DFIR Tech Blog – an AI playground

Deutsch English
Foto von George Prentzas auf Unsplash.com

Scattered Spider: How a Windows Device ID Became the Undoing

15.07.2026 attributiontelemetryscattered-spiderforensic-readiness

On June 30, 2026, a 19-year-old made his first federal court appearance in Chicago after being extradited from Finland, where he had been stopped while trying to board a flight to Japan. The case against Peter Stokes, known online as “Bouquet,” initially reads like a routine Scattered Spider takedown. But a detail buried deep in the unsealed complaint has caught the DFIR community’s attention: Microsoft reportedly handed investigators telemetry tied to a Global Device Identifier (GDID) that traced back to a single Windows installation.

From Help Desk Call to Global Device ID

The underlying intrusion follows Scattered Spider’s now-familiar script: between May 12 and 15, 2025, attackers phoned the retailer’s IT help desk from Google Voice numbers, posed as locked-out employees, and got staff to reset employees’ passwords and the mobile devices tied to their multifactor authentication. That very persistence phase later became the forensic starting point. Microsoft records tied that device ID first to the account the attackers used to keep access during the May 2025 intrusion, then to online accounts prosecutors say belong to 19-year-old Peter Stokes.

Specifically, this involves a GDID: court documents reveal that Microsoft provided telemetry associated with the suspect’s GDID directly to investigators, and the indictment explicitly highlights how the Global Device ID was tied to a specific VPN proxy service IP address to track unmasked adversarial operations. That telemetry linked the same device identifier to multiple clusters of previously unmasked activity, including active ngrok tunneling infrastructure. The core forensic takeaway: attribution doesn’t always require a single mistake — it can come from telemetry that quietly persists across sessions, services, and infrastructure long after a VPN masks the obvious.

At the arrest in Helsinki, investigators also seized two 2-terabyte hard drives. This whole case was built from that kind of material — device records, account links, and IP trails — and in a network this diffuse, the drives could matter more than the conviction itself, if they hold the tools, infrastructure, or contacts that reach the next member.

What This Means for Forensic Teams

The case confirms a fundamental truth of modern attribution and incident response work: modern investigations rely on evidence correlation rather than a single indicator, and digital footprints often extend beyond IP addresses. At the same time, it raises uncomfortable governance questions: enterprises must now ask what diagnostic data is enabled on managed endpoints, how Edge telemetry is configured, and whether logs are preserved long enough to support incident response.

This aligns with current IR best practices — treating identity telemetry as tier-1 forensic evidence and retaining sign-in, audit, and API activity logs well beyond default retention windows to support investigations, insurance reviews, and regulatory scrutiny. Recent SANS FOR508 course updates reflect the same shift: in Spring 2025, FOR508 introduced refined coverage in areas including modern credential abuse, lateral movement detection workflows, memory forensics tooling, and hybrid cloud visibility including Entra ID.

Conclusion

Forensic readiness isn’t a compliance checkbox — it’s the foundation of every later attribution effort. Forensic readiness is the ability to preserve and collect digital evidence before an incident occurs, and without it, investigators cannot establish timelines, identify compromised accounts, or understand exactly how attackers moved through the environment. The GDID case demonstrates that even highly professionalized, VPN-shielded cybercriminals leave traces in telemetry layers that most organizations aren’t actively collecting or reviewing today. Any team that only asks which logs actually exist after an incident has already missed the most important forensic lesson.

← Back to overview