MEET THE TEAM AT BLACK HAT - DEF CON 2026 Learn More

Image
Episode 26  •  Jul 17, 2026  •  43 Min

Attribution and OpSec at Scale

This week's episode is different. Bishop Fox Red Teamers Brandon Kovacs, Thomas Wilson, and Rob Antonucci talk through what attribution actually looks like when device-level telemetry breaks anonymity, what young attackers with real skills but zero tradecraft have in common, and how one credential reset becomes the master key to everything downstream.

Attribution just got a lot harder to hide from. Device-level telemetry doesn't care about your VPN, and neither do the researchers connecting the dots. Microsoft's GDID (a global device identifier tied to every Windows install) was first revealed publicly through Peter Stokes' arrest. A 19-year-old Scattered Spider member tracked through Finland despite running a VPN. The catch: he voluntarily submitted his GDID through Edge, then logged into Snapchat with his real name on the same device. Attribution specialists like Allison Nixon connected those pieces. From the operator side, GDIDs aren't shocking. We always assumed device identifiers existed. What's actually happening is simpler: use Edge, submit your GDID, use your real identity on the same device, and attribution becomes straightforward. The hacker community panicked over nothing. Voluntary submission was always the vulnerability.

The gap between skill and judgment is where law enforcement finds its leverage. Peter Stokes was a 19-year-old member of Scattered Spider with real capability: network access to MGM, Visa, and Twilio. He had the skills. What he didn't have was tradecraft to match. Fifteen years ago, young hackers operated for the challenge and notoriety. Now, as monetization became possible and motivation shifted to financial gain. But that shift in motivation didn't automatically bring operational awareness with it. Attribution specialists connected device-level telemetry to his social media logins; a single opsec mistake (posting his full name online) created the chain law enforcement needed. From the operator side, we're seeing this pattern repeat: young attackers mastering technical skills but asking 'where can I use this?' instead of 'how do I stay hidden?' That gap between the ability to move laterally through enterprise networks and the judgment to cover your tracks is exactly where the leverage sits.

One credential reset puts you everywhere in the network. ShinyHunters scaled a breach of the University of Nottingham with a single technique: call the IT team, impersonate an employee, reset a credential. From there, they were everywhere: student portal, CRM, financial system, across three campuses. They pulled 40+ gigabytes of data because one credential reset opened every downstream system that role administers. This is why both ShinyHunters and Scattered Spider rely on the same technique. It's not sophisticated; it's complete. An RCE gets you one box and a long climb. A compromised credential gets you the entire stack. Young attackers are mastering it because it works, and it keeps working.

Security Headlines:


Brandon Kovacs Headshot

Brandon Kovacs

Senior Security Consultant

Brandon Kovacs (CRT, OSCP) is a Senior Security Consultant at Bishop Fox, where he specializes in red teaming, network penetration testing, and physical penetration testing. As a red team operator, he is adept at identifying critical attack chains that an external attacker could use to fully compromise organizations and reach high-value targets.

To support physical and external testing, Brandon has built the 2023 edition of Bishop Fox’s Tastic RFID Thief to include Wi-Fi and remote control, allowing for more effective capture of RFID badges from a few feet away. He actively performs research and development into artificial intelligence for use in offensive security engagements.

Brandon is also recognized as a deepfake expert, conducting speaking sessions and live demonstrations at several global security and technology conferences. His research focuses on using AI and high-quality deepfakes to perform social engineering.


Bfx25 Thomas Wilson Bio

Thomas Wilson

Senior Red Team Operator

Thomas Wilson is a senior red team operator at Bishop Fox and a musician. From IDEs to DAWs, he is as at home on his own computer as he is on someone else's. You can usually find him at the local card shop slinging spells, up on stage blasting tunes, or with his eyes glued to his monitor for hours at a time (thank goodness for blue light filtering lenses).


Rob Antonucci Profile Bio

Rob Antonucci

Sr. Security Consultant

Rob Antonucci (OSCP) is a Senior Security Consultant at Bishop Fox, where he specializes in red teaming, network penetration testing, and purple team engagements. With over a decade in offensive security, he focuses on realistic adversary simulation against Fortune 500 enterprises — emulating the tradecraft of real-world threat actors to measure and strengthen how organizations detect and respond to attacks.


Subscribe to our PODCAST

Real talk on the threats, trends, and tactics shaping security today

Listen Anywhere