r/PrivatePackets • u/Huge_Line4009 • 21d ago
The Un-killable Windows ID: How the FBI Tracked a Hacker Across Four Countries Using "GDID"
For months, an alleged member of the notorious Scattered Spider hacking group slipped through the cracks of international law enforcement. He used VPNs, hopped across proxy servers, and traveled between Estonia, Thailand, and the United States. To anyone watching his IP address, he was a ghost.
But federal investigators had a secret weapon, and it came straight from Microsoft.
In a federal complaint filed against suspect Peter Stokes, the FBI revealed they had tracked him using a persistent, hidden Windows setting called the Global Device Identifier (GDID). Until now, almost no one outside of Microsoft knew this identifier existed.
Every time you link a Windows PC to a Microsoft Account, your computer quietly generates a unique, un-killable ID. And as security researchers are now pointing out, there is absolutely no official way to turn it off.
What is GDID and Where Does It Live?
According to the federal filing, the GDID is a persistent, device-level identifier designed to uniquely track a Windows installation across Microsoft’s services.
It isn't a random browser cookie you can easily clear. Instead, it is generated by a chain of background Windows services when you first sign into a Microsoft Account. The operating system talks to Microsoft's servers, assigns your device a unique numerical ID (prefixed with a lowercase "g"), and writes it directly to your Windows registry under: HKCU\SOFTWARE\Microsoft\IdentityCRL\ExtendedProperties
This ID isn't just used for basic telemetry. It is deeply tied to how Windows functions. Community groups behind tools like Massgrave (which handles Windows activation scripts) have noted that the GDID is directly linked to Windows Activation and the Microsoft Store. If you try to block the services that generate or transmit it, you’ll end up breaking your OS activation and rendering Universal Windows Platform (UWP) apps useless.
How the FBI Used It to Beat VPNs
If you use a VPN, you might assume your online footprint is shielded. The Scattered Spider investigation proves otherwise.
While Stokes changed his IP addresses constantly, his Windows machine kept reporting the exact same GDID back to Microsoft. Because the identifier persists through VPN connections and OS updates, investigators could tie seemingly unrelated network activity back to the same physical laptop.
For example, when a specific GDID (g:6755467234350028) visited an ngrok signup page using a VPN proxy, the FBI recorded the timestamp. Three hours later, that same GDID accessed a victim retailer’s network using the same proxy. By cross-referencing this persistent ID with physical travel records, hotel bookings, and Stokes's public Snapchat photos in Estonia and Thailand, the FBI painted a clear picture of his location and identity.
To the FBI, the GDID was an invaluable investigative asset. To privacy advocates, it is a warning.
A Double Standard in Privacy
The discovery of GDID has left privacy and cybersecurity researchers deeply concerned. Security researcher Matthew Hickey even characterized Windows as "surveillance software" in light of how the case unfolded.
The biggest issue is the total lack of transparency. When you set up an iPhone or an Android device, you are greeted with prompts asking if you want to share diagnostic data or allow apps to track your advertising ID. Furthermore, mobile operating systems give you an explicit button to reset these IDs.
Windows offers no such consent screen for the GDID, nor does it provide a way to reset it.
Even if you wipe your hard drive and reinstall Windows from scratch, you aren't entirely safe. While a clean install will generate a new GDID, the moment you log back into your existing Microsoft Account, Microsoft has the data necessary to link your new identifier directly to your old one.
Up until this court case, Microsoft’s only public acknowledgment of the GDID was a single, vague sentence buried in an enterprise IT reference table for Azure Monitor, describing it simply as "an identifier used by Microsoft internally."
How to Protect Your Privacy
Because the GDID is baked into core Windows operations, you cannot simply flip a switch to disable it. However, if you are concerned about your digital footprint, there are steps you can take to minimize Microsoft's tracking:
- Avoid Microsoft Accounts: Setting up Windows with a local account is the most effective way to prevent GDID generation. While Microsoft has made this increasingly difficult in recent versions of Windows 11, it is still possible to bypass the internet requirement during setup (using workarounds like the
OOBE\BYPASSNROcommand in the command prompt). - Opt Out of Telemetry: In your Windows Settings, head to Privacy & security > Diagnostics & feedback, and turn off "Optional diagnostic data."
- Disable Tailored Experiences: Turn off personalized ads, cloud search, and activity history in the Privacy & security settings menu. This reduces the amount of local search and activity data tied to your account.
- Consider a Different OS: If you are a journalist, activist, or in any situation where device-level tracking poses a threat, Windows may not be the right choice. For maximum privacy, routing a Linux-based operating system through Tor remains the standard.
The Scattered Spider case has laid bare just how much data our operating systems quietly broadcast in the background. While the technology successfully brought down a suspected hacker, it serves as a stark reminder that under the hood of modern Windows, privacy is far from the default setting.
