/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

← → days · ↑ ↓ browse · Enter similar · o open

How Microsoft's 10-year-old Digital Crime Unit uses unique legal tactics and the company's technical reach to disrupt global cybercrime and state-backed actors

Ten years in, Microsoft's DCU has honed its strategy of using both unique legal tactics and the company's technical reach …

Wired Lily Hay Newman

Context & Ripple Effects

Microsoft's security operations had already paired company resources with public enforcement: its assistance in disrupting the Dorkbot botnet showed how technical evidence could support action against criminal infrastructure. Its threat-intelligence organization was also tracking a broad set of state-sponsored groups, expanding the pool of activity that could be investigated and attributed.

The DCU's decade-long model matters because it makes disruption—not only detection or customer alerts—a core use of a platform company's security reach. Later coverage of the unit using AI to connect two hacking tools in one civil action illustrates how that legal-and-technical playbook can be extended.

First-order effects

  • Microsoft can turn intelligence gathered through its technical footprint into legal and operational actions aimed at cybercriminal infrastructure and state-backed activity.
  • Attackers targeted by DCU actions face a more immediate risk that domains, services, or other enabling infrastructure will be challenged rather than merely identified.

Second-order effects

  • Law-enforcement and infrastructure partners gain a private-sector counterpart that can supply technical attribution and pursue remedies through its own legal channels.
  • Other large technology providers face pressure to treat abuse disruption as an operational security function, not solely a matter for government agencies or affected customers.

Third-order effects

  • If this model continues to scale, cyber defense may become more ecosystem-led: platform owners will increasingly combine telemetry, legal process, and cross-border coordination to contest malicious infrastructure.
  • That shift also concentrates influence over disruption decisions in a small number of firms, likely increasing scrutiny of how private evidence, legal tools, and public authorities are coordinated.

The trend: Cybersecurity is shifting from detecting threats inside individual networks toward platform-scale disruption that combines technical intelligence with legal action.

Discussion

  • @carlypage_ Carly Page on x
    Microsoft has disrupted Storm-1152, a cybercrime operation that sold fraudulent accounts to other groups, including Scattered Spider. It says Storm-1152's services have been used “to injure not just Microsoft” but also “X, Google and their customers” https://techcrunch.com/...
  • @sixdub Justin on x
    The Digital Crimes Unit (DCU)of Microsoft (w/Arkose Labs) has taken legal action against the individuals behind Storm-1152, the number one creator and seller of fraudulent Microsoft accounts. To date, Storm-1152 has created for sale ~750 million accts. https://blogs.microsoft.com…
  • @itsreallynick Nick Carr on x
    Watching the drastic impacts in real-time as the servers came down 🤌 Read more: https://blogs.microsoft.com/ ... [image]
  • @msftsecintel @msftsecintel on x
    Fraudulent online accounts act as the gateway to cybercrime, incl. phishing, identity theft & fraud, DDoS. Microsoft, w/ insights from Arkose Labs, is going after the number one seller & creator of fraudulent Microsoft accounts, a group we call Storm-1152: https://blogs.microsoft…