone on the other end to reset a password or MFA token.

The last few weeks have not been kind to alleged members of the Scattered Spider collective, with 24-year-old British man Tyler Robert Buchanan pleading guilty in California recently to SMS phishing attacks that allegedly netted at least $8 million in cryptocurrency.

Scattered Spider’s success as a hacker is essentially based on one weak link – your IT support department. Make sure your IT staff has a strong, mandatory process for verifying anyone who calls requesting a password reset or MFA change. Additionally, make sure your IT staff knows that they won’t be in trouble if they delay a request, even if the caller claims to be the CEO.

See also: ShinyHunters: New vishing campaign with hundreds of targets

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

Finland: Arrest of teenager alleged to be a hacker from the Scattered Spider group

You should also consider moving away from SMS-based MFA where you can, in favor of phishing-resistant alternatives like hardware security keys. Test your staff regularly, because attackers certainly will.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS