How Microsoft’s Digital Crimes Unit, a cybersecurity company and a global health organization came together to take on a new breed of hacker
One of the first signs of sabotage emerged before dawn on May 14, 2021, when doctors and nurses at several hospitals in Ireland found that they couldn’t access patient records. A ransomware attack had been silently unleashed across the country’s public health network in the middle of the night, after someone had prowled inside the IT system for weeks. By the time many employees arrived at work that morning, tens of thousands of devices had been encrypted, prompting staff to cut off internet access altogether to contain the devastation.
The cyberattack on the Ireland Health Service Executive (HSE) threw its large network of hospitals, clinics and services into chaos, endangering patients who faced delayed treatments and canceled appointments. Care providers, already dealing with the COVID-19 pandemic, reverted to pen and paper as they coped with no electronic patient records, networked phone lines or email.
Many ransomware attacks lock people out of their devices and data until a payment is made. This time, the attackers unexpectedly shared a free decryption key a few days after the strike. But it would still take the HSE four months to fully repair its IT system and 18 months to start contacting the 90,000 people affected by a data breach stemming from the attack. The incident and recovery were documented in a public report commissioned by the HSE.
“There is no underestimating the damage that this cyberattack has caused,” Paul Reid, then chief executive officer at the HSE, testified at a parliamentary health committee a month after the attack. “There are financial costs, certainly, but there will, unfortunately, also be human costs.”
Attackers had hijacked the HSE with a favorite tool of cybercriminals, a version of the legitimate security tool Cobalt Strike that had been “cracked” – i.e., stolen, pirated or otherwise manipulated to bypass licensing controls. A cracked version of the tool would also be used to extort the Costa Rican government a year later, triggering a state of emergency.
When used legitimately, Cobalt Strike is a powerful tool for “red teams,” or security testers who simulate cyberattacks in a safe, controlled environment to identify vulnerabilities. The tool can deploy malware (malicious software) to prowl a network, steal credentials, remotely control systems and carry out other harmful activities for testing purposes.
Around the time of the HSE attack, cracked Cobalt Strike was already emerging as a major threat on the radar of Microsoft’s Digital Crimes Unit (DCU), a diverse team of investigators, lawyers and other experts known for tackling cybercrime in groundbreaking ways.
When the team formed in 2008 to confront the growing problem of malware and other online threats, most cybersecurity groups at other companies were focused on more reactive efforts like patching vulnerabilities and improving antivirus software. Microsoft had a twofold interest in fighting malware: It wanted to safeguard its brand and software code – which hackers often exploit to attack Windows devices – and to proactively protect computer users worldwide.
Over the years, the DCU has developed an aggressive strategy of legal actions and global partnerships to lead more than 30 operations against malware systems, criminal groups, crime enablers and government-affiliated hackers. The operations have included disruptions of Waledac, a prolific botnet, in 2010; Forest Blizzard, a Russian- hacking group that targeted U.S. elections, in 2016; and Lumma Stealer, a fast evolving malware often used in credential theft, in 2025. The work has severed criminal control of millions of infected devices worldwide.
The operations generate valuable threat intelligence that the DCU shares with customers, partners and teams across Microsoft to help strengthen the security of the company’s services and enhance cybersecurity across global industries. The team also analyzes the intelligence and other data to identify evidence for law enforcement investigations, which has resulted in nearly 800 arrests.
“The dynamic nature of cybercrime demands constant vigilance and innovation,” says Steven Masada, Microsoft assistant general counsel and head of the DCU. “Each sector sees different aspects of the cybercrime ecosystem, and when we our insights, we evolve our strategies to counter emerging threats more effectively.”
For cracked Cobalt Strike, the DCU deployed a novel playbook it has pioneered. Instead of targeting individual hackers, the strategy aimed to shut down hackers’ systems for spreading malware, specifically their elaborate web of internet domains and IP addresses. To do that, the DCU would need to file a lawsuit against alleged attackers and get a court order. But despite the team’s considerable expertise, the path to taking down cracked Cobalt Strike would be far from easy.
Unlike operations that had targeted malware directly, the DCU wanted to pursue unauthorized copies of a popular tool owned by another company. And it wanted to focus on many malware groups at once, instead of a single group or botnet (a network of infected computers). This would help drive maximum impact.
