🔒 A 19-year-old cybercriminal was caught despite using a VPN across multiple countries - because Windows has a tracking number built into every install that a VPN can't hide.
Peter Stokes, arrested in Finland in April and extradited to the US last week, is tied to Scattered Spider, the hacking group behind the 2023 MGM and Caesars casino breaches. The group is linked to 100+ intrusions and over $100 million in extortion.
The FBI didn't crack his VPN. Microsoft handed over his Global Device ID (GDID), a unique identifier baked into every Windows installation at setup. It doesn't change when you update, switch networks, or use a VPN. The only way to reset it is a full OS reinstall.
Investigators matched Stokes's GDID across IP addresses in Estonia, New York, and Thailand, correlating with login times on his Snapchat, Apple, and Facebook accounts. The same device that breached a luxury jewelry retailer and demanded $8 million in ransom also logged into Snapchat and a video game from his real network.
So while VPNs mask your IP address, they were never designed to hide device-level identifiers embedded in your operating system. The tracking can live one layer deeper than the one most people defend.
Read more:
itnews.com.au/news/microsoft-d…
databreachtoday.com/scattered-…
Scattered Spider Suspect Extradited From Finland to US
A suspected member of the notorious Scattered Spider cybercrime group has been extradited from Finland to stand trial in the United States. Peter Stokes, 19, a dualwww.databreachtoday.com

tmw 🌈
in reply to jcrabapple • • •2023 hacking? 19-year-old cyber criminal?
i'm not a math genius, but it sounds like this person was a child at the time.
microsoft, spying on children and tracking them around the internet? creepy!
Netraven
in reply to jcrabapple • • •clonedhuman
in reply to jcrabapple • • •subnetspider
in reply to jcrabapple • • •- Don't committ cyber crime, especially not over your home internet connection
- Don't login with personal accounts to a work PC (especially if it runs Windows)
Loy Hena
in reply to jcrabapple • • •☢️ Waschbär ☢️
in reply to jcrabapple • • •Which in essence means. Microsoft holds the key to a lot of criminals from child abusers to drug and human trafickers. But the choose to back down here?
Or rather the FBI know it could cat awhile breed of other assholes if they would only care enough.
In best case MS would have never done that in order to protect users but well in this day and age and especially with that Zeitgeist in the US right now, they will certainly not walk back on that GDID.
Even if they EU tries
🔥 Mireille Sillander 🔥
in reply to jcrabapple • • •Glyph
in reply to jcrabapple • • •BrianKrebs
in reply to jcrabapple • • •Meh. Microsoft, like all other big companies, will respond to legal process. Given that Microsoft's recent operating systems basically require you to log in to their cloud at startup, this is not particularly surprising to me.
And if motivated to pursue a threat actor who is actively harming their customers, Microsoft can tell a great deal about users. As can Google, or FB/Meta. I always said that if just two of those companies decided to find someone responsible for something, they probably could if they shared information.
Marisa
in reply to jcrabapple • • •Nazo
in reply to jcrabapple • • •visnudeva
in reply to jcrabapple • • •Hyde 📷 🖋
in reply to jcrabapple • • •Mathias Hasselmann
in reply to jcrabapple • • •Now replace „cyber criminal“ with „dissident“.
With this level of permanent surveillance western democracies have become a hoax.
Maddad ☑️
in reply to jcrabapple • • •Dóttir Slæðunnar
in reply to jcrabapple • • •This prompted me to have a very nerdy project morning on my Nobara PC. I don't do the criminal stuff this kid did, but like hell I'm going to assume that this isn't being abused.
So I randomed my machine ID, randomed my MAC address, setup a cron to clear old journal files that don't match my current machine ID, got SSH recovery setup in case I nuked my plasma shell, and everything is running so far.
Nobara Linux.