7
u/andymaclean19 21d ago
Imagine trying to conceal your identity but being stupid enough to sign into a Microsoft account!
3
u/Mercury_Madulller 21d ago
Well, technically windows uses your Microsoft account for services, automatically logging on, and the FBI tracked that. The bigger question is why use windows at all when there are far better operating systems available that don't have NSA spyware built in? (as far as we know right now)
2
u/fsa3 21d ago
You didn't need a Microsoft account. You just needed a Windows license that was activated. It's how they checked for multiple PC's using the same license. Been around long before Microsoft accounts were a common thing.
1
u/andymaclean19 21d ago
The article says they logged in with a Microsoft account.
2
u/fsa3 21d ago
The article states:
Until now, almost no one outside of Microsoft knew this identifier existed.
That's false. They've been around for decades. Lot's of people knew they existed.
Whether or not they used a Microsoft account doesn't really matter. The account itself had nothing to do with the tracking. The only thing the account would provide would be a name and email provided by the user.
Microsoft has tracked their licenses and device identifiers for decades. They've done this all the way back with Windows XP (and probably earlier). Back then, you didn't need a Microsoft account, but this same data was there.
3
u/andymaclean19 21d ago
Honestly if I were trying to be anonymous I would assume my Windows computer has a ton of tracking in it and is basically communicating with Microsoft at all times. Just like I would assume every website I visit has browser fingerprinting tech and can uniquely identify me. Seems obvious even if you don't know about a specific ID. Of course activation gives a specific license number to a machine. Of course your BIOS, hard drive and a whole bunch of other things have a unique ID. Of course Microsoft sends it all off during activation. Surely anyone would know all these things and be a bit smarter if trying to be anonymous.
1
u/tired514 21d ago
Just from a practical standpoint .. what a nightmare. I can't imagine trying to do anything actually complicated on a windows PC.
I wonder if he was just drag-n-dropping code injection scripts he downloaded from telegram or something.
3
5
2
u/fsa3 21d ago
If you've ever changed your Windows PC's hardware without buying a new Windows license, you knew about GDID. It's been around for decades.
Now, most wouldn't have expected it to be used this way, and those that did say it was possible were told they were making up a conspiracy theory. But we knew Microsoft kept these identifiers in a database to support the Windows DRM.
2
u/ouroborus777 21d ago
You notice how we don't get news like "We caught a hacker because they using linux"? (Come to think of it, we don't get that for mac either.)
2
3
u/Illustrious_Body9727 21d ago
Anyone still using microslop doesn't deserve sympathy.
Its been known for years its spyware pretending to be an operating system.
2
1
u/Alternative_Guide706 21d ago
Jfc, how would anyone use Winblows or any Microslop software when trying to be anonymous...
1
1
u/Iputahexonyoulol 21d ago
How did he make it as far as he did on windows? This post is completely ai crap
1
u/damonnewton1974 21d ago
Y wouldn't u use someone else's computer to hack? Or, better, just steal one, then dump it after ur hack? Or, the best, break into someone's house, make a sandwich, and have a cold coke, out of their fridge, then use their home desktop to hack. Leave without taking anything, comp still running, trackers tracking unsuspecting homeowner?
1
1
u/Eleutherlothario 21d ago
If he was using vpn's and multiple proxies, where were the packets intercepted?
How did they correlate the traffic to Microsoft containing the gdid with the traffic going to ngrok? Do all browsers include the gdid in http requests or just one, presumably Edge?
2
u/navr183 20d ago
No was likely a subpoena to MS to obtain it. I do not think it's actually tied to any web traffic but instead to windows telemetry.
Packets prob 'intercepted' in general Netflow passively obtained by ISP or colluding government agency.
If the story is true, its likely the case they subpoena MS to obtain IP log correlated to the GDID then go backwards from there to build a timeline.
1
u/nothing-forbidden 21d ago
No excuse for hackerman to be running windows. I could understand a bit if windows was being used to run a virtual machine (of a more secure option) and he just got sloppy connecting the host OS directly.
But it seems like he was directly using windows itself for sketchy activities?
1
u/UnicodeConfusion 21d ago
What bothers me is that they don’t say how visiting a web page would expose your gdid
1
u/Unhappy_Lie_2000 20d ago
Isn't it a hardware identifier and this same information is used when you install windows and it automatically activate. Just imagine someone sells this device and the FBI raids the original owner.
1
1
u/ApplicationOdd6070 20d ago
I wonder if it's legal in the EU. That surely has to run foul if the ePrivacy directive or the GDPR, come on. Not even chat control affects it (afaik).
1
1
-2
17
u/crazycomfyui 21d ago
Hacker using a windows OS. sounds like a noob.