The complexities of this ambitious case meant that it would take two years of detailed technical and legal work to build, starting with Microsoft investigator Jason Lyons, who had worked on the DCU disruptions of TrickBot, Necurs and other notorious botnets.
From his office in Texas, Lyons had been tracking the fallout from cyberattacks around the world, including those in Ireland and Costa Rica, as well as an attack on an essential U.S. fuel pipeline. A former U.S. Army counterintelligence special agent and cybersecurity incident responder, he had spent years working nights and weekends responding to crises in roles. Now he wanted to make a bigger impact on crime.
“Instead of me responding to the bad guys and being on call like a firefighter, I wanted to make their lives a little worse and disrupt their business, their networks,” says Lyons.
During the pandemic, he began to suspect that hackers were increasingly using cracked Cobalt Strike to attack businesses that had become distracted and vulnerable in the sudden shift to remote work. He just had to prove it.
For months, he and a coworker sifted through Microsoft data for clues, starting with alerts for all instances of Cobalt Strike use from the company’s antivirus product Defender. They studied forensic analyses from a company team that responds to customers’ cyberthreat incidents. They developed a database of known attacks involving the tool, with the picture becoming clearer. “The ransomware extortion angle was blowing up at the time, and… cracked Cobalt Strike was all over the internet,” says Lyons.
A full picture of how much hackers were using the tool would have to come from the tool’s owner, Fortra. The risk of failure was high for Microsoft to proceed alone – it needed Fortra to join the case and provide evidence and public support, prompting months of trust-building and information-sharing with an essential partner.
“We didn’t know where Fortra was going to land if we said, ‘Oh hey, we’ve got a huge problem, and you’re part of it,’” Lyons says. “Were they going to help? Were they just going to tell us to suck eggs? We just didn’t know.”
Early in the operation, Lyons and his team tried to buy a copy of Cobalt Strike to open it up and understand how it works. Fortra, a 3,000-employee company headquartered in Eden Prairie, Minnesota, said no. “We don’t just sell it to anybody,” says Bob Erdman, associate vice president for Research & Development at Fortra.
“There is a lot of background vetting before somebody can legitimately obtain a copy. We need to know their use case. Are they a real company? Are they going to use it in a manner that we’re OK with and meets the license criteria we have?”
Fortra already knew the problem – it was seeing around a thousand instances of cracked Cobalt Strike activity every day. It had added more security controls to the software and was already removing unauthorized copies from hacker forums and file-sharing sites.
But Microsoft’s approach was much broader, prompting Fortra to join the case as a co-plaintiff in early 2023. The company shared a list of watermarks linked to unauthorized Cobalt Strike use that turned out to be a crucial piece of evidence. The watermarks are a unique value assigned to every licensed copy of the tool, giving the DCU team and its partners a thorough, precise way to identify unauthorized or compromised copies that needed to be disabled.
“Working with Microsoft allowed us to do what we were doing on a much larger footprint,” Erdman says. “They brought a lot of new data to the table, and we could bring the ability to tear apart the tool and know if it’s a real customer’s copy, or an unauthorized copy that shouldn’t be running.”
When it came to laying out the legal arguments for the case, Richard Boscovich, assistant general counsel for the DCU, knew he would have to present more than a simple intellectual property (IP) case. He had led almost every malware disruption for Microsoft and shaped the company’s legal approach with a knack for using civil laws creatively.
As in cases, he accused cracked Cobalt Strike defendants of breaking a copyright law more usually associated with protecting the work of musicians and artists, not the software code of tech companies. He said that defendants had violated a trademark law that’s often used to fight counterfeits like fake designer bags and stolen logos.
The defendants were never expected to show up in court – the lawsuit was just a mechanism to secure a court order for taking down their malware operation.
For the first time in his malware cases, Boscovich leveraged a civil racketeering law, arguing that developers, sellers, hackers, extortionists and money launderers colluded in a lucrative ransomware-as-a-service enterprise. “We look at all the tools that are available, including tools that weren’t meant to address cybercrime,” he says. “You have to innovate because the cybercriminal is always innovating.”
A former federal prosecutor for 17 years, he understood that it wasn’t enough to argue that hackers are simply misusing Fortra’s software and Microsoft’s code to run malware on Windows devices. For a court to allow the companies to take down other people’s digital assets, Boscovich had to show the public devastation of malware. “Judges don’t really care too much Microsoft as a multinational corporation that’s suffering. They’re like, ‘Why are you in my courtroom?’” he says. “So the case became less protecting Microsoft’s IP or Fortra’s IP, and more protecting the ecosystem and our customers.”
Enter Health-ISAC, a global health security organization representing more than 1,000 member institutions. The Florida-headquartered group joined the case as a co-plaintiff to show the vulnerability of healthcare organizations and the human toll of ransomware.
The pandemic and years of underfunded IT security had left many healthcare organizations susceptible to ransomware. Meanwhile, the need to continue patient care and maintain critical systems like electronic medical records and diagnostic equipment forced some hospitals to pay attackers off, making them profitable targets. In the same year as the HSE attack, U.S. healthcare organizations were hit by a staggering wave of more than 400 ransomware assaults, according to the U.S. Office of the Director of National Intelligence, which oversees the country’s intelligence agencies.
“The modern-day hospital is so reliant on IT that when these systems go down, it’s incredibly devastating,” says Errol Weiss, chief security officer for Health-ISAC. “They can’t do patient intake, and ambulances are diverted. Services slow down because they’re relying on paper and manual processes. If you’re with a patient trying to do surgery and need to know their blood type, you’ve got to go to paper backup and hope it’s available and reliable.”
Ransomware often has severe downstream consequences, and Weiss ticks off a few that made headlines. A rural hospital in Illinois closed after spiraling financially from an attack and the pandemic. Hackers stole patient records from a health network in Pennsylvania and published them, including naked photos of cancer patients receiving treatment. The attack led to a class-action lawsuit against the network and a $65 million settlement. In Finland, a patient died by suicide after a hacker stole confidential records from a psychotherapy center, failed to get a ransom, exposed the records and blackmailed patients.
Health-ISAC, Fortra and Microsoft were able to merge their considerable data and expertise to link cracked Cobalt Strike to 68 health-related ransomware attacks in 19 countries. Their investigation connected cracked copies to eight malware families, including LockBit, a fast encryption and denial-of-service attacker, and Conti, the malware used in the HSE and Costa Rican attacks.
“I’m a big advocate for the work that’s being done,” Weiss says. “There’s an ecosystem that criminals can use to their heart’s content, and unless we do something that, this problem will not go away.”
How Microsoft’s Digital Crimes Unit team break up networks that use “cracked” copies of legitimate software to spread malware
1. With the help of the software’s creators, identify online distributors of unauthorized or compromised copies of software that are being used to mount malware attacks.
2. Bring a civil lawsuit against these distributors based on alleged violations of trademark law. The defendants won’t show up in court, but that doesn’t matter.
3. In court, link the use of cracked software to malware attacks, show the public devastation it causes, and demonstrate the necessity of protecting the digital ecosystem.
4. Gain a court order allowing for the seizure of domains hosting cracked software copies and directing hosting providers to remove them.
5. Systematize the takedowns by crawling the web for instances of cracked software and automatically sending out removal notices to hosting providers.
6. Result: a huge drop in the number of servers hosting unauthorized copies of the cracked software and a reduction in how long unauthorized servers stay active.
Nearly two years after the HSE attack, a U.S. federal judge issued a court order in 2023 allowing Microsoft to seize domains and direct hosting providers to remove instances of cracked Cobalt Strike. The immediate impact was swift, with all malicious .com and .net domains seized within 24 hours of the order.
The disruption has since evolved into a collaborative, automated takedown process, with the DCU crawling the internet for instances of cracked Cobalt Strike, Fortra providing a list of unauthorized watermarks and the DCU sending notices to hosting providers and government cybersecurity authorities to remove illegal IP addresses.
The work has contributed to a 72% drop in the number of servers hosting unauthorized Cobalt Strike and a sharp decline in the lifespan of those servers, which are used to control infected computers. Before the operation, unauthorized servers stayed active for an average of 49 days. By the summer of 2025, the lifespan was a mere 16 days.
“This is the impact of persistent notifications and the automated framework,” says Zoe Krumm, director of data analytics for the DCU. “It’s not just that unauthorized C2s (command-and-control servers) go down. When they go up, they’re not up as long. That gives me chills.”
