HomeSecurityArrest of alleged member of the Scattered Spider group

Arrest of alleged member of the Scattered Spider group

An alleged member of the Scattered Spider has been extradited from Finland to the United States to face federal charges related to conspiracy, cyberattack and fraud. U.S. authorities said the case is another step in their ongoing efforts to prosecute individuals accused of participating in high-profile cybercrime operations linked to the notorious group.

Article image: Alleged Scattered Spider Member Arrested in Finland, Extradited to US.

Peter Stokes, 19, a U.S. and Estonian citizen, made his first appearance in federal court in Chicago after being extradited from Finland. According to the U.S. Department of Justice, Stokes was arrested by Finnish authorities in April on an Interpol Red Notice and was extradited to the United States last week. A criminal complaint, filed in the Northern District of Illinois, accuses him of participating in cyberattacks carried out as part of the Scattered Spider group.

Scattered Spider: Linked to More than 100 Invasions

According to the complaint, Scattered Spider, also known as Octo Tempest, UNC3944 and 0ktapus, has been linked to more than 100 network intrusions. Authorities allege that the group's activities have led to ransom payments exceeding $100 million and additional damages of many millions more.

Researchers said the group targeted companies across the United States by gaining access to employee accounts through fraudulent methods. Once inside corporate networks, the attackers allegedly encrypt data or export sensitive information to remote servers, before demanding payments in cryptocurrency to restore access or prevent the stolen data from being publicly released.

Complaint for Alleged Cyberattack on Luxury Retailer

The criminal complaint describes an alleged cyberattack that occurred in May 2025 involving a luxury jewelry. Federal prosecutors allege that Stokes and other conspirators hacked into the retailer’s computer systems, extracted company data and demanded approximately $8 million in cryptocurrency as a ransom. According to court documents, the retailer’s security team was able to remove the attackers from its network before any ransom payment was made.

See also: Connections between LAPSUS$, Scattered Spider and ShinyHunters

Although the company did not pay the ransom, authorities said it suffered losses of at least $2 million due to business interruption, investigation costs and mitigation efforts.

Scattered Spider - SecNews.gr

Operation Riptide Targets Cybercrime Networks

The extradition and criminal charges were announced by the Department of Justice, the U.S. Attorney's Office for the Northern District of Illinois and the FBI. The investigation also involved the FBI's Copenhagen Police Attaché Office, the FBI's Las Vegas Field Office, the Department of Justice's Bureau of International Affairs and the Finnish National Bureau of Investigation.

Officials said the case is part of Operation Riptide, an ongoing FBI campaign focused on disrupting cybercriminal activities, infrastructure, financial networks and fraud schemes targeting Americans.

According to the FBI, Americans reported losses of more than $20 billion from cybercrime last year, a 26% increase compared to the previous year.

See also: Scattered Spider targets the financial sector

Authorities Report International Cooperation

Assistant Attorney General A. Tysen Duva said the charges stem from years of investigative work by the Department of Justice, the U.S. Attorney's Office and the FBI, adding that authorities will continue to work together to pursue cybercriminals operating across international borders.

Arrest of alleged member of the Scattered Spider group

U.S. Attorney Andrew S. Boutros said the alleged attacks caused significant disruption to businesses across the United States and stressed the government's commitment to prosecuting individuals involved in cyberattacks.

FBI Special Agent Douglas S. DePodesta also highlighted the role of international law enforcement partnerships in identifying alleged members of the hacking group and pursuing cross-border cybercrime investigations.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: Scattered Spider: When Browsers Become an Attack Surface

Recent Guidance on the Scattered Spider Threat

The arrest follows recent law enforcement efforts targeting the Scattered Spider threat group. In July 2025, the FBI and CISA published guidance detailing the group's latest attack techniques, including the use of DragonForce to encrypt VMware ESXi servers.

The advisory urged organizations to maintain isolated offline backups, implement phishing-resistant multi-factor authentication (MFA) , and implement application controls to manage software execution.

The Justice Department stressed that the complaint against Stokes contains only allegations. As with all criminal cases, he is presumed innocent until proven guilty in court.

The Peter Stokes case is yet another episode in the international effort to tackle organized cybercrime groups, which in recent years have become one of the biggest threats to businesses, government agencies and critical infrastructure. Scattered Spider remains under the microscope of law enforcement authorities, with recent arrests showing that cross-border cooperation between security agencies is intensifying, even when the perpetrators operate from different countries.

At the same time, experts warn that the group’s tactics continue to evolve, with an emphasis on social engineering, account compromise and ransomware attacks. For organizations, strengthening cybersecurity mechanisms, training staff and implementing modern protection technologies remain the most effective defenses against threats that are becoming increasingly organized and financially devastating.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS