
Adobe stock
In April, a 19-year-old member of the Scattered Spider hacking group was arrested at Helsinki airport on a United States complaint alleging the individual was responsible for a range of crimes, including a ransomware attack on a US-based luxury jeweller.
What has everyone talking is not the individual arrested, but how the United States was able to track down and arrest them. In an unsealed criminal complaint, US prosecutors detail how Microsoft provided the technical information the US government used to track the individual’s illegal activities across virtual private networks (VPNs), proxies, and multiple countries.
The 39-page criminal complaint provides some of the first in-depth details of Microsoft’s Global Device Identifier (GDID). GDID is “a persistent, device-level identifier designed to uniquely identify an installation of a Windows operating system on a device, either a physical device (e.g., a mobile phone or laptop) or virtual machine, across certain Microsoft services and scenarios.”
Lack of transparency
Microsoft’s own lack of transparency regarding GDID means we can only base our understanding of GDID on the unsealed criminal complaint and independent, third-party reverse engineering, which appear to indicate that GDID can be used to track nearly all of one’s activities back to a Windows device. Reverse engineering confirms that when a Windows device logs in with a Microsoft Account, a server assigns a permanent GDID that is stored locally, used by various Windows background services, and included in all reports the operating system sends to Microsoft.
Before the criminal complaint, the only mention of Microsoft’s GDID described it as an “internal identifier.” In the criminal complaint, Microsoft claims GDID is for managing software licensing, but its ability to link online activity and its central role in tracking the alleged Scattered Spider hacker across multiple countries despite network-level protections indicate that GDID can be used for far more than software licensing.
The fact that GDID can negate certain network-level protections brings new risks to Canada’s privacy and security. Now that the US and everyone is aware of GDID, there is now a race to leverage this for legitimate and illegitimate purposes.
The potential risks of GDID do not necessarily come from Microsoft itself, but rather from how it could be leveraged by actors seeking to harm DND/CAF or Canada. This poses a new risk, given that Windows is the most widely used operating system in Canada and Microsoft is the most used cloud service by the Government of Canada.
The Government of Canada must demand that Microsoft be fully transparent about how GDID can be used to track activity.
The Government of Canada is a major customer of Microsoft, and this relationship will not end anytime soon. This is also the case for DND/CAF, which is arguably one of the most reliant on Microsoft products within the Canadian government.
Looking at Defence365
This reliance goes beyond the fact that Microsoft Windows is the most widely used operating system because DND/CAF’s entire digital ecosystem relies on Microsoft products. DND/CAF uses Defence365, a defence enterprise version of Microsoft 365, a cloud subscription service that includes Exchange, Outlook, Teams, SharePoint, OneDrive, and more, to provide the entire Defence Team with digital tools for working and collaborating. DND/CAF’s reliance on Microsoft products is growing too.
In June 2025, DND/CAF announced $560 million in investments for “digital foundations,” as part of Our North, Strong and Free. A significant portion of these investments went towards Microsoft and improving Defence365. The new revelations about GDID’s ability to track devices regardless of network-level protections raise concerns about DND/CAF's ability to use Microsoft products without being tracked by foreign actors.
This is important to understand its impact, as DND/CAF use many network-level protections that would normally prevent such tracking. DND/CAF must now contend with the fact that these existing protections are insufficient to guard against a new method of tracking the military’s activities. GDID is no longer just an internal identifier for Microsoft but must be treated as a tool for tracking activity.
This raises multiple questions: How much can Microsoft’s GDID be used to track the Canadian military, and can it be used by the United States and malicious actors against Canada? Microsoft’s lack of transparency about GDID does not inspire much trust given the existing concerns about Microsoft's willingness to protect digital sovereignty.
Even if Microsoft increases its transparency, DSG and CAFCYBERCOM must partner with CSE to conduct a risk assessment of GDID on the military’s existing digital ecosystem and its impact on tracking military operations. DND/CAF’s Digital Foundations Initiative is costed at $3.6 billion, with $800 million required on an ongoing basis; only $2.25 billion and $560 million ongoing have been allocated thus far.
Although not all of this will be invested in Microsoft products, a significant amount will go to Microsoft products or applications that run on Windows operating systems. This makes it necessary to understand the extent to which Microsoft and foreign actors can use GDID to track or identify DND/CAF so that the government can take appropriate action to ensure Canadian national defence and sovereignty.
Microsoft did not respond to a request for comment.








