---
title: "Windows Device ID in Hacking Case Raises Questions About Enterprise Telemetry"
url: https://daily.dev/posts/windows-device-id-in-hacking-case-raises-questions-about-enterprise-telemetry-599kucv0b
source_url: https://securityboulevard.com/2026/07/windows-device-id-in-hacking-case-raises-questions-about-enterprise-telemetry
type: article
source: "Security Boulevard"
published: 2026-07-08T22:44:07.547Z
updated: 2026-07-08T22:44:30.897Z
tags: ["security"]
reading_time: 4
upvotes: 0
comments: 0
language: en
---

> ## Documentation Index
> Fetch the complete documentation index at: https://daily.dev/llms.txt
> Use this file to discover all available pages before exploring further.

# Windows Device ID in Hacking Case Raises Questions About Enterprise Telemetry

**[Security Boulevard](https://daily.dev/sources/securityboulevard)** · 4 min read · 0 upvotes · 0 comments

## Summary

A federal case against an alleged Scattered Spider member reveals how a Microsoft Global Device Identifier (GDID) helped FBI investigators link a Windows installation to a 2025 breach at a luxury jewelry retailer. The persistent identifier was tied to an ngrok account signup and correlated with IP addresses, online accounts, and travel data — demonstrating how endpoint telemetry can serve as a forensic anchor even when suspects use VPNs and aliases. The case raises governance questions for enterprises about what Windows telemetry collects and what can be disabled. The breach itself followed the classic Scattered Spider playbook: help desk impersonation to reset MFA-linked accounts, followed by lateral movement via ngrok and Teleport, 77GB of data exfiltration, a blocked ransomware attempt, and an $8M extortion demand. The key takeaway for security teams is that phishing-resistant MFA alone cannot protect against social engineering of help desk staff — account recovery workflows must be treated as high-risk processes requiring strict verification.

## Full article

daily.dev links to this article rather than hosting it. Read it at the original source: <https://securityboulevard.com/2026/07/windows-device-id-in-hacking-case-raises-questions-about-enterprise-telemetry>

## Similar posts on daily.dev

- [Microsoft Confirms Windows GDID Device Identifier That Cannot Be Disabled, Documented in FBI Case Filing](https://daily.dev/posts/microsoft-confirms-windows-gdid-device-identifier-that-cannot-be-disabled-documented-in-fbi-case-fi-41de1nn3d) · Hacker News · 0 upvotes · 0 comments
- [Windows is watching: Anti-piracy tool fingers Scattered Spider suspect](https://daily.dev/posts/windows-is-watching-anti-piracy-tool-fingers-scattered-spider-suspect-llvutwvx7) · The Register · 0 upvotes · 0 comments

---

Tags: [#security](https://daily.dev/tags/security)

[View this post on daily.dev](https://daily.dev/posts/windows-device-id-in-hacking-case-raises-questions-about-enterprise-telemetry-599kucv0b)
