{"id":11050,"date":"2025-07-16T08:52:33","date_gmt":"2025-07-16T08:52:33","guid":{"rendered":"https:\/\/naijaglobalnews.org\/?p=11050"},"modified":"2025-07-16T08:52:33","modified_gmt":"2025-07-16T08:52:33","slug":"microsoft-digital-escorts-could-expose-defense-dept-data-to-chinese-hackers-propublica","status":"publish","type":"post","link":"https:\/\/naijaglobalnews.org\/?p=11050","title":{"rendered":"Microsoft \u201cDigital Escorts\u201d Could Expose Defense Dept. Data to Chinese Hackers \u2014 ProPublica"},"content":{"rendered":"<p>\n<\/p>\n<p>ProPublica is a nonprofit newsroom that investigates abuses of power. Sign up to receive our biggest stories as soon as they\u2019re published.<\/p>\n<h3 class=\"highlights__heading\">Reporting Highlights<\/h3>\n<ul class=\"highlights__list\">\n<li class=\"highlights__highlight\"><span class=\"highlights__subheading\">Chinese Tech Support: <\/span> Microsoft is using engineers in China to help maintain the Defense Department\u2019s computer systems \u2014 with minimal supervision by U.S. personnel.<\/li>\n<li class=\"highlights__highlight\"><span class=\"highlights__subheading\">Skills Gap: <\/span> Digital escorts often lack the technical expertise to police foreign engineers with far more advanced skills, leaving highly sensitive data vulnerable to hacking.<\/li>\n<li class=\"highlights__highlight\"><span class=\"highlights__subheading\">Ignored Warnings: <\/span> Various people involved in the work told ProPublica that they warned Microsoft that the arrangement is inherently risky, but the company launched and expanded it anyway.<\/li>\n<\/ul>\n<p class=\"highlights__disclaimer\">\n        These highlights were written by the reporters and editors who worked on this story. <span id=\"survey-placeholder\"\/>\n    <\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"2.0\">Microsoft is using engineers in China to help maintain the Defense Department\u2019s computer systems \u2014 with minimal supervision by U.S. personnel \u2014 leaving some of the nation\u2019s most sensitive data vulnerable to hacking from its leading cyber adversary, a ProPublica investigation has found.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"3.0\">The arrangement, which was critical to Microsoft winning the federal government\u2019s cloud computing business a decade ago, relies on U.S. citizens with security clearances to oversee the work and serve as a barrier against espionage and sabotage.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"4.0\">But these workers, known as \u201cdigital escorts,\u201d often lack the technical expertise to police foreign engineers with far more advanced skills, ProPublica found. Some are former military personnel with little coding experience who are paid barely more than minimum wage for the work.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"5.0\">\u201cWe\u2019re trusting that what they\u2019re doing isn\u2019t malicious, but we really can\u2019t tell,\u201d said one current escort who agreed to speak on condition of anonymity, fearing professional repercussions. <\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"5.1\">The system has been in place for nearly a decade, though its existence is being reported publicly here for the first time.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"6.0\">Microsoft told ProPublica that it has disclosed details about the escort model to the federal government. But former government officials said in interviews that they had never heard of digital escorts. The program appears to be so low-profile that even the Defense Department\u2019s IT agency had difficulty finding someone familiar with it. \u201cLiterally no one seems to know anything about this, so I don\u2019t know where to go from here,\u201d said Deven King, spokesperson for the Defense Information Systems Agency.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"7.0\">National security and cybersecurity experts contacted by ProPublica were also surprised to learn that such an arrangement was in place, especially at a time when the U.S. intelligence community and leading members of Congress and the Trump administration view China\u2019s digital prowess as a top threat to the country.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"8.0\">The Office of the Director of National Intelligence has called China the \u201cmost active and persistent cyber threat to U.S. Government, private-sector, and critical infrastructure networks.\u201d One of the most prominent examples of that threat came in 2023, when Chinese hackers infiltrated the cloud-based mailboxes of senior U.S. government officials, stealing data and emails from the commerce secretary, the U.S. ambassador to China and others working on national security matters. The intruders downloaded about 60,000 emails from the State Department alone.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"10.0\">With President Donald Trump and his allies concerned about spying, the State Department announced plans in May to \u201caggressively revoke visas for Chinese students\u201d \u2014 a pledge that the president seems to have walked back. The administration is also trying to arrange the sale of the popular social media platform TikTok, which is owned by a Chinese company that some lawmakers believe could hand over sensitive U.S. user data to Beijing and fuel misinformation with its content recommendations. But experts told ProPublica that digital escorting poses a far greater threat to national security than either of those issues and is a natural opportunity for spies.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"11.0\">\u201cIf I were an operative, I would look at that as an avenue for extremely valuable access. We need to be very concerned about that,\u201d said Harry Coker, who was a senior executive at the CIA and the National Security Agency. Coker, who also was national cyber director during the Biden administration, added that he and his former intelligence community colleagues \u201cwould love to have had access like that.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"12.0\">It is difficult to know whether engineers overseen by digital escorts have ever carried out a cyberattack against the U.S. government. But Coker wondered whether it \u201ccould be part of an explanation for a lot of the challenges we have faced over the years.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"13.0\">Microsoft uses the escort system to handle the government\u2019s most sensitive information that falls below \u201cclassified.