A federal court filing has done what years of privacy debates couldn’t: it forced Microsoft to publicly explain a tracking identifier built into every Windows installation. The identifier is called a GDID, short for Global Device Identifier, and until this case surfaced, most Windows users had never heard the term.
The story broke after Finnish authorities detained a 19-year-old traveler at Helsinki’s airport in April 2026, acting on an Interpol Red Notice. By July, US prosecutors had unsealed a 39-page complaint naming him as Peter Stokes, an alleged member of the Scattered Spider hacking collective, tied to a 2025 ransomware extortion attempt against a US jewelry retailer. Buried inside that complaint was a technical detail that has since drawn attention from security researchers worldwide: Microsoft’s own GDID system, quietly running in the background of roughly 1.6 billion Windows devices, was central to how investigators tracked Stokes across VPNs, proxy servers, and three countries.
What makes this case notable isn’t just the arrest. It’s the confirmation, in Microsoft’s own words within a federal filing, that the GDID exists, that it persists across a device’s lifetime, and that there is currently no built-in way for a user to switch it off without breaking core Windows features like activation and Store access.
What Is a GDID and Where Does It Come From
According to the unsealed complaint, a Microsoft representative described the GDID as a persistent, device-level identifier meant to uniquely identify a single Windows installation, whether on a physical machine or a virtual one, across specific Microsoft services.
In practical terms, a GDID functions as a permanent digital fingerprint that Microsoft assigns to a device the moment Windows is installed or a user signs in with a Microsoft account. Microsoft primarily uses the identifier for software licensing and Microsoft Store app management. Because it links a device’s activity to a single, stable identity, however, it also gives investigators a consistent thread to follow, even when a user changes IP addresses or routes traffic through different VPN services.
The identifier survives routine Windows updates, though a full, clean reinstall of the operating system generates a new one. Even then, Microsoft acknowledged in a footnote to the complaint that a single Microsoft account can accumulate multiple GDIDs over time, meaning old and new identifiers can still be linked back to the same account.
A Single Sentence of Public Documentation
Despite its scope, Microsoft has published almost nothing about the GDID outside of internal or enterprise-facing materials. The only public reference security researchers have located is a single line in the Azure Monitor documentation for Delivery Optimization reporting, where a data column labeled GlobalDeviceId is described only as an identifier “used by Microsoft internally.” Everything else about how the GDID is generated and transmitted has come from independent reverse engineering, not from Microsoft’s own consumer-facing documentation.
How Windows Actually Generates a GDID
Independent researchers who examined the system trace its origin to the Microsoft Account sign-in process itself.
From Sign-In to Storage
When a Windows device is linked to a Microsoft account, a background system service known as wlidsvc communicates with Microsoft’s login servers and receives a value called a Device PUID, or Passport Unique ID. This value is generated on Microsoft’s servers, not calculated locally from anything unique to the hardware. Windows simply receives the string and stores it.
That PUID is written in plain text into the Windows registry, under the current user’s identity settings. From there, the Connected Devices Platform, the same background service that supports features like Phone Link, cloud clipboard syncing, and Nearby Share, reads the PUID and registers it with Microsoft’s internal Device Directory Service, the identity system behind Microsoft’s cross-device features. At that point, the value is reformatted with a lowercase “g” prefix, becoming the GDID. Delivery Optimization, the peer-to-peer update-sharing feature in Windows, then reports that same value back to Microsoft’s servers whenever a device shares or receives update data with other Windows machines on the network.
The Simple Version
Signing into Windows with a Microsoft account triggers a server-assigned, permanent ID number tied to that installation. Several background Windows services read and relay that number, and it becomes attached to activity data the device reports back to Microsoft, including update-sharing traffic.
Reinstalling Windows does generate a new GDID, but Microsoft’s own account, OneDrive, and activation records give the company multiple ways to associate the new identifier with the old one, provided the same Microsoft account is used again.
How Investigators Used the GDID to Track Stokes
According to the complaint, Stokes was allegedly identified largely because he used the same Windows device across nearly all of his online activity, allowing the GDID to link actions that would otherwise have appeared unconnected.
The Jewelry Retailer Breach
Prosecutors allege that members of Scattered Spider called the retailer’s IT help desk from Google Voice numbers, impersonated locked-out employees, and convinced support staff to reset three internal accounts, two of which had administrator-level access. From there, the group is accused of deploying a network tunneling tool called ngrok to bypass the retailer’s defenses, transferring roughly 77 gigabytes of data to cloud storage, and ultimately sending a ransom demand for $8 million in cryptocurrency. The retailer refused to pay and reportedly spent close to $2 million on incident response and cleanup.
Connecting a Device to a Person
Investigators subpoenaed ngrok and traced the account used in the attack to a specific VPN proxy IP address, a dead end on its own since proxy addresses rotate constantly. But Microsoft’s records showed that a device carrying a specific GDID had visited the ngrok signup page at the same moment the account was created, then visited the retailer’s own website three hours later through the same proxy address. Because a GDID does not rotate the way a VPN exit node does, it gave investigators a stable anchor point to build a timeline around.
