Hook

Their other posts in the index, biggest breakout first.
scattered spider member used a VPN, tunneling tools and IP's across three countries and the FBI caught them anyway because of a tracking ID, Microsoft back into every Windows installed. Every Windows installation gets assigned something called a GID, global device identifier, persistent device level ID used for telemetry and licensing. It survives OS updates. Does not rotate when your IP changes. There's no opt-out setting. The only way to get a new one is through a fresh Windows installed. That's how Peter Stokes got caught. The 19 year old highlighted scattered spider member who is just extradited to the United States. May 2025 breach of a luxury jewelry retailer, the crew social engineer the IT help desk into resetting multi-factor authentication. Set up a tunnel to steal 77 GB of data before demanding $8 million. Stock did this all behind a VPN. Microsoft records show his GID hitting the sign-up page at the exact minute. Attacker account was created. In that same device kept surfacing IP's, TNL, New York, Thailand, right along sight is personal on Snapchat, matching his state department's travel records. VPN hit the network, but it never hit the machine. There's no published Microsoft policy when GDPR data gets shared with law enforcement. There's no consumer oversight. There's no transparency report that breaks it out. Most people learned about this identifier through a court filing. Fall for more, Cyber News.