Scattered Spider Suspect, 19, Extradited From Finland to Chicago
Peter Stokes, a dual U.S.-Estonian citizen, faces conspiracy, intrusion and fraud charges tied to the loose-knit crew behind a string of high-profile enterprise breaches.

Key points
- Peter Stokes, 19, a dual U.S. And Estonian citizen, was extradited from Finland and appeared in Chicago federal court on June 30.
- A judge ordered him held in custody; the Justice Department confirmed the extradition on July 1.
- He faces counts of conspiracy, computer intrusion and wire fraud in the Northern District of Illinois.
- Scattered Spider members have partnered with ALPHV/BlackCat and RansomHub to monetise access through encryption and extortion.
- Prosecutors have signalled more indictments are likely.
Who is Peter Stokes?
Stokes appeared in Chicago federal court on June 30, where a judge ordered him detained. The Justice Department confirmed the extradition on July 1. The indictment, unsealed in the Northern District of Illinois, is not yet public in full. Court records do not detail which specific intrusions he is alleged to have participated in, or what role prosecutors will attribute to him. A detention memo cited flight risk and the transnational nature of the alleged conduct. He did not enter a plea.
What is Scattered Spider?
Scattered Spider, tracked variously as UNC3944 and Octo Tempest, is not a formal ransomware crew in the RaaS mould. It's a loose, English-speaking collective, heavy on Western teenagers, known for aggressive social engineering: SIM swaps, help-desk impersonation, MFA fatigue. Members have partnered with ALPHV/BlackCat and RansomHub to monetise access through encryption and extortion. Our reporting on how service desks keep getting talked out of MFA resets on 24 June 2026 is a direct guide to the technique Scattered Spider has refined.
The September 2023 intrusions at MGM Resorts and Caesars Entertainment are the marquee cases. Caesars paid a ransom. MGM refused. Both suffered significant operational disruption.
Should you worry about more arrests?
Stokes is the latest in a slow-drip series. U.K. Authorities detained a suspected member in Spain last year. Florida charged Noah Urban, who later pleaded guilty. Five others were indicted in California in late 2024 on charges tied to phishing campaigns against telecom and crypto firms. Tyler Buchanan, the Scottish core of the group's 2022 phishing spree, pleaded guilty in U.S. Federal court on 28 May 2026. Prosecutors have signalled more indictments are coming.
Does the Finnish extradition tell us anything new?
The speed is worth noting. Extradition from EU states on cybercrime charges typically runs longer than this case appears to have. That may reflect close cooperation between the FBI's Chicago field office and Finland's National Bureau of Investigation, which assisted the case.
Common questions
What charges does Stokes face?
Conspiracy, computer intrusion and wire fraud in the Northern District of Illinois. He has not yet entered a plea.
What makes Scattered Spider different from other ransomware groups?
The group relies on human-layer attacks rather than purely technical exploits: convincing a service desk to reset an MFA token, phishing an Okta credential, then pivoting from identity into cloud infrastructure. Those techniques don't require any specific arrested individual. The playbook has already been copied by adjacent crews, and the group's recruiting pipeline keeps refilling.
Will arresting members stop the group?
Probably not quickly. Scattered Spider's tradecraft doesn't depend on a small fixed roster. The arrests matter for accountability and deterrence, but defenders shouldn't expect the threat model to shift because one member is in custody in Chicago.



