U.S. Senator Accuses Microsoft of “Gross Cybersecurity Negligence”
Senator Wyden highlights Microsoft's outdated encryption and default settings as key factors enabling ransomware attacks that exposed data of 5.6 million patients, urging FTC action.
- On September 10, 2024, Senator Ron Wyden called on the FTC to investigate Microsoft for cybersecurity negligence linked to ransomware attacks on U.S. health care organizations.
- This call was prompted by a ransomware incident in May 2024 targeting Ascension Health, where attackers exploited default Microsoft configurations and a vulnerable RC4 encryption method through a Kerberoasting technique.
- The attack involved a contractor clicking a malicious Bing link in Microsoft Edge, which infected a laptop, spread through Ascension's network, and led to exposure of private data from 5.6 million patients.
- Wyden criticized Microsoft, suggesting the company is contributing to cybersecurity problems while profiting from solutions, whereas Microsoft responded that although RC4 accounts for less than 0.1% of traffic, completely disabling it would disrupt many systems.
- Wyden warned that without FTC intervention, more high-impact cyber incidents will occur due to Microsoft's default configurations, which continue to leave customers vulnerable despite plans to disable RC4 by 2026.
15 Articles
15 Articles
U.S. Senator accuses Microsoft of “gross cybersecurity negligence”
U.S. Senator Ron Wyden has sent a letter to the Federal Trade Commission (FTC) requesting the agency to investigate Microsoft for failing to provide adequate security in its products, which led to ransomware attacks against healthcare organizations. [...]
US Senator urges probing Microsoft over cybersecurity negligence, ransomware risks
Senator Ron Wyden urged the Federal Trade Commission to investigate Microsoft for “gross cybersecurity negligence,” citing ransomware attacks, outdated encryption, and monopoly concerns, highlighting the 2024 Ascension hospital breach that exposed data of 5.6 million people.
Wyden calls on FTC to investigate Microsoft for ‘gross cybersecurity negligence’ in protecting critical infrastructure
Sen. Ron Wyden, D-Ore., on Wednesday called for the Federal Trade Commission to investigate Microsoft, saying the company’s default configurations are leaving customers vulnerable and contributing to ransomware, hacking and other threats. That includes the 2024 Ascension hospital ransomware attack, which resulted in the theft of personal data, medical data, payment information, insurance information and government IDs for more than 5.6 million p…
Coverage Details
Bias Distribution
- 50% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium










