On July 1, 2026, the US Department of Justice announced the arrest and extradition of alleged Scattered Spider member Peter Stokes. However, this press release from the DOJ is extremely interesting, and for way more reasons than initially meets the eye.
As a security practitioner, the criminal complaint is a fascinating read, providing a deep dive into the various tracking mechanisms (wait, I mean “telemetry”) that exist in different products and platforms and how they can be used as evidence. However, for anyone concerned about online or personal privacy, this is a textbook example of how these mechanisms can be used against you.
Let’s break down the tracking mechanisms cited in the criminal complaint, how they were used as evidence against Stokes, and what those mean for those concerned about privacy.
| Tracking mechanism | How it was used as evidence | Privacy concerns |
| Microsoft Global Device ID (GDID) | Microsoft associated a unique device identifier with a VPN IP address used to create an account involved in the intrusion, linking the device to the suspect. | Device IDs can persist across sessions and services, allowing long-term tracking even when IP addresses change. Users are often unaware that hardware or software identifiers uniquely identify their devices. |
| IP address correlation | Investigators compared residential IP addresses, VPN endpoints, RDP logs, Apple account logins, Snapchat activity, and Microsoft records to show the same infrastructure was used across multiple services. | IP addresses reveal approximate location, ISP, and behavioral patterns. Correlating IPs across providers allows for a more detailed reconstruction of a person’s online activities. |
| Provider account records | Records from cloud providers, secure tunneling services, Apple, Snapchat, Facebook, and Microsoft established account ownership, login history, and associated identifiers. | Service providers retain extensive metadata beyond user content, including login timestamps, devices, IPs, and linked accounts that users may not expect to be preserved. |
| Cross-platform account linkage | Apple, Facebook, Snapchat, and Microsoft accounts were linked using shared IP addresses, communications, and account content. | Separate online identities that users perceive as isolated can be merged into a unified profile through common identifiers and metadata. |
| Social media content | Snapchat images, Facebook photos, captions, conversations, and media were used to establish relationships, intent, travel, wealth, aliases, and communications with co-conspirators. | Social media posts often reveal far more than intended, including associations, travel, lifestyle, interests, and timelines that persist long after posting. |
| Travel metadata | Photos posted online were corroborated using State Department travel records to validate international travel. | Combining government travel records with social media allows investigators to verify movement patterns and timelines with high confidence. |
| Cloud server logs | Remote Desktop Protocol (RDP) logs from a virtual server recorded connection times and originating IP addresses, allowing attribution to known accounts. | Infrastructure logs created for operational purposes become powerful forensic records that can reconstruct historical user behavior. |
| VPN usage records | Although the suspect used VPN services, investigators correlated VPN exit nodes with other identifiers and provider records. | VPNs protect traffic from observers but do not guarantee anonymity when providers maintain logs or activities are correlated across multiple datasets. |
| Temporal correlation | Investigators compared timestamps across RDP sessions, Apple logins, Snapchat activity, Microsoft records, and server access to show consistent patterns. | Even if individual datasets lack identifying information, synchronized timestamps across services can uniquely identify users through behavioral fingerprinting. |
| Communication metadata | Chat logs, messaging records, usernames, and aliases (“Bouquet,” “Jordan,” etc.) established relationships with other members of the group. | Metadata (who communicated with whom and when) can reveal social networks even without examining message contents. |
| Cloud storage artifacts | Investigators examined the contents of a virtual private server containing exfiltrated files, Telegram search tools, authentication apps, ransomware artifacts, and logs. | Data stored on cloud infrastructure often persists after users believe it has been deleted and may contain evidence from multiple activities. |
| Microsoft threat intelligence telemetry | Microsoft’s security researchers used machine IDs, IP addresses, malware samples, and observed infrastructure to identify recurring threat actor activity over time. | Commercial security providers collect large-scale telemetry from endpoints and cloud services. While valuable for cybersecurity, this telemetry can also enable long-term behavioral tracking of devices and users. |
Perhaps the most shocking element of these tracking mechanisms is the Microsoft Global Device ID (GDID). It acts as a persistent device identifier that Microsoft can associate with activity across its services. The complaint does not fully explain how the identifier is generated internally, but it does describe how investigators used it.
What is a Microsoft Global Device ID (GDID)?
