Microsoft's Global Device Identifier Revealed as Tracking Tool in Cybercrime Case

Microsoft's Global Device Identifier Revealed as Tracking Tool in Cybercrime Case

First seen 24 Jul 2026, 11:43 UTC Feeds.4SysopsComputing 83% similarity 48.9

Article Content

Browse articles
ThreatCluster

A US court filing has disclosed that Microsoft's Global Device Identifier (GDID) tracks user behavior across Windows installations. This persistent key, tied to every Windows OS since Vista, is generated on Microsoft's servers and stored locally, enabling tracking of various services like Edge and the Microsoft Store. The GDID was instrumental in tracing a cybercriminal, Peter Stokes, who was arrested for a major data breach involving a jewelry retailer. Stokes used the GDID while accessing the victim's site through a VPN, leading to his identification by the FBI. While Microsoft claims the GDID is for internal use, its lack of transparency raises concerns among users and security experts. The incident highlights the potential misuse of such tracking mechanisms in cybercrime.

Key Points: • Microsoft's GDID tracks user behavior across all Windows installations since Vista. • The GDID played a crucial role in identifying a cybercriminal linked to a major data breach. • Concerns have been raised about the transparency and privacy implications of the GDID.

ThreatCluster AI

Timeline

2025-05-01
Scattered Spider hacking group breaches jewelry retailer
The group stole 77GB of data and demanded $8 million in cryptocurrency as ransom.
Computing
2026-04-01
Peter Stokes arrested for cybercrime
The 19-year-old was arrested in Finland and extradited to the USA for his role in the jewelry retailer breach.
Computing
2026-07-01
GDID details revealed in FBI complaint
The FBI's criminal complaint against Stokes disclosed the use of GDID in tracking his activities.
Computing
2026-07-24
GDID tracking concerns raised
Security experts and users express concerns over the lack of transparency regarding the GDID.
Computing

Community

Browse all →