The operation has had a particularly significant impact in the U.S., thanks to the Digital Millennium Copyright Act (DMCA), a federal law that imposes steep fines on hosting providers who fail to quickly remove IP addresses hosting infringing content. “The DMCA is a very big hammer,” Boscovich says. “The order goes out. The sites go down.”
In response, hackers have moved many cracked Cobalt Strike servers out of the U.S. and into countries with less regulation like China and Russia. Some security experts compare the maneuvering to a game of Whac-A-Mole, with the DCU chasing hackers globally with rapid takedowns customized for different countries, local laws and international IP treaties.
The DCU is also continuing to seize domains and “sinkhole” them, redirecting malicious traffic to Microsoft servers for threat intelligence analysis. It has shared evidence from the case with law enforcement agencies to support criminal investigations. Fortra has worked with European law enforcement agencies to remove nearly 600 malicious IP addresses. And both companies have shared their expertise in the case at security conferences to help others battle ransomware.
“This case is a powerful example of our team’s mission in action,” says DCU head Masada, a former federal prosecutor who led cases against major cybercrime groups in that role. “It highlights our commitment to strong partnerships and continual innovation to disrupt cybercriminal operations and protect not just our customers but the broader digital ecosystem.”
For DCU investigator Lyons, the operation was another opportunity to make the digital world a little safer for large numbers of customers through teamwork with his colleagues, an eclectic group of lawyers, analysts, former law enforcement and government workers, and other experts dedicated to fighting cybercrime. “I’ve been able to do a lot of cool things in my life, protecting national security with the military and counterintelligence and things like that,” Lyons says. “But if I had to look back on my career, the greatest impact I’ve ever had is this job. We are helping millions of people.”
Microsoft’s chief technology officer and amateur potter Kevin Scott on how the web will be transformed by AI in coming years
Back in 1993, Kevin Scott saw a demo of the Mosaic browser, the first widely used graphical interface for the nascent World Wide Web. As a technologist more interested in back-end workings than user experiences, he wasn’t impressed.
“I was like, this is the stupidest thing I’ve ever seen,” recalls Scott, then an intern at the National Center for Supercomputing Applications at the University of Illinois Urbana-Champaign, where Mosaic was developed. “I didn’t understand it at all. Like, why would anyone care that?”
But a few years later, Scott’s thinking shifted.
He built his own HTTP server from scratch, stood it up on a public IP address and realized anyone in the world could access it. Scott saw how easy it was to create and on the internet – an open platform that offered people the power of permissionless innovation, a place where anyone with imagination could go experiment and try out their ideas. Using a simple set of protocols, people could build what they wanted, how they wanted, no approval needed.
Now Microsoft’s Chief Technology Officer, Scott sees a similar spirit of openness and innovation around the agentic web, an emerging vision of an internet powered by artificial intelligence (AI). “I haven’t felt this sort of excitement and this amount of creative energy building brand new things in a while,” he says.
As Scott explains, the agentic web is an open ecosystem of AI agents that can act on behalf of users. These agents won’t just answer questions. They’ll perform complex tasks, make purchases and interact with services. They can navigate websites and APIs. They will understand users’ goals and preferences, learning from interactions to improve over time.
“You want to be able to tell an agent to go do arbitrarily complicated things,” he says. “And it should be able to get access to all the resources it needs to do those things relatively autonomously, inside of the parameters you’ve defined for how much you want to be involved in the process.”
The agentic web represents a radical shift in how we use the internet and what we have come to expect from it. In the 1990s, websites were mostly read-only, static pages of content that users couldn’t interact with. There was no AI involved, and any “intelligence” came from basic algorithms and humans creating and linking content.
Over the following decades, the web became a more dynamic and engaging experience. Social media platforms allowed people to connect online, and websites evolved from static information hubs to virtual communities. Users became participants and content creators, not just consumers of information.
As the web evolved through the 2000s, artificial intelligence was advancing in ways that would soon converge with internet services. AI researchers leveraged the massive datasets the web produced to train powerful models. That laid the groundwork for large language models, which began to emerge in the 2010s and transformed how we interact with digital content, enabling machines to understand and respond to human language with unprecedented fluency.
Large language models, Scott says, shifted web from typing keywords into a box – “that was revolutionary technology 20 years ago that kind of looks barbaric now by comparison” – to a more interactive, natural way of getting information.
“You don’t have to think things in terms of keywords,” he says. “You just say exactly what you want, and to the extent that the system has to guess at all what it is you’re looking for, it can even ask you to clarify.”
