Microsoft Just Confirmed the Tracking Number Hiding in Every Windows PC
A hacking case just outed the tracking number Microsoft never told you existed
A few weeks ago, federal prosecutors in Chicago unsealed a complaint against a 19 year old accused of helping run part of the Scattered Spider hacking group. Buried in that filing is a detail that reaches well beyond this one case, and it affects anyone who owns a computer running Microsoft Windows.
To catch the 19-year-old, Microsoft handed the FBI a tracking number attached to his Windows computer. This unique ID followed him through VPNs, proxy servers, and stops in four countries.
It’s called a Global Device Identifier, or GDID. Before this case, the ID was effectively unknown, buried in an enterprise IT reference page that nobody had really noticed or understood.
What the Complaint Showed
Peter Stokes, who allegedly went by “Bouquet” online, is accused of helping break into a jewelry retailer in May 2025. Stokes called the company’s IT help desk and posed as a locked out employee. Once inside, the group installed tunneling software, pulled 77 gigabytes of data, and sent a ransom note demanding $8 million. The retailer opted not to pay.
What matters for anyone running a Windows computer is how investigators worked backward to Stokes. Microsoft’s records showed the GDID g:6755467234350028 hitting the signup page for a tunneling tool at the exact minute an account tied to the attack was created. Three hours later, the same ID showed up on the jewelry retailer’s site, through the same VPN proxy. From there, Microsoft matched that device’s activity to Snapchat, Facebook, and Apple accounts prosecutors say belong to Stokes, across Estonia, New York, and Thailand. That allowed federal investigators to connect Stokes to the crime.
The Windows GDID gets generated the moment you set up Windows with a Microsoft Account. It sits in your registry, survives every Windows update, and reports back to Microsoft through ordinary background traffic. Reinstall Windows clean and you get a new GDID, but sign back into the same Microsoft Account and Microsoft has an easy path to tie the new one to the old one anyway.
Microsoft’s own description of GDID, quoted in the complaint, is vague. It calls GDID an identifier that uniquely identifies a Windows installation “across certain Microsoft services and scenarios.” There’s no mention of advertising, but no pre-emptive denial either.
That’s to be expected, to be honest, because Windows already has a separate identifier built specifically for advertising, called the Advertising ID. It sits under Settings and Privacy. Unlike GDID, though, you can reset that one or turn it off entirely (which I recommend you do).
AI scams are here and getting more sophisticated. One of the best things you can do to protect yourself is to remove your personal information from Google and the data broker sites. That starves the scammers of vital information, making you a harder target. You can DIY, or pay a reasonable fee to a provider like DeleteMe to do it for you. Sign up today and get 20% off using our affiliate link here. We’ve used DeleteMe for five+ years and love it for the peace of mind. It’s also a huge time saver and an instant privacy win.
Microsoft Has a Record of the Exact Pages You Visited
Per the complaint, Microsoft didn’t just note that Stokes’s PC connected to ngrok’s website at some point. It had a record of the exact signup page he visited at the exact minute tied to his GDID. Three hours later, the same GDID shows up again for the retailer’s website. That means Microsoft was recording his browsing history, and permanently linking it to his machine via the GDID.
Independent researchers who’ve picked apart the complaint point to Windows Defender SmartScreen and Microsoft Edge as the likely source. When a Windows PC has its diagnostic data setting turned up to “enhanced” or “optional” instead of “basic,” both features send the URLs you visit back to Microsoft, tagged with your GDID. The purported purpose is to check pages and downloads for malware. Microsoft hasn’t confirmed that’s exactly what happened on Stokes’s PC, but several independent technical breakdowns of the complaint point to that explanation.
Some of you are probably questioning whether an alleged hacker would use Microsoft Edge. The browser has basically no market share, so it’s unlikely that Stokes used it, at least intentionally.
It turns out he didn’t need to use Edge for that browsing record to exist. Windows has a documented habit of forcing certain links open in Edge no matter which browser you’ve set as your default. That includes anything typed into the taskbar search box, widgets, the Start menu, Copilot, and links inside Outlook, Teams, News, and Weather. Those all route through a special microsoft-edge:// address that, as of recent Windows builds, cannot be redirected to another browser at all.
So someone can run Chrome or Brave for everything they do on purpose and still generate Edge-routed, SmartScreen-tagged traffic just by searching something from the taskbar or clicking a widget. Edge is never officially opened by the user. Windows may have just routed Stokes’s browsing there quietly in the background, the way it does for a lot of people who think they’ve never touched Edge at all.
None of that Edge back-and-forth actually matters for the bigger picture though:
The GDID reports back to Microsoft through Windows Update, the Microsoft Store, and Delivery Optimization, none of which care what browser you have installed.
That’s actually how most of the Stokes case got built anyway. The ngrok signup page was one data point. The bulk of the tracing came from matching his GDID’s timing and IP address against logins on his personal Snapchat, Facebook, and Apple accounts, separate from the browser he used. It just took using the same Windows machine for everything, which is what most people do without thinking twice about it.
A commenter on gHacks’s coverage claimed there’s a second, hardware level identifier that survives a full wipe and shows up even if you’ve never touched a Microsoft Account. I haven’t found that confirmed anywhere in the actual reporting or in the complaint, so treat it as an open question for now, not a fact. It’s the kind of detail other reporters will probably chase down as this story gets picked apart further.