\u201d According to the government, this \u201chigh impact level\u201d category includes \u201cdata that involves the protection of life and financial ruin.\u201d The \u201closs of confidentiality, integrity, or availability\u201d of this information \u201ccould be expected to have a severe or catastrophic adverse effect\u201d on operations, assets and individuals, the government has said. In the Defense Department, the data is categorized as \u201cImpact Level\u201d 4 and 5 and includes materials that directly support military operations.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"14.0\">John Sherman, who was chief information officer for the Department of Defense during the Biden administration, said he was surprised and concerned to learn of ProPublica\u2019s findings. \u201cI probably should have known about this,\u201d he said. He told the news organization that the situation warrants a \u201cthorough review by DISA, Cyber Command and other stakeholders that are involved in this.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"15.0\">In an emailed statement, the Defense Information Systems Agency said that cloud service providers \u201care required to establish and maintain controls for vetting and using qualified specialists,\u201d but the agency did not respond to ProPublica\u2019s questions regarding the digital escorts\u2019 qualifications.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"16.0\">It\u2019s unclear whether other cloud providers to the federal government use digital escorts as part of their tech support. Amazon Web Services and Google Cloud declined to comment on the record for this article. Oracle did not respond to requests for comment.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"17.0\">Microsoft declined to make executives available for interviews for this article. In response to emailed questions, the company provided a statement saying its personnel and contractors operate in a manner \u201cconsistent with US Government requirements and processes.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"18.0\">Global workers \u201chave no direct access to customer data or customer systems,\u201d the statement said. Escorts \u201cwith the appropriate clearances and training provide direct support. These personnel are provided specific training on protecting sensitive data, preventing harm, and use of the specific commands\/controls within the environment.\u201d In addition, Microsoft said it has an internal review process known as \u201cLockbox\u201d to \u201cmake sure the request is deemed safe or has any cause for concern.\u201d A company spokesperson declined to provide specifics about how it works but said it\u2019s built into the system and involves review by a Microsoft employee in the U.S.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"19.0\">Over the years, various people involved in the work, including a Microsoft cybersecurity leader, warned the company that the arrangement is inherently risky, those people told ProPublica. Despite the presence of an escort, foreign engineers are privy to granular details about the federal cloud \u2014 the kind of information hackers could exploit. Moreover, the U.S. escorts overseeing these workers are ill equipped to spot suspicious activity, two of the people said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"20.0\">Even those who helped develop the escort system acknowledge the people doing the work may not be able to detect problems.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"21.0\">\u201cIf someone ran a script called \u2018fix_servers.sh\u2019 but it actually did something malicious then [escorts] would have no idea,\u201d Matthew Erickson, a former Microsoft engineer who worked on the escort system, told ProPublica in an email. That said, he maintained that the \u201cscope of systems they could disrupt\u201d is limited.<\/p>\n<p>The Defense Department requires anyone working with its most sensitive data to be a U.S. citizen, U.S. national or permanent resident. \u201cNo Foreign persons may have such access,\u201d according to the department\u2019s cloud security requirements. Microsoft, however, has a global workforce, so it created the digital escort system as a work-around. Here\u2019s an example of how it works and the risk it poses:<\/p>\n<p>Tech support is needed on a Microsoft cloud product.<\/p>\n<p>A Microsoft engineer in China files an online \u201cticket\u201d to take on the work.<\/p>\n<p>A U.S.-based escort picks up the ticket.<\/p>\n<p>The engineer and the escort meet on the Microsoft Teams conferencing platform.<\/p>\n<p>The engineer sends computer commands to the U.S. escort, presenting an opportunity to insert malicious code.<\/p>\n<p>The escort, who may not have advanced technical expertise, inputs the commands into the federal cloud system.<\/p>\n<p> Illustrations for ProPublica<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"25.0\">A Microsoft contractor called Insight Global posted an ad in January seeking an escort to bring engineers without security clearances \u201cinto the secured environment\u201d of the federal government and to \u201cprotect confidential and secure information from spillage,\u201d an industry term for a data leak. The pay started at $18 an hour.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"26.0\">While the ad said that specific technical skills were \u201chighly preferred\u201d and \u201cnice to have,\u201d the main prerequisite was possessing a valid \u201csecret\u201d level clearance issued by the Defense Department.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"26.1\">\u201cPeople are getting these jobs because they are cleared, not because they\u2019re software engineers,\u201d said the escort who agreed to speak anonymously and who works for Insight Global.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"27.0\">Each month, the company\u2019s roughly 50-person escort team fields hundreds of interactions with Microsoft\u2019s China-based engineers and developers, inputting those workers\u2019 commands into federal networks, the employee said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"28.0\">In a statement to ProPublica, Insight Global said it \u201cevaluates the technical capabilities of each resource throughout the interview process to ensure they possess the technical skills required\u201d for the job, and provides training. The company noted that escorts also receive additional cyber and \u201cinsider threat awareness\u201d training as part of the government security clearance process.