Microsoft’s launch of Copilot in 2023 further redefined how people use and interact with the internet. Not simply a standalone chatbot, Copilot was designed to enhance productivity and creativity in work and daily life. Integrated across Microsoft applications, the conversational assistant quickly became a valuable tool capable of helping with everything from summarizing meetings and managing inboxes to helping plan vacations and suggesting what to make for dinner.
In late 2024, Microsoft introduced Copilot Agents, task-specific assistants that can act autonomously, orchestrate workflows and respond to triggers from external systems. While Copilot began as a productivity assistant, it has become a foundational layer for Microsoft’s vision of the agentic web, where AI agents collaborate across systems and websites to handle complex tasks for people.
Achieving that vision, Scott says, requires a new set of protocols, standards and conventions that allow agents to interact with the web in meaningful ways. And crucially, he says, the agentic web must remain as open as possible to encourage broad participation and not stifle innovation.
“The thing that worries me most AI, more than anything else, is that we lose that environment of participation too soon because of commercial pressures,” Scott says. “In the early stages of something like AI, you have no idea whether you’ve discovered the best possible idea yet. So you don’t want anything to get in the way of that discovery of the best possible.” Everyone working in AI right now, Scott says, should strive for more openness, not less.
“We should want things to evolve more in the direction of how the internet evolved, where it really is simple and permissionless and encourages lots of people being able to do the most creative thing that they can imagine doing – rather than things being more vertically integrated and closed off to people being able to freely participate.”
Microsoft’s role, Scott believes, is to provide platforms that empower others. Microsoft’s partnership with OpenAI is key to advancing the agentic web, he says, but there is a need for broader collaboration – with AI infrastructure companies, developers and regulators.
“As a platform company, we’re only as good as our partners are,” he says. “We have to create the conditions for lots of people to have a lot of success.”
As an example of that openness, Scott points to the Model Context Protocol (MCP), a new standard introduced by AI company Anthropic that standardizes how AI systems connect to external data sources and tools. Like early internet protocols, MCP is composable – designed to be modular and interoperable – and can be combined with other components or systems to build more complex functionality. Scott likens it to HTTP, the system that lets browsers communicate with websites.
“It’s a super, super simple protocol – it’s open source, and it’s not that much work to wire a thing you’re already doing or build something from scratch and give it an MCP interface,” he says with enthusiasm. “Anything that can speak to an MCP endpoint can then access the thing you just put out there. It has all of the things that I thought were really interesting the early web protocols.”
Another key innovation is NLWeb, an open-source framework developed by Microsoft to bring conversational interfaces to websites. The system lets any site become an AI app by enabling users and AI agents to interact with web content using natural language. Instead of having to rely on site menus or keyword searches, users can just ask questions – for example, “Can you tell me which recipes on this site are gluten-free?” – and the NLWeb-equipped site responds intelligently.
NLWeb was developed and conceived by R.V. Guha, a technical fellow at Microsoft and the creator of widely used web standards including RSS, RDF and Schema.org. Built on those standards, NLWeb makes it easy to make content and services discoverable by AI agents, Scott says.
“It’s a low-effort way to participate in the agentic web,” he says. “There are businesses that don’t exist yet that are going to use NLWeb as the way to build their little slice of the agentic web to help agents serve their users better.”
Scott gives a practical example from his own life: sourcing specialized and sometimes obscure materials for his pottery projects, like sodium hexametaphosphate (the active ingredient in Calgon), which is used to enhance ceramic glazes. With NLWeb-enabled sites, an agent could find suppliers, compare prices and even make purchases – all without Scott needing to do anything.
“Instead of having to make a list of things that I want to buy and ordering them, I could have had the agent do all of it,” he says.
One recurring theme in Scott’s agentic web vision is that of memory – specifically, how AI agents remember and use information. Without memory, agent interactions are transactional and limiting. “If you were delegating a task to an employee or colleague who had no memory, it would be very difficult for them to do anything useful,” he says. “Memory will make agents more efficient and useful.”
Scott envisions standards for memory like those around documents – created, owned and shared by their users. The approach, he says, would allow people to control how their data is used and prevent fragmentation, with different agents having siloed memories and being unable to collaborate on tasks.
“You don’t want to have to teach every new agent you’re using what your preferences are,” he says. “It would be way easier if those were part of a set of memory preferences you could .”
Recent breakthroughs are already improving those capabilities, Scott says. Copilot and other agentic systems are getting better at remembering information from interactions and using it in the appropriate context, similar to how human memory works.
“If you think biological memory, it has really good recall. You can recall across a huge number of experiences,” Scott says. “The first thing that you remember something may not be accurate, but you have a whole bunch of tools at your disposal to refine the precision of the recollections. I think that’s going to be an important quality of the memories that agents have.”
Scott grew up in the small rural town of Gladys, Virginia. His was a family of makers, the sort of folks who were forever tinkering with cars or restoring furniture and couldn’t let their hands be idle, even for a moment. Working on furniture projects with his dad and grandfathers as a kid, Scott developed a deep curiosity craftsmanship and a fascination with how things are made.
As someone who is passionate making things – from digital tools to books, jewelry and ceramics – Scott views the question of the role of artificial intelligence in creativity as “one of the more interesting challenges of our times.”
In an interesting experiment, he recently used Copilot and other AI tools to reverse-engineer a 17th-century Japanese ceramic firing process called hikidashi, in which pots are pulled from a hot kiln to quickly cool and develop a distinctive glaze. There is little documented the technique in English, and AI helped Scott find Japanese sources of information, translate them and adapt the process to modern materials.
“If I didn’t have AI to help, the problem would probably be so daunting that I would just have to give up on it before I got it solved, because I’d have to move onto something else,” he says. “For me, it’s really accelerating my own creative productivity.”
But Scott is clear that AI should support creativity, not replace it. “I don’t want AI designing anything I’m making. I’m perfectly happy to use it to help me solve a technical problem with something that I’m doing, but I want to do the work,” he says. “I think the most important thing for a creative person is that they should be able to choose how they want to use AI tools, if at all.”
That philosophy extends to Scott’s broader view of AI. Tools are only as important as the people who use them, he says. And the best tools empower people to create for each other.
“You can have a whole universe where AI is making a bunch of shit for other AIs,” he says. “But we as human beings would be profoundly uninterested in that. We do things for each other.”
Scott is optimistic the current moment, seeing it as an inflection point that could rival or even surpass the mobile revolution. “We are on an inevitable course right now,” he says. “The technology exists. It’s good enough. The only thing stopping it is cost and diffusion.”
His advice? Be ambitious. Try things. AI technology is getting better and cheaper all the time, so don’t wait and risk having to play catch-up later. To Scott, the agentic web offers the same exhilarating, limitless possibility he felt standing up that server decades ago.
“There are a whole bunch of people who are working feverishly using these AI tools to make brand new things that I haven’t even imagined yet,” he says. “And it could be the most amazing thing in the world. And then I get the chance to experience new things and have my mind changed.”
“To me, it’s just awesome when the world’s in that state.”
Key terms to help you understand this new AI-powered version of the internet
Agent (A) An AI-powered helper that can take actions, make decisions and interact with other agents or humans on your behalf. Think of an agent as a digital assistant that’s proactive, not just reactive – able to handle tasks, answer questions and learn as it goes.
Agentic web (B) An open ecosystem in which AI agents act on behalf of users – from handling complex tasks to making purchases and collaborating with other agents across different sites and services. The evolution of the internet, the agentic web will make online experiences more personalized and efficient.
Agentic memory (C) An agent’s ability to remember things over time, like your preferences, past conversations and tasks you’ve asked it to do. Instead of starting from scratch every time, agentic memory helps agents build up knowledge and get smarter helping you.
Copilot Agents (D) Specialized AI agents built into Microsoft Copilot that can help with specific tasks like researching, summarizing or organizing information. Designed to work together and with you, Copilot Agents can be customized for different roles and workflows.
Model Context Protocol (E) A new technical standard introduced by AI company Anthropic that helps AI agents connect to external tools, apps and data sources in a smart and consistent way, even if they’re running on different platforms or models. MCP is like a common language that allows AI agents to “talk to” other systems to get things done.
NLWeb (F) Short for “Natural Language Web”, NLWeb is an open-source framework developed by Microsoft that lets humans and AI agents interact with web content using natural language. Any NLWeb-enabled site can become an AI app – instead of clicking through menus or forms, you just ask for what you want using natural language.
Carl Ledbetter has been shaping the world for 30 years. As Microsoft’s Partner Director of Design, he is the visionary behind landmarks in hardware including the IntelliMouse, the Xbox and the game-changing Adaptive Controller. He talks us through five influential creations he helped bring to life
The IntelliMouse (1996)
“My first day at Microsoft was 30th January 1995, when I was hired to design a new mouse. At the time, Microsoft was very much a software company, so I expected to pick up a few new skills, meet interesting people and create a product or two and be done. I certainly didn’t expect to still be here 30 years later contributing to a legacy of hardware design.
I soon realized the most important thing when designing products for Microsoft was to understand the customer. With the mouse, the challenge was coming from the Excel team. They were saying that people were producing enormous spreadsheets that were too big to fit on a screen. The only way to navigate around this environment was through scroll bars at the top and bottom and then trying to zoom in and out. My job was to create a mouse that made that easier.
I quickly learned a lot spatial mapping. When someone is navigating on a screen, their mind maps forward, back, left and right in a certain way. It’s abstract and subconscious, but you cannot mess with that as an industrial designer. If a product looks good and brings beauty to what you’re doing, that’s great, but it needs to be intuitive, and it must have a functional value.
With that in mind, I started thinking how to put control directly in the user’s hands. I created sketches and built prototypes with all these different ways to zoom in and out, to pan, to scroll… Eventually I determined that a wheel was probably the best way of doing this: it was adaptable and flexible and fit naturally within the mouse’s shape. We refined it, shaped the mouse to fit the hand and made the wheel feel as intuitive as possible. The result was the IntelliMouse – which went on to be Microsoft’s most popular and best-selling mouse for years. I’m proud that it set the bar for ergonomics, and it is great to see the wheel still deployed in a lot of mice today. When people ask what I do, my wife always jokes, ‘Yeah, he invented the wheel.’”
ActiMates Barney (1997)
“Six months into my role at Microsoft, the hardware division made a bold move, acquiring a company pushing the boundaries of interactive technology. Together, we launched a new generation of toys – starting in 1997 with none other than the beloved purple dinosaur Barney. The reason I’ve included ActiMates Barney in my selection is because it’s another example of where Microsoft was ahead of its time.
The industrial design aspect was limited – we created intuitive receivers that fit into both the ActiMates ecosystem and the – but the experience was incredible. Kids could play with Barney on his own – you could cover his eyes and he would say, “I can’t see you” and then you’d pull your hand away and he would say, “there you are” – but the real differentiator was when you connected him to a PC. There was a game which asked you math problems and, as you were going through them, Barney could help you because of the connection between the game, the PC and the toy. If you plugged a receiver into your TV, you could watch the Barney & Friends show with the toy to you and it would respond to whatever was happening on screen. It was like having a virtual friend there for these kids. That didn’t exist before.
ActiMates was an ambitious and forward-thinking entry into consumer entertainment and helped Microsoft build momentum in the PC gaming space. It also proved that Microsoft technology could be more than just functional – it could be magical.
Like pretty much everything I’ve been involved in, it is part of a quest to try to do things that impact people in new ways. Of course there’s a business behind these things, but that’s never the starting point. The beginning is always ‘How do we do something that can really change the way people engage with the world?’ And that’s not a bad way to spend your career.”
The Xbox (2001-today)
“The mission behind these consoles echoes everything I’ve learned over 30 years – to create technology that’s powerful, purposeful and beautifully integrated into people’s lives. How did Xbox come to be? For the first-generation version (released in 2001), we had to be super scrappy: we were leveraging off-the-shelf components to get it out. But what is interesting for me is how we refined it with every new iteration.
One of the first things I did was to work on the controller. The first controller was way too big. It hurt people’s hands, so we used our human factors expertise for the iteration – it was designed for comfort. We thought control layouts and worked with female gamers to see what was needed for their hand sizes.
This human-centric design was at the heart of everything we did with Xbox from then on. With Xbox 360 (2005), we started to push what could be done with wireless technology and online gaming. Xbox 360 S was an exercise in reduction. Instead of having all these plug-in wireless receiver antennas and the hard drive on top that looked a bit like Frankenstein’s forehead, we were able to make the console significantly smaller and still build in everything.