Agents then cross-referenced that device’s activity against other accounts already suspected of belonging to Stokes. The table below summarizes the key correlations described in the complaint.
| Date | Device Activity Tied to the GDID | Corresponding Account Activity |
|---|---|---|
| June 4, 2024 | Device used an IP address in Tallinn, Estonia | Same IP logged into a Snapchat account minutes earlier and a Facebook account about 80 minutes later |
| November 17 to 18, 2024 | Device appeared on a New York-based IP address | Matched logins to an Apple account and a Snapchat account |
| November 26, 2024 | Device visited the Empire Hotel’s website | A Snapchat photo posted the day before matched décor from an advertised Empire Hotel suite |
| February 2, 2025 | Device appeared on a Thailand-based IP address | Matched Apple and Snapchat logins; a Snapchat post the day before referenced a Bangkok hotel |
| January 8, 2025 | Device logged into the mobile game Growtopia from an Estonian IP | Same IP had accessed an Apple account, then a linked Ubisoft account, two minutes earlier |
No single entry in that table would have been conclusive on its own. What made the case, according to the complaint, was that the same GDID kept surfacing at the same times as accounts investigators already linked to Stokes, across four countries over roughly eight months. The filing also notes that Microsoft had flagged Stokes to the FBI once before, in an October 2024 referral describing what the company called “online services telemetry.”
Why Privacy Researchers Are Uneasy Despite the Arrest
Few security researchers are questioning whether the right person was arrested. Prosecutors allege Stokes and other Scattered Spider members were involved in more than 100 corporate intrusions and over $100 million in ransom payments. Rather, the concern centers on how little the public knew about the GDID system before this case forced it into the open.
Expert Reaction
Malware researcher Costin Raiu raised the issue on the Three Buddy Problem security podcast, questioning how widely similar identifiers exist across other platforms and whether they are tied more permanently to hardware itself. Security researcher Matthew Hickey was more direct, describing aspects of Windows telemetry as functioning like surveillance software.
No Consent Prompt, and a Licensing Dependency
Two structural details underpin those concerns. First, a GDID is assigned automatically the moment a user signs into a Microsoft account, with no consent screen or opt-out prompt. By comparison, Apple’s advertising identifier requires an App Tracking Transparency prompt and offers a visible reset option, and Android’s system works similarly. Windows currently offers neither.
Second, the identifier is tied directly into how Windows verifies its own license. Massgrave, the developer group behind the Microsoft Activation Scripts project, has noted that Windows setup sends hardware information to Microsoft’s servers and receives identifiers back, the same tokens later reused for Store access and license validation. Breaking that pipeline breaks activation and Universal Windows Platform app functionality, which is why a full workaround does not currently exist for most users. Anyone who has lost a Windows license after replacing a motherboard has already encountered a smaller-scale version of this same system.
Every major operating system retains some form of persistent device identity, and every technology company can be compelled by law enforcement to hand over records. What sets Microsoft apart in this case, researchers argue, is the combination of limited public disclosure and limited user control compared with Apple’s and Google’s equivalent systems.
What Windows Users Can Do About It
A clean Windows reinstall is not the fix many assume it to be. It generates a new GDID, but signing back into the same Microsoft account gives Microsoft ample means to connect the new identifier to prior activity. A few settings changes offer more meaningful protection, though none eliminate the underlying system entirely.
- Use a local account instead of a Microsoft account during setup, where possible. Microsoft has made this option harder to find in recent versions of Windows 11, though it remains available with extra steps.
- Turn off optional diagnostic data collection under Settings, then Privacy and Security, then Diagnostics and Feedback.
- Disable personalized advertising by turning off the advertising ID under Privacy and Security, then Recommendations and Offers.
- Turn off Cloud Content Search under Privacy and Security, then Search, to stop local searches from being sent to Bing.
- For journalism, activism, or personal safety situations involving a real threat model, security researchers generally recommend avoiding Windows entirely in favor of a Linux distribution routed through Tor, since a GDID identifies the Windows installation itself regardless of which VPN service sits on top of it.
The Bigger Picture
Stokes’ arrest is not in dispute among researchers covering this case, and the underlying investigation into Scattered Spider’s activity has been treated as a legitimate law enforcement success. The broader issue researchers are raising is one of transparency. A persistent device identifier used for licensing and fraud prevention is not unusual among major software vendors. What is unusual, in this case, is that Microsoft’s only public documentation of the GDID system, prior to this court filing, was a single sentence in an enterprise IT reference table, not disclosed in any consumer-facing privacy documentation reviewed by researchers.
Users who take steps to limit account-based tracking, disable optional telemetry, and switch to a local account can reduce some data exposure. None of those steps, however, change the fact that the GDID itself continues to exist on Windows devices, tied to a Microsoft account rather than to the user directly, and that its existence became broadly known to the public only after a federal court filing made it unavoidable.



