LIVE · cybersecurity feed
Live wire
law enforcement

Court Filing Reveals Windows Device ID Helped FBI Trace Alleged Scattered Spider Hacker

A court filing revealed that a persistent Windows device ID helped the FBI trace an alleged Scattered Spider hacker. The identifier linked the suspect to a break-in at a luxury jewelry retailer.

zeroday.news · 25d ago

The Federal Bureau of Investigation has reportedly used a persistent Windows device ID to track an individual suspected of involvement with the Scattered Spider hacking group. This digital fingerprint is said to have been instrumental in connecting the suspect to a security breach at a high-end jewelry retailer.

The device ID, a unique identifier assigned to Windows operating systems, can persist across various system changes and reconfigurations. Its persistence makes it a valuable tool for law enforcement and cybersecurity professionals seeking to trace digital activities back to specific devices and, by extension, their users.

According to court documents, the FBI leveraged this specific device ID to establish a link between the alleged hacker and the intrusion into the luxury jewelry retailer's network. The nature of the breach and the specific data compromised were not detailed in the information available.

Scattered Spider, also known as GoldFactory, is a cybercriminal group that has been active for several years. The group is known for its involvement in various forms of cybercrime, including ransomware attacks and SIM-swapping operations, often targeting telecommunications companies and other large organizations. Their methods frequently involve social engineering and exploiting vulnerabilities to gain access to victim networks.

The use of a persistent device ID highlights a common, albeit sometimes overlooked, aspect of digital forensics. While sophisticated attackers may employ techniques to mask their online presence, unique hardware or software identifiers can provide a crucial trail for investigators.

The specific details of how the device ID was obtained or how it was linked to the suspect were not disclosed. However, such investigations often involve a combination of technical analysis of compromised systems, network traffic monitoring, and correlation with other digital evidence.

This development underscores the ongoing efforts by law enforcement agencies to combat organized cybercrime. The ability to trace digital breadcrumbs, even those seemingly minor like a device ID, can be critical in building cases against sophisticated hacking operations.

The luxury jewelry retailer targeted in this incident has not been publicly identified. The investigation is ongoing, and further details may emerge as legal proceedings progress.

law enforcementattributiontrackingwindowscybercrime
ShareXLinkedInWhatsAppFacebook

More News

view all →
vulnerability

Coldcard Hardware Wallet Flaw Linked to $70 Million Bitcoin Theft in 41 Minutes

An attacker drained 1,196 Bitcoin addresses in 41 minutes on July 30, taking 1,082.65 BTC worth about $70.2 million at the time. Galaxy Research mapped the sweep and tied it to a firmware flaw in Coldcard, the Bitcoin-only hardware wallet made by Canadian firm Coinkite. A March 2021 firmware integration error routed seed generation to a deterministic software pseudorandom number generator (PRNG

vulnerabilitycritical

Rails patches critical Active Storage flaw with RCE potential

A critical vulnerability in the Active Storage framework can allow an unauthenticated attacker to read arbitrary files from a Rails application, and potentially escalate to remote code execution (RCE). [...]

malware

Russian Hackers Hijack Hotel Wi-Fi to Steal Microsoft 365 Tokens

Microsoft says Russian hackers hijacked hotel Wi-Fi portals to spread malware and steal Microsoft 365 tokens from travelers. Microsoft Threat Intelligence disclosed CaptiveCrunch, a campaign it attributes to Storm-2945, an operational sub-cluster of Midnight Blizzard, the Russian SVR-linked group also known as APT29 and Cozy Bear. Since early May 2026, Storm-2945 has been manipulating DNS […]

CVE-2026-48449critical

Adobe fixed a maximum-severity vulnerability flaw in Campaign Classic

Adobe fixed a maximum severity vulnerability in Campaign Classic that could let attackers run code remotely without user interaction. Adobe has addressed a critical vulnerability, tracked as CVE-2026-48449 (CVSS score of 10.0), in Adobe Campaign Classic, the company’s enterprise marketing automation platform. The flaw is caused by incorrect authorization and could allow attackers to execute […]

security

Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments

The funding round was led by SYN Ventures, with participation from existing investors DataTribe and TEDCO. The post Balance Theory Raises $19 Million to Help Enterprises Manage Cybersecurity Investments appeared first on SecurityWeek.

vulnerabilitycritical

Ruby on Rails Patches Critical Vulnerability

The flaw can be exploited by unauthenticated attackers to read arbitrary files and potentially achieve remote code execution (RCE). The post Ruby on Rails Patches Critical Vulnerability appeared first on SecurityWeek.