Why Nobody Caught This Sooner
GDID was under the radar because it never had a public name. Compare that to the iPhone’s ad identifier (IDFA). Apple’s version had a name, years of critics, and plenty of bad press before Apple added a consent screen for it in 2021. Something with a name gets attention. GDID was an unknown until this complaint made it public.
If GDID ever gets tested under a privacy law like GDPR, my guess is it runs into the same consent problems regulators have already raised about hidden identifiers elsewhere. Nobody’s tested it yet, because almost nobody knew to ask. More to come on this I’m sure.
How Could the GDID Be Used Against You?
The Stokes situation involves the FBI going straight to Microsoft. They had the federal legal process on their side.
That matters because the law that let them do it, the Stored Communications Act, draws a hard line between government agencies and everyone else. Government entities have real ways to compel a provider like Microsoft to hand over records. Private citizens and companies suing each other don’t have that option. Courts have repeatedly quashed ordinary civil subpoenas seeking this kind of data from providers, so the pool of who else could use this is limited. It’s really only other government agencies, not divorce lawyers or corporate litigation teams. Still there are some scenarios to be aware of.
State tax residency audits are the clearest example. High earners who claim they moved from a state like New York or California to a no income tax state like Florida or Texas already get audited using exactly this kind of digital trail, credit card charges, cell tower pings, EZ Pass records, social media check-ins, anything that shows where someone actually was on a given day. A permanent device log tied to specific timestamps and IP addresses is a cleaner, more precise version of the same evidence. A state revenue department, as a government agency, should have the same legal standing to go after it that the FBI had with Stokes.
Immigration proceedings are another fit. USCIS and ICE already build cases around continuous physical presence for naturalization, and around marriage fraud in green card petitions, using travel records, credit card charges, and social media to establish where someone actually was and when. A device log tied to specific timestamps and locations is a sharper version of evidence immigration authorities already subpoena routinely in these cases. Immigration enforcement is squarely a government function with the same standing as the FBI’s.
Securities regulators are the example that mirrors the original case most closely. What actually caught Stokes wasn’t a location log by itself, it was proving that one device sat behind supposedly separate identities, his hacking activity and his personal social media, at the same times and places. An SEC investigation into insider trading or market manipulation runs on similar logic: proving an anonymous or offshore trading account was operated from the same machine as someone’s known identity. That’s a government agency doing the identical cross-referencing the FBI did, aimed at a trader instead of a hacker.
Should You Just Leave Windows?
One of the top questions I get these days is whether a reader should ditch Windows, so this case is good timing. Unfortunately, your options are limited and come with real tradeoffs.
Macs are not the clean escape people assume. Every Mac has a Hardware UUID baked into the logic board. That ID is permanent and survives a wipe. There’s also a separate identifier called a DSID, tied to your Apple ID, that links the machine to your account across iCloud and everything else Apple runs. That identifier works the same way GDID does. It’s tied to your account, not your network connection, so switching VPNs wouldn’t have hidden it any better than it hid Stokes.
Nobody’s used an Apple ID to build a case like this one (at least that we’re aware of), but the risk works the same way. I haven’t found anything showing Apple logs the specific pages you visit against that identifier, the way this complaint shows for Windows, so the exposure may be smaller right now.
Linux is the one option where none of this applies, since there’s no vendor account sitting underneath the operating system for an identifier to attach to. I wrote a full breakdown of when that move actually makes sense back in December, including where Windows 10’s end of support fits into the decision and why Recall was already a warning sign before any of this GDID business surfaced. If you’re open to looking at a computer running Linux, this is the place to start:
What You Can Actually Do Right Now
If you’re staying on Windows for now, at minimum set it up with a local account instead of a Microsoft Account. Microsoft has made this deliberately annoying to find. This does require starting with a fresh install of Windows, so it’s not a painless process.
During setup on a new or freshly reinstalled machine, you’ll hit a screen asking you to connect to Wi-Fi before you can continue, that’s the moment to act. Press Shift and F10 together to open a command prompt, type OOBE\BYPASSNRO, hit enter, and setup restarts with an option to continue without internet and create a local account instead.
Microsoft has been closing this specific loophole in newer Windows builds. So if the command stops working on your machine, search online for the current method rather than assuming Microsoft finally removed the option for creating a local account. People keep finding new ways around it, which will assume is the case until further notice.
Looking for help with a privacy issue or privacy concern? Chances are we’ve covered it already or will soon. Follow us on X and LinkedIn for updates on this topic and other internet privacy related topics.
Disclaimer: None of the above is to be deemed legal advice of any kind. These are *opinions* written by a privacy and tech attorney with years of working for, with and against Big Tech and Big Data. And this post is for informational purposes only and is not intended for use in furtherance of any unlawful activity. This post may also contain affiliate links, which means that at no additional cost to you, we earn a commission if you click through and make a purchase.
Know your doxxing risk. DoxxScore gives you a personalized exposure assessment and action plan in under 5 minutes. Get Your Risk Score →
Check out our new, free username generator to help you create unique usernames for different accounts. Reusing usernames is convenient, but terrible for your privacy. This tool makes it easy to create unique usernames on the fly.



Wasnt Intel processors supposed to have a back door? Seem to remember something about that many years ago. 'intel inside'