RC RANDOM CHAOS

Windows' hidden Global Device ID helped the FBI unmask a Scattered Spider suspect

· via Hacker News

Original source

Microsoft Can Track Users via a Windows Device ID

Hacker News →

An unsealed U.S. cybercrime complaint has exposed a little-known Windows tracking mechanism called the Global Device Identifier (GDID) — a unique number Microsoft ties to each Windows installation. Investigators leaned on GDID records while probing a May 2025 breach at a luxury jewelry retailer, correlating the same identifier against specific web activity, visited sites, and timestamps to pin the intrusion to one machine. Microsoft handed the GDID data to the FBI, which used it to help build the case against 19-year-old U.S.-Estonian national Peter Stokes, allegedly linked to the Scattered Spider extortion crew. Stokes was arrested on April 10 at Helsinki Airport as he tried to board a flight to Japan.

What makes the GDID notable for privacy is its persistence. It survives Windows updates and has no consumer-facing toggle to disable it; only a full OS reinstall mints a new one. The complaint also indicates the identifier is associated with IP-address history that follows the device even when the user switches on a VPN, undercutting a common assumption that VPN use meaningfully anonymizes a Windows machine.

The case is a reminder that operating-system telemetry can double as forensic evidence. For defenders and investigators, a stable, hardware-adjacent identifier that vendors can produce on legal request is a powerful attribution tool. For everyone else, it underscores how much durable, non-optional tracking data Windows retains — and that Microsoft can and does share it with law enforcement.

Read the full article

Continue reading at Hacker News →

This is an AI-generated summary. Read the original for the full story.