financetom
Business
financetom
/
Business
/
US Senator Wyden pushes FTC to investigate Microsoft for 'gross cybersecurity negligence'
News World Market Environment Technology Personal Finance Politics Retail Business Economy Cryptocurrency Forex Stocks Market Commodities
US Senator Wyden pushes FTC to investigate Microsoft for 'gross cybersecurity negligence'
Sep 10, 2025 11:42 AM

*

Senator's letter to FTC chairman cites ransomware attacks

against infrastructure, health care organizations

*

Senator compares Microsoft ( MSFT ) to 'arsonist selling

firefighting

services to their victims'

*

Ransomeware attack on hospital operator exposed data of

more

than 5 million people, Senator says

By AJ Vicens

Sept 10 (Reuters) - U.S. Democratic Senator Ron Wyden on

Wednesday requested the Federal Trade Commission "investigate

and hold Microsoft ( MSFT ) responsible" for its role in a string of

high-profile cybersecurity incidents in recent years, saying the

company's approach to security "continues to threaten U.S.

national security."

Wyden wrote in a September 10 letter to FTC Chairman Andrew

Ferguson that the tech giant's "gross cybersecurity negligence"

has resulted in ransomware attacks against critical

infrastructure, including U.S. health care organizations at

least in part due to default configurations in the Windows

operating system.

"At this point, Microsoft ( MSFT ) has become like an arsonist

selling firefighting services to their victims," Wyden wrote,

and government agencies and other companies have "no choice" but

to use the company's products due to its "near-monopoly over

enterprise IT."

An FTC spokesperson acknowledged that the agency had

received the letter but declined to comment further.

Widen said a prime example was the May 2024 ransomware attack on

hospital operator Ascension, which according to the company

exposed private medical and insurance data of nearly 5.6 million

people.

Wyden wrote that the hospital operator told his staff that a

contractor using an Ascension laptop clicked on a malicious link

served up by Microsoft's ( MSFT ) Bing search engine, which then allowed

the hackers to gain access to the company's network and

ultimately the organization's Microsoft Active Directory server,

which is used to manage user accounts.

Microsoft's ( MSFT ) support for outdated encryption technology and

default configuration settings set up by Microsoft ( MSFT ) allowed for

the attack approach in the Ascension case, according to Wyden,

and Microsoft ( MSFT ) has not done enough to educate companies about how

to mitigate the threat.

A Microsoft ( MSFT ) spokesperson said Wednesday that RC4, the

encryption standard referenced by Wyden, is old and makes up

"less than .1% of our traffic," and that the company discourages

customers from using it.

"However, disabling its use completely would break many

customer systems," the spokesperson said, and the company is

gradually reducing the extent to which customers can use it

while trying to provide warnings and guidance on the safest way

to use it.

RC4 will be disabled by default in certain Windows products

starting the first quarter of 2026, and the company will include

"additional mitigations" for existing deployments, the

spokesperson said.

Wyden has previously pushed for U.S. government investigation

and review of Microsoft's ( MSFT ) role in cyberattacks, including after

revelations in July 2023 that Chinese-linked hackers stole

thousands of U.S. officials' emails.

(Reporting by AJ Vicens in Detroit. Editing by David Gregorio )

Comments
Welcome to financetom comments! Please keep conversations courteous and on-topic. To fosterproductive and respectful conversations, you may see comments from our Community Managers.
Sign up to post
Sort by
Show More Comments
Related Articles >
Tata Power Renewable Energy wins 200-MW project in collaboration with SJVN
Tata Power Renewable Energy wins 200-MW project in collaboration with SJVN
Nov 28, 2023
The firm and dispatchable renewable energy (FDRE) project, designed with a hybrid of solar, wind, and battery storage, is aimed at providing a stable and dispatchable energy supply during peak hours. Shares of Tata Power Company Ltd ended at ₹270.75, up by ₹12.60, or 4.88%, on the BSE.
SJVN secures 200-MW wind power project at ₹3.24 per unit
SJVN secures 200-MW wind power project at ₹3.24 per unit
Nov 16, 2023
Projected to generate 482 million units in its inaugural year post-commissioning, the cumulative energy generation over a 25-year span is anticipated to reach 12,050 million units. Shares of SJVN Ltd ended at ₹75.17, down by ₹0.50, or 0.66%, on the BSE.
This sustainable jewellery brand is luring some women away from gold
This sustainable jewellery brand is luring some women away from gold
Oct 30, 2023
Aulerth's offerings range from ₹5,000 to as high as ₹2.8 lakh. Are women willing to spend this much on jewellery made from scrap? Founder and CEO Vivek Ramabhadran definitely believes so. Aulerth produces couture-inspired pieces in association with designers like JJ Valaya, Suneet Varma, among others. It has reported 33% repeat customers in the past year and expects a spike to 40% soon.
Suzlon's S144–3 MW wind turbines get big boost from Indian government
Suzlon's S144–3 MW wind turbines get big boost from Indian government
Nov 15, 2023
Th Suzlon wind turbines received the RLMM (Revised List of Models & Manufacturers) listing from the Ministry of New and Renewable Energy, marking an important milestone for the successful commercialisation of the product. Shares of Suzlon Energy Ltd ended at ₹40.49, up by ₹1.85, or 4.79%, on the BSE.
Copyright 2023-2026 - www.financetom.com All Rights Reserved