DEVICES

GDID - An invisible identifier on Windows that helped the FBI capture the famous hacker Scattered Spider

Bùi Đăng MinhMonday, July 20, 20265 min read
GDID - An invisible identifier on Windows that helped the FBI capture the famous hacker Scattered Spider

A 19-year-old man was lining up to board a plane at Helsinki airport to go to Japan when he was stopped. Peter Stokes, a US-Estonian citizen, was arrested on charges of conspiracy, illegal computer intrusion and fraud. What makes this arrest notable to me is not Stokes' identity, but what helped track this young man down: an identifier built into every Windows 11 installation, something that almost no normal user knows about its existence.

The attack started with a phone call

Stokes is accused of being a member of Scattered Spider, a cybercriminal group that also operates under the names Octo Tempest, UNC3944 and Oktapus, and according to the US Department of Justice has extorted more than $100 million to date. The way this group operates is not by sophisticated exploits (technical vulnerabilities), but by techniques that manipulate human psychology, also known as social engineering. The incident that led to the main charges against Stokes occurred in May 2025: attackers called the technical support department of a high-end jewelry company in the US via Google Voice, pretending to be internal employees whose accounts were locked. The support department believed and reset the login information, helping this group take over three accounts, of which two accounts had administrative rights. From there, they stole important data and demanded a ransom of $8 million in cryptocurrency. The company eventually regained the infrastructure and did not pay the ransom, but operational losses were said to be around $2 million.

[​IMG]
[​IMG]

It is worth mentioning that this case became the thread for prosecutors to follow the digital and paper trail, eventually leading to Stokes' arrest in Helsinki more than a year later. And in that tracking process, Microsoft plays a role that perhaps even Windows users did not expect.

What is GDID, and why does it "know" so much?

According to public court documents, Microsoft provided the FBI with data from GDID, short for Global Device Identifier, a unique identifier assigned to each Windows installation to track device-specific telemetry data. This is also the reason why sometimes replacing a major component in your computer causes your Windows license to be revoked, because the system recognizes that the "device" associated with that GDID code has changed.

What-is-GDID-the-Windows-device-fingerprint-that-helped-the-FBI-catch-a-hacker-scaled.jpeg
What-is-GDID-the-Windows-device-fingerprint-that-helped-the-FBI-catch-a-hacker-scaled.jpeg

Microsoft admits that GDID cannot be disabled on Windows From court documents, it can be seen that GDID had almost built a fairly complete profile on Stokes before the prosecution could build a case, the only thing left was to put the pieces together into a complete story. Information such as web access history, gaming history, IP address, use of tools like Ngrok, simply a tool used to open network tunnels often used by both legitimate developers and hackers, Stokes' Azure account status, are all recorded with a specific time stamp, and all this data is provided by Microsoft to the investigation party. In other words, Stokes' Windows computer quietly recorded enough detail to link a specific person, specific physical hardware, to network activities and geographic location, without him voluntarily providing any information.

The line between cybersecurity and user monitoring

From a law enforcement perspective, this is clearly a positive story: a seemingly harmless technical identifier has helped bring a suspect linked to a notorious cybercrime group to justice. But I think what's worth stopping to think about is not the results, but the opposite question: how deep is the level of detail and penetration of the telemetry system on Windows really? In this case, GDID data was used to catch a hacker. But if the same data falls into the hands of someone with bad intentions, or is simply misused outside the scope of a criminal investigation, the consequences will be completely different. The tech-savvy user community has been complaining about Windows' level of telemetry data collection for years, and a whole trend of "debloat" (removing unnecessary data collection components, ads, and features from Windows) has arisen from that discomfort. But unlike components that can be disabled with a few clicks in the settings, GDID is not something users can actively disable.

Nguồn / Original source: Tinh tế