A Global Device ID (GDID) is a unique identifier assigned by Microsoft to a device interacting with Microsoft services. Unlike an IP address, which may change frequently, a GDID is intended to represent the device itself.
Conceptually:
- IP Address: “Where was the connection coming from?”
- User Account: “Who logged in?”
- GDID: “Which physical device was used?”
This allows Microsoft to recognize the same device across multiple sessions, even if the user changes networks, travels, reconnects through different ISPs, or uses a VPN.
What does the complaint say?
The complaint explains that Microsoft investigators observed a specific VPN IP address being used to create a Microsoft account. Microsoft then associated that activity with a specific GDID.
Investigators later observed the same GDID appearing in additional Microsoft records involving the defendant.
This became significant because it demonstrated that:
- multiple Microsoft accounts
- created at different times
- from different IP addresses
were actually being accessed from the same physical device.
The GDID therefore became stronger evidence than IP addresses alone.
Information associated with the GDID
According to the complaint, Microsoft was able to associate the GDID with:
- Microsoft account creation:
The GDID was linked to the creation of Microsoft accounts used during the intrusion. - Login history:
Microsoft associated subsequent authentication events with the same GDID.
This demonstrated continued use of the same device. - IP addresses:
Microsoft records linked the GDID to VPN exit nodes, residential IP addresses,
and other observed login IPs allowing investigators to correlate device usage
across changing network locations. - Timeline of activity:
Because Microsoft recorded timestamps alongside the GDID, investigators
reconstructed when accounts were created, when logins occurred, and when
devices authenticated. - Multiple Microsoft accounts:
One of the strongest aspects of the evidence was that a single GDID appeared
across multiple Microsoft accounts. This allowed multiple accounts and VPN IPs
to be associated with a single physical device. - Attribution:
The GDID was one component in a larger attribution effort that also incorporated:- Apple account records
- Snapchat records
- Facebook records
- VPS logs
- VPN provider logs
The investigators did not rely solely on the GDID. Instead, they used it as one persistent and unique identifier among many.
How might this be used to track you?
Let’s say you start using your computer at home, then move to a coffee shop. Later, you connect to a VPN service, and then eventually connect to a hotel’s WiFi before going to work.
| Location | IP Address |
| Home | 100.1.x.x |
| Coffee Shop | 26.72.x.x |
| VPN | 12.6.x.x |
| Hotel | 176.11.x.x |
| Work | 119.55.x.x |
When looking at activity based on IP addresses, each of these five locations would initially appear to be associated with different devices. With GDID tracking, however, Microsoft can determine that the same device was used throughout, despite the changing IP addresses.
The groundbreaking aspect of this complaint is that it removes any speculation about how Microsoft might be able to use the data that they collect from every Windows user – we now have the evidence to prove what privacy advocates suspected all along: Windows is spying on you.
Privacy implications
From a privacy standpoint, persistent device identifiers such as the GDID have several implications:
- Long-term tracking: Because the identifier remains stable while IP addresses change, activity across networks and over time can be linked to a single device.
- Cross-account correlation: If the same device is used to access multiple Microsoft accounts, those accounts may be associated through the shared device identifier, even if they use different usernames or email addresses.
- Reduced anonymity: VPNs, NAT, or changing networks obscure location but do not necessarily prevent a persistent device identifier from linking sessions together.
- Rich metadata: When combined with timestamps, IP addresses, account registrations, and authentication logs, a device identifier can support detailed reconstruction of a device’s history of interaction with Microsoft services.
I’m Concerned About My Privacy – What Can I do About it?
It’s important to recognize what can and cannot be prevented. A Microsoft Global Device ID (GDID) exists because Microsoft’s own services recognize a device over time. If you regularly use Windows, Microsoft Edge, Office, OneDrive, Xbox, Outlook, Teams, or sign into a Microsoft account (whether by choice or by employer mandate), Microsoft will have opportunities to associate your activity with a persistent device identifier.
