A leading U.S. senator has called on the Federal Trade Commission (FTC) to investigate Microsoft for “gross cybersecurity negligence” that has enabled ransomware attacks against critical U.S. infrastructure.
Sen. Ron Wyden (D-Ore.), the ranking member of the Senate Finance Committee, wrote a letter to FTC chair Andrew Ferguson detailing how Microsoft's default software configurations have created vulnerabilities that threat actors have exploited to launch devastating ransomware attacks.
The lawmaker specifically cited the 2024 breach of Ascension, one of the nation's largest non-profit health care systems, as a prime example of the consequences of Microsoft's security practices. The St. Louis-based provider suffered a breach after a hacker exploited a vulnerability to gain access to a contractor’s system. The vulnerability was exploited when that contractor clicked on a malicious search result in Microsoft's Bing search engine, with the resulting breach disclosing the data of some 437,000 patients.
According to intelligence reports cited by Wyden, ransomware attacks surged to more than 5,000 incidents in 2024 – a 15% increase from the previous year and a staggering 103% jump from 2022.
"Microsoft has utterly failed to stop or even slow down the scourge of ransomware enabled by its dangerous software,” Wyden wrote in his letter, and then called on the FTC to probe the company’s “negligence in a marketplace where its dominance has profound, foundational influence on cybersecurity practices and to hold the company accountable for its shortcomings.”
Wyden claims his staff urged Microsoft officials in July 2024 to warn customers about the breach, but the company took three months to respond. In October 2024, Microsoft published a blog post with recommendations and announced plans for a security update to disable RC4 encryption. However, 11 months later, that promised update has yet to be released.
Wyden criticized Microsoft's response as inadequate, noting that instead of clear guidance for senior executives, the company “published a highly technical blog post on an obscure area of the company's website on a Friday afternoon” with no meaningful publicity efforts.
Wyden also accused the tech giant of profiting from the very problems it creates. Instead of delivering secure software, the company has built what Wyden calls “a multibillion-dollar secondary business selling cybersecurity add-on services to those organizations that can afford it.”
Wyden likened Microsoft to an “arsonist selling firefighting services to their victims.”
The letter continues: “And yet government agencies, companies, and nonprofits like Ascension have no choice but to continue to use the company’s software, even after they are hacked, because of Microsoft’s near-monopoly over enterprise IT.”
“I urge the FTC to investigate Microsoft and hold the company responsible for the serious harm it has caused by delivering dangerous, insecure software to the U.S. government and to critical infrastructure entities, such as those in the U.S. health care sector,” Wyden wrote. “Without timely action, Microsoft’s culture of negligent cybersecurity, combined with its de facto monopolization of the enterprise operating system market, poses a serious national security threat and makes additional hacks inevitable.”
Comments