Forgot your password?
typodupeerror
Microsoft Government United States

How Microsoft's 'Little Workaround' Created a Major Threat to America's Defense Department (propublica.org) 34

This week Slashdot reader joshuark found the story of exactly how in 2025 ProPublica reporter Renee Dudley confirmed Microsoft was running tech support for the U.S. Defense Department through China, America's biggest cybersecurity adversary — and how that investigation ultimately changed U.S. government policy.

The reporter first found an ad offering $18 to $28 to hire Americans as "digital escorts" for China-based tech support, then just searched LinkedIn for people who apparently had answered the ad. They discovered that at the time "Behind the scenes, unseen by the users at the U.S. government, it's not just one person who responds," explains ProPublica's podcast. "It's two people... The China-based engineer is the one who knows how to fix the problem. On their end, they produce a block of code to solve it and send it over to the digital escort in the U.S. The digital escort then just copy-pastes it... All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data."

But amazingly to confirm it, ProPublica's researcher just had to input "Microsoft" and "escort" into the U.S. Patent Office search bar, and actually found patents related to digital escorts — along with names of the current and former Microsoft employees listed as inventors. Had the government signed off on the practice? "I could see what Microsoft actually told the government," the reporter says on the podcast, "And there was no mention of foreign engineers being used, and definitely no mention of China."

ProPublica's story was published on a Tuesday, according to the podcast, and by Friday "Microsoft said it had stopped using China-based engineers to support Defense Department cloud systems." And America's Defense Department "also opened up an investigation, looking into whether any of Microsoft's China-based engineers had compromised the government's national security.
This discussion has been archived. No new comments can be posted.

How Microsoft's 'Little Workaround' Created a Major Threat to America's Defense Department

Comments Filter:
  • by yanestra ( 526590 ) on Saturday July 18, 2026 @07:31PM (#66245556) Journal
    At Microsoft, you're not paid for situational awareness, quite the opposite, on no level. That's why nearly every single country in the world now reflects on the services of this company which became a security risk on many different levels. Nobody wants that, nobody can afford that.
  • New Heights (Score:5, Insightful)

    by RitchCraft ( 6454710 ) on Saturday July 18, 2026 @07:44PM (#66245574)

    This is a level of stupid that only Microsoft could pull off. Now, why has Microsoft not been charged with treason? Nadella is the definition of greedy bastard.

    • Nobody is that "stupid" in those departments.

      The question should be what was the quid pro quo?

      We can imagine what the PLA got out of it but what favor did Microsoft get?

      And how high up the chain did it go? Who specifically approved the arrangement?

      At least Microsoft probably has Windows 11 "backups" of the hard drives of anyone who might think of bringing charges.

      Not sure if that strategy can be called stupid. Lots of other words apply.

      "One Nation Under Blackmail" is a popular phrase.

    • Re: (Score:3, Informative)

      This is a level of stupid that only Microsoft could pull off. Now, why has Microsoft not been charged with treason? Nadella is the definition of greedy bastard.

      And if Trump was true to his own rantings, Nadella would be a "greedy bastard" with his head on a pike in the Oval Office.

      But Trump only cares about China as a comic book villain. He uses 'evil' countries to distract MAGA from America's true enemies: oligarchs, corporations, and anyone else with enough cash to bribe politicians, flout the law, and steer the government.

    • by gweihir ( 88907 )

      I think it is comparable to the level of stupidity that MS displayed when they started blocking accounts by judges and prosecutor it the International Court of Justice. They could not have made it any clearer that they are not a reliable service provider. Or when the gave the personal identification of Swedish Regulators to the US congress, without even trying to fight that order. Yes, I know the actual extreme stupidity happened here when MS did not oppose the law that created this requirement on them.

      Long

    • It's not treason unless you do it for the purpose of harming your country or aiding an adversary. This is "only" sharing confidential and potentially classified material out of scope, which is also serious but doesn't call for anyone to be hung by the neck until dead.

