Microsoft Device Identifier Ties Scattered Spider Hacker to Arrest

How a Windows device identifier gave investigators the break they needed to track down a cybercriminal.

By Central
A Microsoft GDID linked the hacker to the crime, bypassing VPNs and proxies.
Highlights
  • The GDID linked the hacker's device to the exact minute of the ngrok account creation.
  • The same device was used for personal accounts, including Snapchat and Facebook, aiding identification.
  • Scattered Spider has been linked to over 100 intrusions and $100 million in ransom payments.

Federal prosecutors have revealed that a Microsoft Global Device Identifier (GDID) played a decisive role in identifying and ultimately arresting an alleged member of the notorious Scattered Spider cybercriminal group, a case that underscores the limits of anonymity infrastructure in the face of persistent endpoint telemetry. Peter Stokes, a 19-year-old dual U.S. and Estonian citizen, was taken into custody in Finland on April 10, 2026, as he attempted to board a flight to Japan, according to a superseding complaint filed in the Northern District of Illinois. He was found carrying two two-terabyte hard drives and is now being held pending extradition on charges that include violations of the Computer Fraud and Abuse Act, wire fraud, and conspiracy.

Scattered Spider Ties and an $8 Million Extortion Attempt

Prosecutors allege that Stokes operated under the handles “Bouquet,” “Spencer,” and “Jordan” and was a member of Scattered Spider — also tracked as Octo Tempest, UNC3944, and 0ktapus. The group has been linked to more than 100 intrusions and over $100 million in ransom payments. Stokes was extradited to the United States following an Interpol Red Notice and now faces federal charges in Chicago for conspiracy, computer intrusion, and fraud. The complaint centers on the breach of a multibillion-dollar luxury retailer, identified only as “Company F,” where attackers deployed voice-phishing calls to the IT help desk on May 12, 2025. By impersonating employees and triggering multi-factor authentication resets, they compromised three accounts—including two high-privilege IT administrator accounts—within two to three hours. An ngrok agent was then downloaded and executed on a Company F virtual server, opening an encrypted tunnel to bypass perimeter defenses. Data exfiltration followed via Teleport.sh and Amazon S3, totaling at least 77 GB, after which a ransomware deployment was thwarted and an $8 million extortion demand went unpaid.

How Microsoft’s Global Device Identifier Broke the Cover

Court documents reveal that the breakthrough in attribution came from a Microsoft Global Device Identifier (GDID)—a unique code embedded in every Windows installation. GDIDs are used by Microsoft for diagnostic telemetry, crash reporting, feature-usage analysis, and license verification, and their persistence across system states made them a powerful forensic anchor. Investigators matched the GDID to the exact minute the ngrok account was created on May 12 at 19:21 UTC, linking it to IP address 68.235.46.168—a Tzulo-hosted VPN proxy in Mount Prospect, Illinois. The same device later appeared browsing Company F’s website through the same proxy. From that pivot point, the FBI correlated the GDID’s IP history against accounts known to belong to Stokes: Apple, Snapchat, Facebook, and even a Ubisoft/Growtopia game login. The overlaps were precise. The same device and personal accounts surfaced on identical IPs geolocated to Tallinn, Estonia; New York; and Thailand, each matching Stokes’s State Department travel records and social-media posts from luxury hotels. The VPN masked the network endpoint, but the Windows installation identifier did not rotate with it.

Why the GDID Case Matters for Operational Security

This case offers a stark lesson for anyone relying on VPNs and proxy services alone to maintain anonymity: infrastructure at the network layer can be bypassed by persistent identifiers at the endpoint. A GDID is not something a user can easily rotate or purge without reinstalling Windows or swapping major hardware components. There is no published, comprehensive Microsoft policy detailing when GDID data is shared with law enforcement, no consumer opt-out mechanism, and no transparency report that specifically breaks out GDID disclosures. The practical implication is that any Windows device used for both legitimate personal activity and illicit operations leaves a durable forensic link that can be cross-referenced across multiple platforms and jurisdictions.

What Organizations and Security Teams Should Do Now

For security teams, this case reinforces the critical importance of endpoint visibility. A GDID is just one example of the kind of persistent telemetry that can provide investigators with a breakthrough, but it also highlights that attackers who control the endpoint can still be identified by what they cannot control—the unique hardware and software fingerprints their devices leave behind. Organizations should ensure they have multi-layer endpoint protection solutions in place that include real-time detection of anomalous behavior, such as the deployment of tunneling tools like ngrok on internal servers. They should also implement strict controls around IT help desk processes to prevent social engineering attacks, particularly around MFA resets and privileged account management. For individual users, the case is a reminder that digital privacy requires more than a VPN: endpoint hygiene, separate devices for sensitive activities, and awareness of persistent identifiers are equally important. Anyone concerned about their digital footprint should consider using dedicated endpoints for high-risk activities and regularly auditing the telemetry their devices expose. The Scattered Spider case proves that anonymity is only as strong as the weakest identifier, and in this instance, that identifier was baked into the operating system itself.

Share This Article