-
A 19-year-old accused Scattered Spider member was extradited from Finland to the United States in July 2026.
-
Investigators tied him to a jewelry retailer hack that stole 77 GB of data and demanded $8 million.
-
A hidden Windows tool called GDID helped link his online activity to the crime.
A hidden tool inside Windows computers has just played a big role in a major cybercrime case. Investigators used it to help track down a teen suspect accused of hacking companies for money.
The U.S. Department of Justice says the suspect is Peter Stokes. He holds citizenship in both the United States and Estonia. Finnish police arrested him in April 2026. He later moved to the United States for trial. Prosecutors unsealed the case against him in July.
The charges include conspiracy, cyber intrusion, and fraud. Stokes belongs to a hacking group known as Scattered Spider, according to prosecutors. He has not been convicted of any crime. The complaint only lists accusations, not proven facts.
The jewelry store attack that started it all
The case centers on an attack from May 2025. Hackers allegedly targeted a luxury jewelry retailer. They did not break in through code alone. Instead, they used trickery.
The attackers called the company’s IT help desk. They pretended to be real employees. This trick fooled staff into resetting passwords. It also reset security codes tied to those accounts, according to Reuters.
Three employee accounts fell into the hackers’ hands this way. Two of those accounts held high-level access. That access let the hackers move freely inside the company’s systems.
Once inside, the group stayed hidden for a while. They quietly pulled data out of the network. In total, they allegedly grabbed about 77 GB of files. That is a huge amount of information. Large-scale data theft campaigns can affect far more victims, as seen in a Canadian hacker pleads guilty in a Snowflake data theft campaign affecting millions, which involved the theft of data from multiple organizations.
The hackers then made a demand. They wanted roughly $8 million paid in cryptocurrency. The jewelry company refused to pay. Still, the damage added up fast. Investigators say the company lost at least $2 million. Those losses came from cleanup costs and lost business, not the ransom itself.
How Microsoft’s hidden ID helped track him down
One detail stands out in this case. It involves a lesser-known Microsoft tool called the Global Device Identifier, or GDID. Every Windows computer gets a GDID when it connects to certain Microsoft services. This ID stays linked to that one device. It does not change easily, even if the user hides behind other tools.
Investigators built their case step by step. They first gathered records from tech services the suspect used. These included a tunneling tool called ngrok and a separate VPN provider. Both services keep logs of connections, according to a report from The Register.
From there, agents asked Microsoft for help. Microsoft’s own records showed which GDID matched specific internet addresses. That same GDID later showed up again, tied to other online activity linked to Stokes.
Think of a GDID like a name tag glued to one specific computer. It does not reveal who owns that computer right away. Investigators still need extra clues, such as account logins or IP addresses, to connect the dots.
This case shows how those separate clues can add up. Alone, a GDID means little. Combined with other records, it becomes a powerful trail. Reports from CSO Online and The Stack describe it as one piece of a larger puzzle, not a single smoking gun.
What the case means for everyday Windows users
This story does not mean every Windows user faces the same risk. Regular people are not usually targeted this closely. Law enforcement builds cases like this over months, using many data sources at once.
It also does not mean VPNs are pointless. A VPN still hides your internet address from many websites. However, this case shows that other records can sometimes fill in the gaps a VPN leaves open.
Privacy experts have raised concerns about GDID for other reasons too. Some point out that Windows quietly collects a lot of background data. A blog post from ProtonVPN argues this kind of tracking raises bigger privacy questions beyond just criminal cases.
Court documents make clear that GDID played a supporting role here. It was not the only proof used against Stokes. Investigators combined it with service records, IP logs and other digital trails, according to The Record.
The case is still moving through the courts. Stokes remains innocent under the law until a judge or jury says otherwise. His trial will likely reveal more about how investigators built their case, piece by piece.
For now, the story offers a lesson in digital footprints. Even careful hackers leave small traces behind. Sometimes, those traces come from tools built into the very system they use to hide.