The U.S. Department of Justice has charged 19-year-old dual U.S.-Estonian national Peter Stokes in a case linked to the hacking group Scattered Spider. After being extradited to the United States, Stokes appeared in federal court in Chicago. In a July 1 statement, the DOJ said Finnish authorities arrested him in April under an Interpol Red Notice. Prosecutors filed charges including conspiracy, cyber intrusion, fraud, and related offenses. The department said the allegations remain unproven, and Stokes is presumed innocent unless convicted in court.
Luxury jewelry retailer targeted in failed $8 million crypto extortion attempt
The complaint focuses on a May 2025 intrusion at a luxury jewelry retailer. Prosecutors allege Stokes and others used phishing calls to the company’s technology help desk while posing as employees seeking password resets. The attackers then allegedly gained access to employee accounts, including accounts with elevated privileges. According to the DOJ, the group stole company data and demanded about $8 million in cryptocurrency.
The retailer did not pay. It removed the intruders from its network, but prosecutors said the company still suffered at least $2 million in losses tied to business disruption, investigation costs, and response efforts. The allegations point to a familiar access path: social engineering aimed at internal support channels, with help-desk impersonation still functioning as an effective way into corporate systems.
Scattered Spider tied by prosecutors to more than 100 intrusions
The DOJ said Scattered Spider is also tracked as Octo Tempest, UNC3944, and 0ktapus. Prosecutors linked the group to more than 100 network intrusions and over $100 million in ransom payments. The methods described by the department include social engineering, account takeovers, data theft, and crypto extortion directed at corporate victims.
In a separate 2024 case, U.S. prosecutors charged five people tied to Scattered Spider over alleged phishing, SIM swapping, and at least $11 million in stolen cryptocurrency. That case involved victims at companies and a crypto exchange, showing that the group’s activity was not limited to corporate data breaches and could extend into direct digital asset theft.
Ransomware payments are falling, but pressure on companies remains
The case lands at a time when ransomware groups continue to rely on crypto payments even as more victims refuse to pay. Chainalysis said ransomware cash-outs fell 35% in 2024, citing law enforcement action, sanctions, and stronger recovery planning as factors disrupting criminal networks. In its 2026 ransomware report, Chainalysis said threat actors received more than $820 million in on-chain payments in 2025, about 8% lower than 2024, while claimed attacks rose 50%.
The DOJ said the Stokes case is part of the FBI’s Operation Riptide, which targets cybercrime actors, infrastructure, and financial networks. The case also highlights why blockchain tracing remains central to these investigations: authorities can connect wallets, exchange records, and transaction flows to real-world activity. In another recent action, U.S. prosecutors charged alleged operators of the AudiA6 crypto laundering network, which was accused of processing more than $389 million in transactions.
The department’s position is clear in this filing: suspects based outside the United States can still face U.S. charges when attacks hit American businesses or their customers. That approach keeps legal pressure on cyber extortion groups using cryptocurrency to demand ransom or move proceeds.