We made a misstep with 2013’s Xbox One, we got a few things wrong with that, but it’s like soccer, right? You miss, but it’s all the recovery. How fast did you bounce back? And Xbox One S and Xbox One X were definitely comebacks. These products are incredible.
I just love the progression. We design for the everchanging landscape of devices and the way people play. Every time we make a new edition, it’s this exercise of refine, refine, refine. So while on the inside we’re adding more and more technological capabilities, on the outside we’re striving to keep it simple. And we’re not done yet. We recently launched Ally X, which is a collaboration with Asus [to create a new line of handheld gaming devices]. This world just keeps getting bigger.”
“While it wasn’t the commercial success I thought it deserved to be, Zune was, in many ways, the highlight of my career. There were so many ideas crammed into that music player. It was a physical device but also an entire ecosystem that had a bunch of technological advancements you can see in technology today – it has had a real ripple effect. You could tracks Zune-to-Zune, Airdrop before Airdrop if you will; it had a PC client so you could listen across devices, Zune marketplace where you could buy tracks and set up playlists and a subscription service, offering unlimited access to millions of songs. Looking back on it, I don’t even know how we did it all in the time we had.
From an industrial design perspective, we were really pushing what you could do with molded resins. If you look at the design of that first device, you can see what’s called a ‘double shot’ plastic casing on it. The first shot was an opaque color, sort of root beer brown, and then over the top of that, we layered a coating that almost made it look like worn beach glass. What that gives you is a depth to the product, thanks to the ways light would come through and reflect off the surfaces. We really wanted to create something that when you held it in your hand, it felt special, not just like a hunk of plastic. We wanted to feel you’re getting a glimpse into this world of music.
Zune was one of the most collaborative projects I have worked on. Everybody was shipped into this small building down in Bear Creek, which is off Microsoft campus down in Redmond. You had marketing, designers, program managers and engineers all jammed into this building, and it felt like this small community of purpose. Everything was celebrating the art of creating music. There’s a whole case study on Zune that would show how if you can mobilize people with a clear goal to go do something, you can change the world.
While we may not have sold millions, it’s awesome to see the ideas we had in that space play out in different ways, in different businesses and different teams. I love that. There are certainly no sour grapes.”
The Xbox Adaptive Controller (2018)
“In my 30-plus years in design, the product I am most proud of is the Xbox Adaptive Controller, which was designed to meet the unique needs of gamers with limited mobility. It was one of those grassroots ideas that seems to take on a life of its own. You can trace the origins back to the Xbox Elite controller, which allowed you to personalize the device by remapping buttons and controls for how you play. When we were doing some research on what people think of it, we discovered that people with disabilities were modding it so they could play games one-handed. This started us thinking what more we could do. After a Microsoft Hackathon, we came up with a design that we thought would be even more adaptable and inclusive, but when we started meeting with these players, we found that it provided little value because many of them couldn’t hold the controller. We were being told, ‘The idea of it is right, but the solution is wrong.’ That’s when I first heard the phrase: ‘Nothing us without us.’ We were being told, ‘Don’t pretend you know what we need and what we want on your own: Work with us.’ This became something I applied across my professional life from then on – don’t be so bold as to design for people whose needs you don’t understand. So, we started working with hospitals and wounded veterans. They tried prototypes, gave us feedback and helped create the Adaptive Controller we know.
It’s not a mass market product, but I don’t think I’ve worked on anything with a bigger impact. We created something that unlocked the ability for people to play games that they could not otherwise, and as a designer, that’s a proud moment. I’ll never forget talking to a wounded veteran who told me that this product changed his life. Before he felt like an outcast, like he no longer fit in, that all the things that he used to like to do, he couldn’t do any more because of his disabilities. But through gaming he found a new sense of purpose and a place where the playing field was even. That was very powerful. Since 2014, Microsoft’s core mission statement has been ‘to empower every person and every organization on the planet to achieve more.’ I can’t think of a product I’ve worked on that better embodies this than the Adaptive Controller.
It’s part of the reason I’m still excited to be at Microsoft 30 years on. There’s always a new challenge. Right now, we are seeing a pivot for the entire industry with AI, and Microsoft is at the heart of that. I, like a lot of people, use AI every day, and it has profoundly changed the way I work. I can get a lot more done. We’re in a constant state of change with technology, and AI is the latest great leap forward. Being in the middle of that, seeing how we work and interact with the world changing, is a pretty cool place to be.”
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
