CSIDB logo
Threat actor

Peter Stokes

Attribution profile

Type
Undetermined
Location
-
Known incidents
1 incident
Sources
0 sources
First seen
2024-08-01
Last seen
2024-08-01
Updated
2026-09-09 14:12
Aliases
1 alias

STIX characteristics

Threat actor characteristics are available to members.

Profile narrative

The threat actor known by the alias Peter Stokes has appeared in open‑source reporting related to cybercriminal activity. This alias is specifically associated with the Scattered Spider group, a loosely organized collective that has been linked to several high‑profile intrusions. Peter Stokes is not a widely documented individual outside of the particular incident described in the sources. The name is used to refer to one of the participants involved in the August 2024 cyber intrusion against Transport for London.

On 1 August 2024, members of the Scattered Spider group conducted a cyber intrusion against Transport for London, the public transit authority serving the United Kingdom capital. The attack disrupted online passenger services, disabled real‑time information boards and resulted in the compromise of customer data held by the organization. Investigators determined that the intruders gained access to the Oyster refunds system and subsequently halted the processing of children’s photocard applications. The incident produced an estimated financial loss of £39 million and affected roughly ten million individuals who rely on the transport network. Evidence linking the perpetrators to the breach was recovered from seized electronic devices and from their online communications.

Two individuals who were identified as part of the Scattered Spider team pleaded guilty to charges stemming from the Transport for London breach. Each defendant received a custodial sentence of five and a half years imprisonment. Following the convictions, law‑enforcement agencies have pursued additional arrests and extradition requests targeting other alleged members of the group. The alias Peter Stokes is therefore understood to be connected to this criminal consortium rather than to any state‑sponsored or nation‑state actor.

Public sources do not detail the specific malware families, exploit tools or initial access vectors employed in the Transport for London operation. Nevertheless, the intrusion demonstrated the ability to obtain unauthorized access to transit‑critical IT systems and to manipulate service‑related functions. The observed consequences included service disruption, exposure of personal data and a substantial financial impact on the victim organization. No further campaigns or operations have been publicly attributed to the Peter Stokes alias beyond this single incident. As a result, the current public profile of Peter Stokes is limited to his role as an alias of a participant in the Scattered Spider‑linked Transport for London cyber intrusion.

Incidents

Attributed incidents are available to members.

1 incident

Sources

Sources available to members: 0 sources.

CSIDB