Court Filing Shows Microsoft Telemetry Helped FBI Identify Alleged Scattered Spider Member

Last updated: July 6, 2026 Reading time: 3 minutes
Disclosure
Share
Court Filing Shows Microsoft Telemetry Helped FBI Identify Alleged Scattered Spider Member
  • Newly unsealed court documents show Microsoft telemetry helped investigators identify an alleged Scattered Spider member.
  • The FBI combined Microsoft data with records from several technology providers to build its case.
  • Experts say the filing does not support claims that Microsoft tracks users’ complete online activity.

Newly unsealed U.S. court records have revealed that Microsoft device telemetry helped the FBI identify an alleged member of the Scattered Spider cybercrime group. The documents also show investigators relied on digital evidence from several technology companies instead of a single source.

According to a U.S. Department of Justice (DOJ) affidavit, investigators connected a Windows Global Device ID (GDID) to the creation of an ngrok account. Authorities believe attackers used that account during a May 2025 cyberattack against a luxury jewelry retailer.

The investigation led authorities to 19-year-old Peter Stokes. Prosecutors allege he belongs to the Scattered Spider hacking group. Finnish authorities arrested him before extraditing him to the United States to face federal charges.

Microsoft Telemetry Helped Investigators Trace Digital Activity

According to the affidavit, the Ngrok account was registered through a VPN address. That step prevented investigators from identifying the account owner through internet records alone.

Microsoft later determined that the same Windows Global Device ID accessed the ngrok registration page when the account was created. That discovery gave investigators an important lead despite the suspect’s use of a VPN.

The FBI expanded the investigation using records from several technology providers. Authorities also collected information from internet service providers, Apple, Google Voice, Snapchat, Facebook, cryptocurrency transactions, and the VPN provider.

Investigators combined subscriber records, account details, IP history, and search warrants to connect multiple online identities. Together, those records strengthened the government’s case against the suspect.

The DOJ alleges attackers used the ngrok account during an intrusion targeting a luxury jewelry retailer in May 2025. Prosecutors say the group stole sensitive company information before demanding an $8 million ransom.

Authorities estimate the retailer suffered more than $2 million in losses from the attack.

Social Media Claims Over Microsoft Telemetry Face Scrutiny

The newly unsealed filing quickly sparked discussions across X and other social media platforms. Many users claimed Microsoft’s Windows telemetry allowed investigators to monitor complete browsing histories, gaming sessions, and social media activity.

However, the affidavit makes no such claim. Instead, the court filing shows Microsoft telemetry served as only one investigative element. The Windows Global Device ID linked a device to activity surrounding the ngrok account. Investigators still depended on independent evidence from several companies before identifying the suspect.

Cybersecurity researchers have also urged people not to misinterpret the court documents. They note the filing describes a coordinated investigation rather than unrestricted surveillance through Windows telemetry.

Case Renews Debate over Device Telemetry and Digital Investigations

The disclosure has renewed discussions about the diagnostic information modern operating systems collect. Privacy advocates continue questioning how authorities may use that information during criminal investigations.

The privacy debate extends to how companies handle user data. Texas has filed a lawsuit against Meta and WhatsApp over alleged misleading privacy claims.

At the same time, the case highlights how investigators increasingly combine digital evidence from multiple platforms. Modern cybercrime investigations rarely depend on records from one provider alone.

Scattered Spider remains one of the world’s most closely watched cybercrime groups. Security researchers have linked its members to high-profile ransomware attacks and sophisticated social engineering campaigns against major organizations.

The newly released court records also demonstrate the growing value of forensic evidence. Attackers may hide behind VPNs and anonymous services, but investigators can still reconstruct digital activity by combining independent records from multiple providers.

The case also offers an important clarification. Microsoft telemetry did not provide investigators with a complete record of the suspect’s online activity. Instead, it supplied one investigative lead that authorities verified using evidence gathered from numerous technology companies throughout the investigation.

Share this article

About the Author

Rebecca James is an IT consultant with forward thinking approach toward developing IT infrastructures of SMEs. She writes to engage with individuals and raise awareness of digital security, privacy, and better IT infrastructure.

More from Rebecca James

Related Posts