Microsoft Tracked a Hacker Through His VPN. Read the Complaint Twice.
Pillar 01 · Security
In April, a 19-year-old alleged member of Scattered Spider was arrested at Helsinki airport. The unsealed US criminal complaint runs 39 pages. Buried in it is the first public description of Microsoft's Global Device Identifier. GDID.
The complaint describes GDID as a persistent, device-level identifier that uniquely marks a Windows installation across Microsoft services. Independent reverse engineering since points the same direction. Log in with a Microsoft Account and a server assigns the device a permanent GDID. It is stored locally. Windows background services use it. It appears to ride along in the reports the operating system sends home. Microsoft could clarify the details any time it likes. It has not.
The suspect used VPNs. He used proxies. He moved across countries. None of it mattered. The identifier lived below the network layer. Every hop, every exit node, every border crossing carried the same device fingerprint back to Redmond. Microsoft handed the correlation to US prosecutors and the map drew itself.
Sit with the mechanism, because it invalidates most of what governments currently call cloud security.
Network controls assume the adversary is outside the wire. Residency clauses assume the risk lives where the data sits. GDID ignores both. It operates inside the operating system, underneath the firewall, underneath the VPN, underneath the contract. The perimeter was never the boundary. The vendor was.
Here is the part that should bother Ottawa more than the hacker story. This was lawful. No breach occurred. Microsoft received a US legal demand and complied, as US law requires it to. The CLOUD Act debate has been abstract for years. It now has a case number.
Defence365 and the $3.6 billion question
Vanguard Defence connected the dots to DND/CAF this week, and the exposure math is uncomfortable. Defence365 runs the entire Defence Team on Microsoft 365. The Digital Foundations initiative is costed at $3.6 billion, with a large share flowing to Microsoft products or software running on Windows. Every one of those endpoints carries a persistent identifier assigned by a foreign server, embedded in telemetry DND does not control, discoverable under laws Canada does not write.
The lazy response is to demand Microsoft explain itself. Fine. Ask. Microsoft declined to comment for the Vanguard piece, which tells you the expected value of asking.
The serious response starts by admitting two things.
First, DND should keep the hyperscalers. Microsoft is very good at what Microsoft does. Nobody else operates collaboration, identity and productivity at that scale, and Defence365 is already embedded across the entire Defence Team. Ripping it out would cost billions, take a decade, and deliver a worse product. Leverage the investment. Anyone selling rip-and-replace is selling fantasy.
Second, the identifier is unremovable. You cannot fully disable GDID. The published settings limit what it captures. They do not delete it.
So the design question changes. Stop asking how to hide the device. Start asking what the device can reach.
Two exposures, one fix still available
An identifier correlates activity. A warrant compels content. These are different exposures with different remedies. The first one is lost. The second one is an architecture decision, and it is still on the table.
The fix leaves the suite alone and moves the substance out of it. Be precise about the split, because precision is what separates architecture from marketing. Mail routing needs envelopes. Search needs indexes. Collaboration needs the service to see what it is serving. That exhaust stays with Microsoft, and no honest vendor will tell you otherwise.
The documents are a different matter. The files, the datasets, the attachments, the archives. The material a warrant is actually after. Those can live in a custody layer: encrypted at the client, sharded across independent operators, keyed so that no single party can reconstruct them. Then full vendor cooperation with a foreign demand produces the envelope and nothing the custody layer holds. The warrant arrives. The vendor complies. The substance does not exist in any form the vendor can produce. Compliance and disclosure stop being the same event.
One honest caveat. The client doing the encrypting runs on Windows. Keys touch memory on an operating system the vendor updates. Endpoint trust is a real residual, and anyone who claims to have eliminated it is lying. The custody layer moves the compelled-disclosure boundary from everything to the envelope. That is a large move. It is not a magic one.
That split lets each party do what it does best. The hyperscaler runs the experience. The custody layer holds the data. Microsoft loses nothing it should have had in the first place.
This applies with more force at the AI layer, which nobody in the Canadian defence conversation is discussing yet. Every Copilot query is Graph data plus telemetry plus a device identifier, correlated by design. The identifier problem and the custody problem converge exactly where DND is spending next.
DSG, CAFCYBERCOM and CSE should run the GDID risk assessment Vanguard calls for. Scope it correctly. The headline finding is already known: the platform vendor sits inside the trust boundary and always did. The useful output is a custody requirement layered on top of the Microsoft investment, written into Digital Foundations before the remaining $1.35 billion is allocated. Keep the platform. Own the data.
https://www.vanguarddefence.ca/p/how-much-can-microsoft-track-the-canadian-military-with-gdid
Bias declaration: I founded SkyeConnex. We build zero-knowledge data custody. This story is good for my business. The complaint is still 39 pages long, and it still says what it says.
More from the blog
CBC and CTV Say Canada's Cloud Market Is "Broken." They're Half Right.
A Better Question Doesn't Survive a Subpoena
Bergson Lopes Rego published a piece in CDO Magazine called "The Data Sovereignty Illusion." Read it. The diagnosis is…
Read → Commentary · 5 min readHave You Ever Wondered Where Your Data Goes in the Cloud?
You upload the quarterly numbers. A little spinner turns. "Saved to the cloud." Reassuring phrase, the cloud. Sounds…
Read → Regulation · 3 min readThe Kill Switch Has a Loyalty Program - Microsoft is in the Trump trap
Three weeks before Brad Smith promised Europe that Microsoft would protect it from Washington, Microsoft had already…
Read →