A cybercrime case revealed how Microsoft records can link a Windows device identifier to online activity. Here’s what this means for your privacy and safety on Windows devices right now.
Table of Contents
What Happened?
According to PCMag, a newly unsealed cybercrime complaint showed how Microsoft records helped investigators link online activity to one Windows device. The case involves Peter Stokes, 19, who faces U.S. charges tied to the Scattered Spider hacking group.
The complaint says investigators used a Microsoft Global Device Identifier, or GDID, while examining a May 2025 attack on a luxury jewelry retailer. A GDID is a unique number tied to a Windows installation on a device that can stay the same across normal Windows updates.
The records showed that the same device identifier appeared alongside specific internet activity, websites, and timestamps. That matters because your online activity can leave more traces than you may realize. A VPN may hide your usual internet address, but other device signals can still create a longer digital trail.
This case did not involve a reported data breach affecting ordinary Windows users. Still, it shows how device, account, and activity records can be combined to create a detailed picture of someone’s online behavior.
Information leaked in other incidents can add even more personal details to that picture. Names, email addresses, passwords, and other data may help criminals target you with phishing, fraud, or impersonation attempts. Many people also do not realize their information was leaked until suspicious activity appears later.
If you are unsure whether your information was leaked, automatic monitoring can help you spot problems earlier. Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Was Affected and What Data Was Exposed?
The complaint does not describe a broad leak of Windows users’ data. The Microsoft records discussed in the case focused on one device tied to Peter Stokes. Those records linked the GDID to internet addresses and visits to certain webpages. The complaint does not say how many Windows users have similar records.
The luxury jewelry retailer was a separate victim in the cyberattack. The complaint says criminals stole at least 77 gigabytes of company data. However, the retailer’s name and the full list of affected people were not shared publicly.
How Microsoft Records Linked the Device to Online Activity
A Global Device ID, or GDID, is a unique number tied to a Windows installation. Microsoft uses it to recognize a device across certain services.
According to the criminal complaint, Microsoft connected the GDID to internet addresses, visits to third-party websites, and specific times. The identifier stays the same during normal Windows updates.
Reinstalling Windows creates a new GDID, although PCMag noted that Microsoft may still connect it to the old one through a Microsoft account or internet address. Microsoft has not publicly explained whether users can easily disable or remove the identifier.
Futureproof monitors your information for data leaks 24/7 and guides you with clear steps to keep it safer from scams.
Run a free checkWhat This Case Means for Your Windows Privacy
A VPN can hide your internet address from websites, but it does not remove identifiers created by your operating system. Prosecutors said Stokes used a VPN. Even so, investigators linked his online activity to his Windows installation through Microsoft records.
The source does not suggest that Microsoft routinely watches ordinary users. However, the case raises questions about what device information Microsoft stores, how long it keeps it, and when it may share those records.
The main privacy concern is that one device identifier may be connected to websites, internet addresses, account activity, and exact times.

3 Ways to Take More Control of Your Windows Privacy
These steps may reduce unnecessary data collection and help you better understand what Microsoft stores:
1. Review information in your Microsoft privacy dashboard
Go to account.microsoft.com/privacy and sign in with your Microsoft account. Open Activity history, then review categories such as browsing, search, location, and apps and services. Select a category to view the available records. Depending on the data type, you may be able to delete individual items, clear activity from a certain day, or remove the entire history.
Also review Ad settings and turn off personalized ads if you do not want Microsoft using your activity for tailored advertising. The dashboard only shows information linked to your Microsoft account and may not display every type of device data Microsoft stores.
2. Reduce optional Windows data sharing
On Windows 11, open Start > Settings > Privacy & security > Diagnostics & feedback. Review the diagnostic data choices and turn off optional sharing you do not need. You can also select Delete under Delete diagnostic data.
Next, open Privacy & security > General. Review settings for personalized ads, suggested content, and app launch tracking. Turning off the advertising ID limits its use for personalized ads. However, this setting does not appear to disable the Global Device ID discussed in the case.
3. Protect your Microsoft account and main email
Open your Microsoft account security page and review recent activity. Microsoft displays important sign-ins from the previous 30 days. Look for devices, locations, or changes you do not recognize. If something looks unfamiliar, select the option to secure your account.
Then turn on two-step verification. It requires a second check when you try to sign in from an unfamiliar device. Your email may also help recover your Microsoft account and many other services. Use a strong, unique password and protect it with two-step verification.
You Can Limit Windows Data Sharing, but Some Tracking Still Remains
The Microsoft Global Device ID is different from cookies or browser history, so clearing those records may not reset it.
Still, reviewing your Windows privacy settings can reduce optional data sharing and show what activity is linked to your account. Strong account security can also help prevent unauthorized access.
You may not control every identifier your computer creates, but you can limit tracking, review stored activity, and act quickly when something looks wrong. Futureproof can also help you find leaked information earlier and take clear steps to reduce your risk.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
