A Silent Windows Identifier Exposed a Hacker: How the FBI Arrested a Scattered Spider Member Despite a VPN
Despite using a VPN and IPs in three countries, the FBI tracked a Scattered Spider member via a stable Windows identifier (GDID) that appeared on the ngrok signup page in the same minute. A lesson in OpSec and privacy.
The hacker thought he was safe behind a virtual private network (VPN) and IP addresses spread across three countries. But what he did not account for was that his own device left a stable fingerprint that no VPN changes. This is the story of how an internal identifier in Windows helped the FBI track down and arrest Peter Stokes, the 19-year-old accused of belonging to the notorious hacking group Scattered Spider, despite all the layers of anonymity he used.
The Case in Brief
According to a criminal complaint filed in the Northern District of Illinois, Stokes (a US-Estonian citizen with aliases including "Bouquet") is accused in a May 2025 attack on a luxury jewelry company the documents refer to as "Company F." He was arrested in Helsinki on April 10 while trying to board a flight to Japan, then extradited to the United States where he remains in custody awaiting trial, charged with conspiracy, computer intrusion, and fraud. The Scattered Spider group (also known as Octo Tempest and UNC3944) is credited with more than a hundred attacks and extortion exceeding one hundred million dollars.
What Is the "Global Device Identifier" (GDID)?
The key to the case is an identifier called GDID (Global Device Identifier): a unique number Microsoft assigns to every Windows installation, used for legitimate technical purposes like diagnostic telemetry, crash reports, feature-usage analysis, and license verification. The crucial point is that this identifier is "stable and stubborn": it does not change when you switch your IP address via VPN, survives system updates, and changes only with a fresh Windows reinstall. So tightly is it tied to the device that swapping a major hardware component may invalidate the Windows activation itself.
The Fatal Mistake: One Minute Revealed Everything
Here lies the heart of the story. The hacker created an account on the ngrok tool (a legitimate tunneling tool sometimes used to build tunnels into compromised networks) via a VPN address, thinking it untraceable. But Microsoft's records showed that the same GDID (ending in 6755467234350028) reached the ngrok signup page at the exact same moment the account was created, on May 12, 2025, at 19:21 UTC. One minute, one device, one fingerprint — enough to open a crack that widened all the way to an arrest warrant.
How Did They Link the Device to the Human?
The identifier alone convicts no one; the real work was in correlating it. Investigators at the Chicago field office, within "Operation Riptide," compared the IP history associated with this GDID against accounts known to belong to Stokes: Apple, Snapchat, Facebook, and even a Ubisoft gaming login tied to Growtopia. The overlaps were specific: the same device and his personal accounts appeared on identical IP addresses in Tallinn (Estonia), New York, and Thailand, matching his official travel records and photos he himself posted from luxury hotels on Snapchat. Logging into his personal account from the same address ended the mystery of his identity.
The Technical Lesson: The Network Layer Is Not the Device Layer
The fundamental lesson of this case is that a VPN hides only the "network layer," that is, the externally visible IP address. But it does nothing about what the operating system itself "broadcasts" to its developer's servers. As the case's technical analysis summed up: "the VPN masked the network endpoint, but the Windows installation identifier did not rotate with it." Anonymity infrastructure protects the connection layer, not the endpoint (the device). This is a principle security professionals know well: hiding your address does not mean hiding your device.
The Troubling Side: A Question for Everyone, Not Just Criminals
Although the case ended with the arrest of a suspect in serious crimes, it raises a question that concerns the ordinary user too. According to reports, there is no detailed public policy specifying when GDID data is shared with law enforcement, no announced opt-out mechanism for the user, and no transparency report detailing requests for this specific identifier. This means, according to specialists, that anyone who values their privacy should assume their device leaves a stable trace no matter how they hide their network. No need to panic, but a fact to factor in. For those who want to reduce what is broadcast, diagnostic data can be set to the minimum in Windows privacy settings — though that does not remove the GDID itself.
This case remains a double lesson. For defenders and digital forensic investigators, it is a reminder that small "OpSec" mistakes — like using a personal device in a criminal operation — defeat the strongest anonymity tools. For the ordinary user, it is a window into the depth of silent tracking in the systems we use daily. In both cases, the rule is one: privacy is not built on a single tool, but on understanding all the layers where your device leaves its fingerprint.
Newsletter
Enjoyed this?
Subscribe and get every new article and news post straight to your inbox.