Let’s break down a number of privacy recommendations and their effectiveness. Note that the goal here is to avoid correlation and not to aid in committing cybercrime.
| Recommendation | How it helps | Effectiveness Against Persistent Device Tracking | Tradeoffs |
| Use Linux as your primary operating system | Linux distributions generally do not report telemetry to a central vendor comparable to Microsoft’s Windows ecosystem. There is no Microsoft-generated GDID associated with the operating system itself. | ★★★★★ | Some commercial software and games may not be available. Requires some learning. |
| Use a privacy-focused Linux distribution (Ubuntu, Debian, Linux Mint, etc.) | These distributions collect little or no telemetry by default and emphasize user control over the system. | ★★★★★ | May require finding Linux alternatives for certain applications. |
| Use Tails for highly sensitive browsing | Tails runs from a USB drive, routes traffic through Tor by default, and is designed not to leave traces on the host computer after shutdown. | ★★★★★ | Not intended for everyday use; slower and less convenient. |
| Use Qubes OS for compartmentalization | Qubes isolates activities into separate virtual machines, reducing the risk that different identities or tasks become linked through the same environment. | ★★★★★ | High hardware requirements and a steeper learning curve. |
| Use a local Windows account instead of a Microsoft account | Reduces the amount of device telemetry directly associated with your identity. | ★★★★☆ | Some Windows features require a Microsoft account. |
| Avoid signing into Microsoft services unless necessary | Limits Microsoft’s ability to associate your device with a long-term account history. | ★★★★☆ | Loses synchronization and cloud features. GDID will still be captured with any sign in to Microsoft services. |
| Separate work and personal devices | General best practice. Physical separation prevents a single device identifier from linking multiple aspects of your life. | ★★★★★ | Requires additional hardware. |
| Use separate browser profiles or containers for different identities | Keeps cookies, login sessions, and local storage isolated between activities. | ★★★★☆ | Easy to accidentally use the wrong profile. |
| Use different browsers for different purposes | Limits cross-site and cross-account tracking through browser state and extensions. | ★★★☆☆ | Does not prevent OS-level device recognition. |
| Disable browser synchronization | Prevents browsing history, passwords, tabs, and settings from being merged across devices. | ★★★☆☆ | Less convenient when switching devices. |
| Reduce Windows diagnostic telemetry | Lowers the amount of information sent to Microsoft, though required telemetry cannot be completely disabled on consumer editions. | ★★★☆☆ | Some telemetry remains mandatory. |
| Use privacy-focused browsers (Firefox, Brave) | These browsers include stronger anti-tracking protections and reduce browser fingerprinting opportunities. | ★★★☆☆ | Does not stop tracking after signing into online accounts. |
| Use browser extensions that block trackers (uBlock Origin, Privacy Badger) | Prevents many third-party tracking scripts and advertising networks from collecting browsing behavior. | ★★★☆☆ | Some websites may require exceptions. |
| Use separate virtual machines for different activities | Each VM appears as a separate computing environment, making correlation more difficult across activities. | ★★★★☆ | Additional system resources and management required. |
| Avoid installing unnecessary software | Every application can introduce additional telemetry or unique identifiers. | ★★☆☆☆ | Minimal downside other than limiting software choices. |
| Regularly review connected devices and account activity | Helps identify unexpected devices or account access that could indicate compromise. | ★★☆☆☆ | Does not reduce existing tracking. |
| Use a VPN | Conceals your public IP address from websites and your ISP. | ★★☆☆☆ | Does not prevent a logged-in service from recognizing your device via identifiers like a GDID. |
| Use Tor Browser when anonymity is important | Reduces browser fingerprinting, isolates sessions, and routes traffic through the Tor network. | ★★★★★ | Slower browsing and some websites block Tor exit nodes. Risk of accidentally using the incorrect browser. |
My Thoughts
First, I must emphasize that it is good to see a Cybercriminal being held accountable for his actions. Our SOC has done extensive research and threat hunting involving Scattered Spider and other threat actors, and I’d speculate that Peter Stokes is personally responsible for interrupting some vacation time I had planned last year (which, from my selfish perspective, is as much of a crime as $100+ million in damages and ransom payments, since I’m terrible at taking time off anyway).
However, I can’t acknowledge this case without recognizing the serious privacy implications clearly spelled out in the DOJ’s evidence. In a world of increasing government surveillance and decreasing personal privacy, knowing that Big Brother Microsoft is watching and logging every move really doesn’t sit well with me. I’m also concerned that more sophisticated cyber criminals are going to be better equipped to cover their tracks, and these tracking mechanisms are going to be more likely to be used to log the activity of everyone as opposed to being useful in future investigations.
I hope I’m wrong. But in case I’m not, it’s probably time to just go install Linux. If you’re not sure where to start, sites like https://distrochooser.de/ can help you figure out what Distribution is best for you.
