Teen Hacker Drains $100M — Extradited

A person in a hoodie working on multiple computer screens in a dimly lit room

A 19-year-old alleged Scattered Spider hacker has been flown into U.S. custody over a $100 million cyber-extortion wave that shows how easily American companies can be gutted from a teenager’s laptop.

Story Snapshot

  • Federal agents extradited 19-year-old dual U.S.–Estonian citizen Peter Stokes, accused Scattered Spider member “Bouquet,” to face hacking and fraud charges in Chicago.
  • Prosecutors say he joined a teen-led cyber gang, hit at least four companies starting at age 16, and helped fuel more than $100 million in ransom attacks.
  • A May 2025 attack on a luxury retailer allegedly stole 100 gigabytes of data and demanded an $8 million crypto ransom, though the victim refused to pay and still ate $2 million in losses.
  • The Trump administration’s Justice Department now has to balance tough punishment for high-tech crime with due process for a suspect who started hacking as a minor.

Who Peter Stokes Is And Why Scattered Spider Matters

Federal prosecutors say Peter Stokes is a 19-year-old dual citizen of the United States and Estonia who operated online under the handle “Bouquet.” According to a six-count complaint filed in the Northern District of Illinois, he is an alleged member of Scattered Spider, a loosely organized cybercrime group that law enforcement links to more than 100 network intrusions and over $100 million in ransom payments worldwide. Agents describe the crew as teen-heavy, decentralized, and focused on social-engineering their way into corporate systems rather than writing elite code from scratch.

The U.S. Department of Justice says Microsoft first tied Stokes’ devices and accounts to Scattered Spider activity in a 2024 criminal referral that helped investigators match “Bouquet” to a real name and home city. Prosecutors later secured a warrant and, in December 2025, filed wire fraud, conspiracy, and computer intrusion charges under seal, laying out at least four intrusions since March 2023. Officials say one of those attacks happened when Stokes was just 16, raising hard questions about when a teenager crosses the line from “kid on a keyboard” to full-on organized criminal.

How The Alleged $8 Million Retail Hack Worked

Court filings describe a May 2025 attack on a multibillion-dollar luxury retailer, identified only as “Company F,” as the centerpiece of the case. Investigators say Stokes and others called the company’s information technology help desk, pretended to be locked-out employees, and talked staff into resetting login credentials. With those fresh passwords, the attackers allegedly jumped into administrator accounts, moved deeper into the network, and claimed to steal about 100 gigabytes of sensitive data, including payment information and internal files.

Prosecutors say the gang then sent a follow-up message with the subject line “IMPORTANT: WE STOLE THE DATA, CONTACT UMMEDIATELY,” demanding an $8 million ransom in cryptocurrency and threatening to leak the data if the company refused. The retailer held the line and did not pay, but still reported more than $2 million in costs from incident response, remediation work, and business disruption. For many readers, that number underscores how fragile large brands can be when a single phone call tricks one help-desk worker, and why strong private-sector defenses matter as much as federal crackdowns.

Airport Arrest, Extradition, And What Evidence The Feds Say They Have

According to Justice Department statements and media reports, Finnish authorities arrested Stokes at Helsinki Airport on April 10, 2026, as he tried to board a flight to Japan. He was flagged on an international Red Notice, detained, and found carrying two two-terabyte hard drives that U.S. investigators now treat as key digital evidence. The United States requested extradition to Chicago, and Finland agreed, sending him into American custody to face conspiracy, computer fraud, and wire fraud counts under federal law.

Investigators say those hard drives may hold logs of stolen data, ransomware tools, or encrypted chats that connect “Bouquet” to Scattered Spider operations, but full forensic results have not been made public yet. Another piece of the puzzle is testimony from accused group leader Tyler Buchanan, who pleaded guilty in 2026 and admitted helping steal at least $8 million through similar schemes, tying key infrastructure back to Scattered Spider. So far, Stokes’ defense team has not publicly challenged the government’s technical evidence, the Microsoft referral, or the claimed handle-to-identity link, leaving the prosecution narrative mostly unanswered in the court of public opinion.

What This Means For Cybersecurity, Due Process, And Conservative Priorities

For Americans who value law and order, this case shows both the promise and the risk of aggressive cyber enforcement. The Trump administration’s Justice Department is using extradition, cross-border warrants, and corporate partnerships to hunt down hackers who hit U.S. businesses from abroad, instead of shrugging and blaming “sophisticated actors” somewhere overseas. That is good news for small businesses, energy companies, hospitals, and local governments that cannot survive multimillion-dollar ransom demands or days of shutdown.

At the same time, the Stokes case highlights how easily powerful tools can slip into a gray zone if Americans stop watching. Prosecutors are asking a jury to hold a now-adult suspect fully responsible for conduct that allegedly started at 16, in a group built largely out of teenagers recruited on gaming forums and chat apps. The criminal complaint is not yet fully public, and there has been no trial verdict, which means conservatives who care about the Constitution should insist on transparent evidence, proper counsel, and a real chance for the defense to test every claim in open court.

Sources:

binance.com, cyberscoop.com, securityweek.com, cyberdaily.au, thehackernews.com, bbc.com, linkedin.com, infosecurity-magazine.com, pmc.ncbi.nlm.nih.gov