A major player in the notorious hacking group Scattered Spider has been extradited to the US to face charges related to a series of high-profile cyberattacks. Peter Stokes, also known as “Bouquet,” was arrested in Finland in April while attempting to board a flight to Japan and is now accused of participating in the group’s activities.
Scattered Spider, which has operated under various aliases including 0ktapus and Octo Tempest, has been linked to over $100 million in ransom payments from its victims. The group has carried out attacks on at least 100 organizations worldwide, including a high-profile hacking campaign against Salesforce in 2025 that saw the personal data of thousands of users compromised.
Stokes is alleged to have been part of a team that hacked into the computer system of a luxury jewelry retailer in May 2025, stealing sensitive data and demanding an $8 million ransom in cryptocurrency. Although no payment was made, the attack caused significant disruption to the business, resulting in losses of at least $2 million.
This development comes as authorities continue to crack down on Scattered Spider’s operations. In April, UK national Tyler Robert Buchanan pleaded guilty to his role in the group’s activities, and several other alleged members have been charged or arrested over the past year. The group announced its retirement last September following a series of high-profile attacks against the retail, insurance, and aviation industries.
The extradition of Stokes marks another significant victory for law enforcement agencies in their efforts to disrupt Scattered Spider’s operations. As we’ve seen with other major hacking groups, dismantling these organizations often requires a sustained effort from authorities around the world working together to track down and apprehend key players like Stokes.
Scattered Spider’s activities have had far-reaching consequences for its victims, not only in terms of financial loss but also in terms of reputational damage. The group’s modus operandi involves hacking into computer systems and stealing sensitive data, which is then used to extort ransom payments from the affected organizations.
The fact that no payment was made in this particular case suggests that the victim may have been able to mitigate some of the potential damage by quickly evicting the hackers from their network. However, the disruption caused by the attack still resulted in significant losses for the business.
For businesses looking to avoid becoming victims of similar attacks, it’s essential to prioritize cybersecurity and take proactive measures to protect themselves against hacking attempts. This includes implementing robust security protocols, conducting regular vulnerability assessments, and staying informed about emerging threats and vulnerabilities.
In this case, Stokes’ extradition serves as a reminder that law enforcement agencies are working tirelessly to disrupt the activities of major hacking groups like Scattered Spider. As we continue to see more high-profile arrests and convictions, it’s clear that these efforts are having a significant impact on the global threat landscape.
Source: SecurityWeek — 2026-07-03