The FBI’s arrest of an alleged member of the Scattered Spider hacking group has triggered a wider debate over Microsoft GDID tracking and user privacy.

Court documents show investigators identified 19-year-old Peter Stokes by linking activity to a persistent Windows Global Device Identifier (GDID). The case has left many Windows users questioning how much device data Microsoft collects and shares.

Microsoft GDID Helped Identify the Suspect

According to the criminal complaint, investigators tracked Stokes through Microsoft GDID, a unique identifier tied to a Windows installation.

Unlike an IP address, the identifier remained unchanged even as the suspect switched VPNs, rotated IP addresses, and used remote desktop connections.

The complaint states that only reinstalling Windows generates a new GDID.

Investigators allegedly matched the identifier to activity linked to locations including Tallinn, New York, and Thailand.

VPNs Failed to Hide Device Activity

Authorities say Stokes used the same Windows device to create an ngrok account while connected through a VPN.

Ngrok is a legitimate tunneling service that allows remote access to systems behind firewalls. Prosecutors allege the suspect used it to maintain unauthorized access to corporate networks.

Investigators also connected the same device to personal accounts on Snapchat, Apple, Facebook, and the online game Growtopia.

The suspect allegedly posted photos of luxury watches, jewelry, and cash on social media while using aliases including “Bouquet,” “Spencer,” and “Jordan.”

Authorities arrested him in Helsinki while he was preparing to board a flight to Japan. He was later extradited to the United States.

Microsoft GDID Raises Privacy Concerns

The case has sparked criticism of Microsoft GDID across social media.

Many users said they were unaware Windows assigns a persistent installation identifier that can be used during investigations.

Privacy researcher IT Guy claimed Microsoft has not publicly explained when GDID information is shared with law enforcement. He also argued there is no known opt-out mechanism or transparency reporting specific to GDID requests.

Researchers at vx-underground also noted that the identifier played a significant role in the investigation despite receiving little public attention.

Experts Say Avoiding Microsoft GDID Is Difficult

Members of the Massgrave project explained that Windows creates device identifiers during installation after communicating with Microsoft’s servers.

Those identifiers are later used for Windows activation, Microsoft Store services, and other platform features.

According to the group, preventing Microsoft GDID generation would also break Windows activation and Universal Windows Platform (UWP) applications.

Some privacy advocates recommend reducing Windows telemetry, avoiding Microsoft accounts, and using alternative browsers.

However, security researchers warn that reinstalling Windows alone offers little protection because a new GDID can often be linked back to the same hardware or Microsoft account.


0 responses to “Microsoft GDID Tracking Sparks Privacy Backlash After Hacker’s Arrest”