The bottom line: Microsoft’s GDID helped investigators identify a cybercriminal, but technical details about the scope and sources of data collection remain unclear in the indictment and affect data protection assessments.
A criminal proceeding against Peter Stokes, an alleged member of the cybercrime group Scattered Spider, has brought Microsoft’s Global Device Identifier (GDID) into focus. The indictment demonstrates how this persistent Windows identifier was used in investigations, but simultaneously raises questions about data collection and the scope of Microsoft telemetry.
The indictment against Stokes documents that Microsoft’s data holdings revealed a connection between his Windows installation and registration with ngrok, a service for secure exposure of local servers. According to the report, the same records tracked usage of Tzulo proxy servers and visits to the victim’s website — a luxury jewelry merchant. The attack occurred in May 2025. Dray Agha from managed detection firm Huntress summarizes the approach: “Microsoft did not monitor ngrok; it monitored the device, and investigators connected the dots.”
GDID is a unique identifier automatically assigned to a Windows installation that persists through updates but is reset upon reinstallation. This identifier is transmitted to Microsoft servers to provision various Microsoft services and bundled Windows apps. The significance lies in the fact that investigators linked multiple data sources — vendor records, IP history, account logs — in a correlation chain to identify Stokes.
However, legal and technical experts emphasize the ambiguity of the indictment. The term “Microsoft records” could encompass various data sources without specifying which Microsoft product captured which information. Benson Varghese, a criminal law specialist attorney, explains: The document is a probable cause determination, not a technical audit. It is unclear whether Windows systematically logged browser history, or whether investigators correlated timestamps and IP data from Microsoft’s systems with separate ngrok and Tzulo records.
Everett Lupton of Slaughter & Lupton notes that the indictment does not disclose whether the data came from Edge, Microsoft Defender SmartScreen, crash reporting, or other Microsoft components. Each scenario would have different data protection and legal implications. If Microsoft only stored timestamps and IP addresses and investigators correlated these with third-party data, this differs significantly from persistent collection of user activity.
The indictment has raised questions in both the technology community and among data protection advocates about Microsoft’s data collection practices and GDID documentation. The proceeding is ongoing and could provide clarity on what telemetry details Microsoft actually stores and how these are made accessible in criminal investigations.
Source: www.csoonline.com · Published 30 July 2026
Lumi AI News — AI-assisted curation in accordance with Art. 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.