A Windows Device ID Helped Trace an Alleged Scattered Spider Hacker to a Jewelry Heist

Federal prosecutors say a single hardware identifier tied a May 2025 intrusion at a luxury retailer to the online accounts of a 19-year-old.

ThreatVectr NewsdeskAI-assistedPublished Updated · Editor: Lee Brown· 4 min read
Illustration: a darkened luxury jewelry display case at night
Illustration made with AI. Not a photograph of the events described.
Share

Key points

  • U.S. Prosecutors have charged 19-year-old Peter Stokes in connection with a May 2025 break-in at a luxury jewelry retailer, according to a newly unsealed federal complaint.
  • Investigators linked Stokes to the intrusion using a persistent Windows device ID, a unique tag Microsoft assigns to each Windows computer that signs into its services.
  • Microsoft records showed the same device ID appeared on both the attacker account used during the intrusion and personal online accounts prosecutors say belong to Stokes.
  • The case is tied to Scattered Spider, a loose group of mostly young English-speaking hackers known for tricking corporate help desks into resetting employee passwords.

A teenager left a trail his hoodie couldn't hide.

U.S. Prosecutors have charged 19-year-old Peter Stokes over a May 2025 break-in at a luxury jewelry retailer. The retailer's name hasn't been made public in the filing.

How they say they found him is the story.

Investigators relied on a Windows device ID, a unique tag Microsoft quietly assigns to each Windows computer when it signs into Microsoft services, something like a serial number that follows the machine around online. Users don't see it. It doesn't change when you swap accounts.

Microsoft records, first reported by The Hacker News, showed the same device ID sitting behind two very different things: the account the hackers used to maintain their foothold inside the jeweler's network during the May intrusion, and a set of personal online accounts prosecutors say belong to Stokes.

Same machine. Two identities. That's the thread the FBI pulled.

How did investigators actually catch him?

By asking Microsoft who else that computer had logged in as. Once the attacker signed into a Microsoft service from their own laptop, even briefly, that device ID was recorded. When agents later asked Microsoft to look up the same ID against other accounts, personal ones surfaced. Prosecutors say those accounts point to Stokes.

It's a reminder that operational security is hard. Career criminals spend years learning to keep work devices and personal devices separate. Teenagers, generally, don't.

We covered Stokes's extradition from Finland on 1 July in "Scattered Spider Suspect, 19, Extradited From Finland to Chicago"; this week's complaint adds the technical detail of how the FBI says it connected him to the May intrusion.

Who is Scattered Spider?

Stokes is alleged to be part of Scattered Spider, a loose crew of mostly young, English-speaking hackers who've caused enormous damage over the last two years. Their signature move isn't exotic malware. It's a phone call.

Members ring a company's IT help desk, pretend to be a stressed employee locked out of their account, and talk the support agent into resetting the password or moving the two-factor code to a new phone. It's social engineering: manipulating people rather than hacking software. Once inside, they steal data and often bring in a ransomware partner, malicious software that scrambles a company's files until a ransom is paid.

The group has been tied to intrusions at casinos, airlines and retailers on both sides of the Atlantic. Several alleged members, all in their late teens or early twenties, have been arrested in the U.S. And U.K.

Should you worry if you shopped at a luxury jeweler this spring?

Possibly. The complaint doesn't yet detail which categories of personal data were taken, or how many customer records were exposed. Watch your post and email inbox for a breach-notification letter.

Two steps worth taking now. Turn on multi-factor authentication, an extra login code sent to your phone, on any account that reuses the same email address. And treat any call or email referencing a recent jewelry purchase and asking you to confirm card details as suspect: that's exactly the kind of hook this data would enable.

Regulators including the FTC in the United States, and the ICO in the United Kingdom if British customers were caught up in this, would have jurisdiction over any formal breach notification. Neither has published one in this case.

© 2026 Threat Vectr