Scattered Spider teen hacker “Bouquet” extradited to US to face charges, DOJ says
A teenage hacker accused of being part of the notorious Scattered Spider ransomware group has been extradited from Finland to the US and is now facing multiple federal hacking and fraud charges.

Image by Cybernews.
A teenage hacker accused of being part of the notorious Scattered Spider ransomware group has been extradited from Finland to the US and is now facing multiple federal hacking and fraud charges.
- An alleged Scattered Spider teen hacker known as “Bouquet” is extradited to the US to face federal charges.
- Prosecutors say the 19-year-old flaunted cash, jewelry, and luxury travel while allegedly helping carry out Scattered Spider ransowmare attacks.
- Court records reveal how the teen allegedly used social engineering schemes to infiltrate companies and demand multimillion-dollar ransoms.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The US Department of Justice (DoJ) on Wednesday announced that 19-year-old Peter Stokes – a dual citizen of the US and Estonia – was extradited last week, making his first appearance in a Chicago federal court on Tuesday.
Prosecutors say Stokes – allegedly operating under the online persona "Bouquet" – is an active member of Scattered Spider, the English-speaking cybercrime group accused of carrying out more than "100 network intrusions" since March 2023, extorting more than $100 million in ransom payments from its victims.
“Scattered Spider has repeatedly targeted US companies, extorting employees, inflicting millions of dollars in losses, and disrupting essential operations,” said Assistant Director Brett Leatherman of the FBI’s Cyber Division.
The Chicago Tribune first reported Stokes was arrested on April 10 in Helsinki while trying to board a flight to Tokyo. The FBI was said to have been building a case against the teen.
Who is “Bouquet”?
According to the criminal complaint, unsealed Tuesday, Stokes faces a slew of charges, including conspiracy to commit wire fraud, conspiracy to commit computer fraud and abuse, wire fraud, and aggravated identity theft.
The court filings detail charges stemming from four specific cyber incidents, including a heist involving a multi-billion-dollar jewelry retailer and an $8 million ransom demand, as well as the seizure of two 2TB hard drives. Prosecutors say the earliest alleged attack took place when Stokes was just 16 years old.
That attack was said to have targeted an online communications platform by convincing its IT support to reset an employee's two-factor authentication, illustrating the group's earliest reliance on social engineering.
Prosecutors say before Stokes' arrest, he flaunted a lavish lifestyle, posting photos from trips to Dubai, Thailand, Mexico, and New York, along with cash and expensive jewelry, according to court records reviewed by the Tribune. He was also known to wear a diamond necklace reading "HACK THE PLANET," which he showed off on social media.
Stokes was even said to have created a meme of himself and his fellow hackers – editing a The Sopranos meme portraying the group as mob bosses – placing his own name over crime boss Carmine Lupertazzi Sr. – and posting it on social media.
Unsurprisingly, the complaint said that Stokes and other members often mocked the FBI in private chats and through memes while investigators were pursuing them.
As witnessed in previous Cybernews coverage in the last three years, the gang has been known to use its public-facing social media channels to taunt and threaten both law enforcement and victims.
Inside Scattered Spider's social engineering tactics
Scattered Spider – also known as UNC3944, Scatter Swine, Oktapus, Octo Tempest, Storm-0875, and Muddled Libra – has been linked to several widely publicized hacks, including the 2023 cyberattacks on MGM Resorts and Caesars Entertainment in Las Vegas.
The group has also been blamed for last year's devastating and months-long ransomware attacks on British retailer Marks & Spencer and Jaguar Land Rover (JLR), carried out by the rebranded “Scattered, LAPSUS$ Hunters” hacker collective. Those attacks led to financial losses of more than $300 million and $2.5 billion, respectively.
The cybercriminal group is known for using sophisticated social engineering attacks to trick employees into giving up their credentials, ultimately allowing the hackers to gain unfettered access to their employers' corporate networks.
Once in the IT system, Scattered Spider is known not only for stealing and encrypting the victim’s data but also for rendering those systems inoperable, while pressuring the victim to pay an exorbitant ransom in cryptocurrency.
In the jewelry store attack, the DoJ says Stokes and his fellow gang members breached the company’s systems using an IT help desk scheme in May 2025 – a known tactic used by the savvy hackers.
Scattered Spider allegedly called the company's IT help desk, impersonated an employee, reset credentials, and gained access, prosecutors said.
After exfiltrating 100GB of data, the group demanded an $8 million payout but was left empty-handed when the company’s security teams booted the hackers from its computer systems.
Although no ransom was ever paid, the DoJ says the high-end retailer still suffered at least $2 million in losses from the business disruption, investigations, and recovery costs.
CISA warned Scattered Spider was expanding its playbook
The US Cybersecurity and Infrastructure Security Agency (CISA) issued a warning advisory detailing the group's tactics, techniques, and procedures (TTPS) last July, following an escalation in successful attacks across many sectors, ranging from retail to airlines to manufacturing.
The group had stepped up its signature attacks on IT help desk workers, moving from targeting direct employees to targeting IT workers at third-party vendors, enabling it to infiltrate multiple companies from a single breach.
The cybercriminals were found targeting companies’ Snowflake accounts for initial network access, as well as Slack, Microsoft Teams, and Microsoft Exchange email accounts to gather intelligence to spear-phish employees.
“The malicious attacks from Scattered Spider caused widespread disruption to businesses and organizations throughout the United States,” said US Attorney Andrew S. Boutros for the Northern District of Illinois.
“These charges underscore our unwavering commitment to keeping pace with technologically savvy criminal actors and holding accountable those who seek to profit from cyber intrusions, including those located in foreign jurisdictions who do harm to American businesses and victims,” Boutros said.
Stokes' arrest and subsequent extradition were carried out in coordination with Interpol and Finnish authorities as part of the FBI’s Operation Riptide, an ongoing campaign targeting criminal actors, infrastructure, and the financial networks that support them.
In 2025, authorities made several arrests in connection with Scattered Spider attacks, with four suspected group members arrested in the UK and another UK national arrested in Spain. All the suspects were between 17 and 22 years old.
Check if your data has been leaked
Unlock more exclusive Cybernews content on YouTube