This week's episode is different. Bishop Fox Red Teamers Brandon Kovacs, Thomas Wilson, and Rob Antonucci talk through what attribution actually looks like when device-level telemetry breaks anonymity, what young attackers with real skills but zero tradecraft have in common, and how one credential reset becomes the master key to everything downstream.
Attribution just got a lot harder to hide from. Device-level telemetry doesn't care about your VPN, and neither do the researchers connecting the dots. Microsoft's GDID (a global device identifier tied to every Windows install) was first revealed publicly through Peter Stokes' arrest. A 19-year-old Scattered Spider member tracked through Finland despite running a VPN. The catch: he voluntarily submitted his GDID through Edge, then logged into Snapchat with his real name on the same device. Attribution specialists like Allison Nixon connected those pieces. From the operator side, GDIDs aren't shocking. We always assumed device identifiers existed. What's actually happening is simpler: use Edge, submit your GDID, use your real identity on the same device, and attribution becomes straightforward. The hacker community panicked over nothing. Voluntary submission was always the vulnerability.
The gap between skill and judgment is where law enforcement finds its leverage. Peter Stokes was a 19-year-old member of Scattered Spider with real capability: network access to MGM, Visa, and Twilio. He had the skills. What he didn't have was tradecraft to match. Fifteen years ago, young hackers operated for the challenge and notoriety. Now, as monetization became possible and motivation shifted to financial gain. But that shift in motivation didn't automatically bring operational awareness with it. Attribution specialists connected device-level telemetry to his social media logins; a single opsec mistake (posting his full name online) created the chain law enforcement needed. From the operator side, we're seeing this pattern repeat: young attackers mastering technical skills but asking 'where can I use this?' instead of 'how do I stay hidden?' That gap between the ability to move laterally through enterprise networks and the judgment to cover your tracks is exactly where the leverage sits.
One credential reset puts you everywhere in the network. ShinyHunters scaled a breach of the University of Nottingham with a single technique: call the IT team, impersonate an employee, reset a credential. From there, they were everywhere: student portal, CRM, financial system, across three campuses. They pulled 40+ gigabytes of data because one credential reset opened every downstream system that role administers. This is why both ShinyHunters and Scattered Spider rely on the same technique. It's not sophisticated; it's complete. An RCE gets you one box and a long climb. A compromised credential gets you the entire stack. Young attackers are mastering it because it works, and it keeps working.
Subscribe to our PODCAST
Real talk on the threats, trends, and tactics shaping security today
Recommened Resources