Microsoft can track users using Windows device ID, report says
A federal investigation that led to the arrest of a 28‑year‑old hacker on charges of unauthorized access to corporate networks has also uncovered evidence that Microsoft’s Windows operating system can be used to monitor individual users’ activity. According to court documents released by the U.S. Attorney’s Office, the suspect, identified only by initials, exploited a vulnerability in a popular remote‑access tool to infiltrate several companies. During the probe, investigators recovered logs showing that the malware was capable of retrieving a device’s unique hardware identifier, IP address, and location data, which could then be correlated with Microsoft’s telemetry services. The findings suggest that, beyond its stated diagnostic purposes, the Windows platform can aggregate enough information to track a user’s movements across different networks and devices.
Microsoft responded to the revelations by emphasizing that data collection is governed by its privacy policy and is intended for security, performance optimization, and feature improvement. The company noted that users retain control over telemetry settings and that any location‑based data is anonymized unless a user explicitly enables location services. Privacy advocates, however, have called for greater transparency and stricter oversight of such capabilities. The case highlights ongoing tensions between cybersecurity enforcement, corporate data practices, and user privacy, underscoring the need for clearer guidelines on how operating‑system telemetry can be accessed and utilized.