A U.S. senator has demanded the FTC investigate Microsoft cybersecurity negligence after several high-profile breaches. Senator Ron Wyden argues that Microsoft’s weak security defaults and outdated encryption created unnecessary risk for hospitals, businesses, and government networks. His call reflects growing concern about the responsibility of major technology firms in protecting critical infrastructure.
Senator Wyden’s Claims
Wyden highlighted the Ascension hospital ransomware attack in May 2024. That incident compromised the medical and insurance records of 5.6 million people. Attackers reportedly gained access by exploiting weaknesses in Microsoft’s Active Directory and default configurations.
He also criticized Microsoft’s continued reliance on RC4 encryption, a protocol long regarded as insecure. Cybercriminals can exploit this weakness using methods like Kerberoasting, which allow privilege escalation and lateral movement within compromised networks.
Wyden described Microsoft as “an arsonist selling firefighting services to their victims,” suggesting that organizations have little choice but to depend on insecure products.
Microsoft’s Response
Microsoft countered that RC4 now accounts for less than 0.1% of traffic across its systems. The company pledged to phase it out entirely by early 2026 and provided mitigation guidance for customers still using it. Microsoft also emphasized its ongoing work to strengthen security defaults and minimize exposure to legacy protocols.
Why the FTC May Step In
Wyden’s request that the FTC investigate Microsoft cybersecurity negligence raises broader questions about accountability. Critics argue that leaving insecure protocols enabled by default puts organizations at risk of massive breaches. For sectors like healthcare, such vulnerabilities carry life-threatening consequences.
Regulatory action could push Microsoft and other tech giants to prioritize secure-by-default settings rather than leaving security decisions to end users.
Conclusion
The demand that the FTC investigate Microsoft cybersecurity negligence underscores the urgency of stronger safeguards in widely used software. Breaches like the Ascension attack show that outdated encryption and poor defaults can endanger millions. As lawmakers apply pressure, Microsoft and other tech leaders face mounting scrutiny to embed stronger protections by design.


0 responses to “FTC Investigate Microsoft Cybersecurity Negligence After Attacks”