According to the United States Department of Justice, Peter Stokes, a 19-year-old man of dual nationality, has been extradited to the United States and is facing criminal charges related to the hackered Spider. According to the prosecution, he was suspected of involvement in a cyber invasion of a high-end United States jewellery retailer and, after stealing the data, demanded approximately $8 million in encrypted money.
Diamond retailers refused to pay after the invasion.
Prosecution documents indicate that the incident occurred in May 2025. According to the prosecution, the assailants impersonated as company employees, initiated a fishing call to the technical support station, requested the replacement of the password and subsequently obtained access to several staff accounts, including those with higher privileges.
According to the United States Department of Justice, the invaders subsequently stole company data and filed a request for an encrypted ransom. The retailer eventually removed the attackers from the internal network and did not pay the ransom, but still suffered at least $2 million in losses due to business interruptions, investigations and emergency disposal.
Scattered Spider was accused of multiple cases of encrypted extortion.
According to the Ministry of Justice, Scattered Spider is also known as Octo Tempest, UNC 3944 and 0ktapus. The organization was alleged to have been involved in over 100 cyber-invasions, and the related ransom payments totalled over $100 million.
According to the prosecution, the group has been using social engineering, account taking, data theft and encrypted extortion for a long time, mainly against business victims. In 2024, the United States prosecution also indicted five other individuals associated with the organization, in cases involving cyber fishing, SIM card transfers and at least $11 million in stolen encrypted currency.
It also shows that the organization ' s activities are not limited to the theft of business data and that some cases have been extended to direct theft of digital assets, including attacks against victims associated with encrypted trading platforms.
There's been a drop in ransom payments, and law enforcement is still being scaled up.
Despite the increasing number of businesses refusing to pay ransoms, encrypted money remains a common method of collecting money for extortion software groups. Chainalysis previously stated that in 2024, the scale of the extortion software had declined by 35 per cent, owing to law enforcement operations, sanctions and increased business resilience.
However, in its 2026 extortion software report, Chainalysis added that in 2025 the groups in question still received more than $820 million in payments on the chain, a decrease of about 8 per cent compared to 2024, but an increase of 50 per cent in the number of alleged attacks. This means that actual payments have been reduced, but the blackmail pressure on businesses has not disappeared.
The role of chain tracking in cybercrime investigations is again reflected in cases. Law enforcement usually combines wallet addresses, exchange records and financial flows to restore the link between encrypted transactions and real identity to facilitate subsequent prosecution.
The Ministry of Justice indicated that the case was part of the FBI “Operation Riptide” operation, which targeted cybercrime personnel, infrastructure and related financial networks. At the same time, the prosecution emphasizes that as long as the attack affects United States businesses or their clients, even if the suspect is abroad, he may face United States prosecution.