      • True, but I thought life in prison is a possibility. I worked defense early in my career. Annually you'd get a briefing about not being stupid as there are consequences. And I recall actual security. You know stuff in tempest rooms with no one allowed unless you have a clearance and machines connected to nothing else in that room. I hear these stories and really just think WTF. From the stupidity of hegs texting reporters with sensitive info to docs in people's closets to microsoft opening the door to Chine
    • by jmccue ( 834797 )
      This is when some high-level people at Microsoft should go directly to jail, do not pass go. If this does not happen, it proves once again the only reason to run for political office (both dem/gop) is to get in line for bribes^H^H^H^H^H^HCampaign Contributions.
  • by ffkom ( 3519199 ) on Saturday July 18, 2026 @07:44PM (#66245576)
    ... and given the price difference, the LLM services behind the tools may be hosted in China, just like those "cheaper IT workers" were. And the "digital escorts" will be as incapable of actually reviewing the code as the ones that "escorted" human IT workers from China. There just is not a trace of conscience in corporations that could prevent this from happening time and again.
  • by david.emery ( 127135 ) on Saturday July 18, 2026 @07:45PM (#66245578)

    That's the argument I heard when a defense contractor about why so many DoD systems specified Microsoft products, particularly Active Directory.

    Of course, "following industry standards" relieves one of the responsibility of actually thinking about what you're buying, including life-cycle costs and security & quality of the products. In that way, DoD was no different than all the other CIOs. Microsoft understood that CIOs were their real customer, and did everything to convince CIOs that Microsoft (regardless of cost) was 'the least risk alternative."

    • by jezwel ( 2451108 )
      While I agree with your premise, the second thing that was sold to CIOs is the lack of required integration between toolsets, as Microsoft products work together "seamlessly".
      For CIOs like ours that inherited a 'best of breed, now make them work together' system, they preferred to spend a little more $$$ on product licensing to save on integration spend - and the consequent headaches every time anyone decided to release a new version of their product...
      It's also easier to blame the one vendor you have rathe
  • by PPH ( 736903 ) on Saturday July 18, 2026 @07:47PM (#66245582)

    So, these people hired as digital escorts are vetted for security clearances, right? Because they will be handling "sensitive data". And as a part of receiving that clearance, they will be informed of their duties and responsibilities when handling said "sensitive data". Or no?

    All of this so that they can follow the government's rule: that you have to be a U.S. citizen or permanent resident to handle sensitive data.

    That's what we call a necessary condition. Not a sufficient condition.

    • by gweihir ( 88907 )

      I tried this out a while ago with my then-boss. We found that you need two (!) supervising engineers and they need to be significantly more competent that the one doing the work for this idea to actually deliver _and_ you need to slow down things massively. Say, one (!) command or line of code per hour or worse. He had no problems sneaking stuff past me, I had no problems sneaking stuff past him.

  • There's a difference between asking an overseas consultant "what buttons do I push to un-jam the purple gizmo?" and between "Enter these new users for me."

  • Sheesh, if I'm paying for an escort then getting her to cut&paste code for me is pretty much the last thing I'll be doing.
  • It's been a thing in China for a while.
  • Microsoft had a layoff in China in June. I imagine this "workaround' isn't a thing anymore.

    If they were working on opensource code, they could end up working on it upstream and still contributing.

  • They stopped using Chinese engineers for US Gov related matters.

    What about for other clients?

  • So if these jobs were granted to those overseas people, it can be argued that there was an oversight in vetting. But building a whole digital escort to circumvent laws is an intentional act. And given that it compromises national security, it must be treason. I don't get it, in the name of saving costs, someone actually knowingly does this? Do they hate their own country or something? Unless the person that created this program is him/herself chinese spy. But if that's the case, how did they get this done w

Evolution is a million line computer program falling into place by accident.

Working...