A federal case against an alleged Scattered Spider member reveals how a Microsoft Global Device Identifier (GDID) helped FBI investigators link a Windows installation to a 2025 breach at a luxury jewelry retailer. The persistent identifier was tied to an ngrok account signup and correlated with IP addresses, online accounts, and travel data — demonstrating how endpoint telemetry can serve as a forensic anchor even when suspects use VPNs and aliases. The case raises governance questions for enterprises about what Windows telemetry collects and what can be disabled. The breach itself followed the classic Scattered Spider playbook: help desk impersonation to reset MFA-linked accounts, followed by lateral movement via ngrok and Teleport, 77GB of data exfiltration, a blocked ransomware attempt, and an $8M extortion demand. The key takeaway for security teams is that phishing-resistant MFA alone cannot protect against social engineering of help desk staff — account recovery workflows must be treated as high-risk processes requiring strict verification.