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"29.0\">\u201cWhile a security clearance may be required for the role, it is but one piece of the puzzle,\u201d the company said. <\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"29.1\">Microsoft did not respond to questions about Insight Global.<\/p>\n<h3>\u201cThe Path of Least Resistance\u201d<\/h3>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"29.2\">When modern cloud technology emerged in the 2000s, offering on-demand computing power and data storage via the internet, it ushered in fundamental changes to federal government operations.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"30.0\">For decades, federal departments used computer servers owned and operated by the government itself to house data and power networks. Shifting to the cloud meant moving that work to massive off-site data centers managed by tech companies.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"31.0\">Federal officials believed that the cloud would provide greater power, efficiency and cost savings. But the transition also meant that the government would cede some control over who maintained and accessed its information to companies like Microsoft, whose employees would take over tasks previously handled by federal IT workers.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"32.0\">To address the risks of this revolution, the government started the Federal Risk and Authorization Management Program, known as FedRAMP, in 2011. Under the program, companies that wanted to sell their cloud services to the government had to establish how they would ensure that personnel working with sensitive federal data would have the requisite \u201caccess authorizations\u201d and background screenings. On top of that, the Defense Department had its own cloud guidelines, requiring that people handling sensitive data be U.S. citizens or permanent residents.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"33.0\">This presented an issue for Microsoft, given its reliance on a vast global workforce, with significant operations in India, China and the European Union. So the company tapped a senior program manager named Indy Crowley to put federal officials at ease. Known for his familiarity with the rules and his ability to converse in the government\u2019s acronym-heavy lingo, colleagues dubbed him the \u201cFedRAMP whisperer.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"34.0\">In an interview, Crowley told ProPublica that he appealed directly to FedRAMP leadership, arguing that the relative risk from Microsoft\u2019s global workforce was minimal. To make his point, he said he once grilled a FedRAMP official on the provenance of code in products supplied by other government vendors such as IBM. The official couldn\u2019t say with certainty that only U.S. citizens had worked on the product in question, he said. The cloud, Crowley argued, should not be treated any differently.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"35.0\">Crowley said he also met with prospective customers across the government and told ProPublica that the Defense Department was the \u201cone making the most demands.\u201d Concerned about the company\u2019s global workforce, officials there asked him who from Microsoft would be \u201cbehind the curtain\u201d working on the cloud. Given the department\u2019s citizenship requirements, the officials raised the possibility of Microsoft \u201chiring a bunch of U.S. citizens to maintain the federal cloud\u201d directly, Crowley told ProPublica. For Microsoft, the suggestion was a nonstarter, Crowley said, because the increased labor costs of implementing it broadly would make a cloud transition prohibitively expensive for the government.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"36.0\">\u201cIt\u2019s always a balance between cost and level of effort and expertise,\u201d he told ProPublica. \u201cSo you find what\u2019s good enough.\u201d Hiring virtual escorts to supervise Microsoft\u2019s foreign workforce emerged as \u201cthe path of least resistance,\u201d Crowley said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"37.0\">Microsoft did not respond to ProPublica\u2019s questions about Crowley\u2019s account.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"38.0\">When he brought the concept back to Microsoft, colleagues had mixed reactions. Tom Keane, then the corporate vice president for Microsoft\u2019s cloud platform, Azure, embraced the idea, according to a former employee involved in the discussions, as it would allow the company to scale up. But that former employee, who was involved in cybersecurity strategy, told ProPublica they opposed the concept, viewing it as too risky from a security perspective. Both Keane and Crowley dismissed the concerns, said the former employee, who left the company before the escort concept was deployed.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"39.0\">\u201cPeople who got in the way of scaling up did not stay,\u201d the former employee told ProPublica.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"39.1\">Crowley said he did not recall the discussion. Keane did not respond to requests for comment.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"40.0\">On its march to becoming one of the world\u2019s most valuable companies, Microsoft has repeatedly prioritized corporate profit over customer security, ProPublica has found. Last year, the news organization reported that the tech giant ignored one of its own engineers when he repeatedly warned that a product flaw left the U.S. government exposed; state-sponsored Russian hackers later exploited that weakness in one of the largest cyberattacks in history. Microsoft has defended its decision not to address the flaw, saying that it received \u201cmultiple reviews\u201d and that the company weighs a variety of factors when making security decisions.<\/p>\n<h3>A Skills Gap From the Start<\/h3>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"42.0\">The idea of an escort wasn\u2019t novel. The National Institute of Standards and Technology, which serves as the federal government\u2019s standards-setting body, had established recommendations on how IT maintenance should be performed on-site, such as in a restricted government office. \u201cMaintenance personnel that lack appropriate security clearances or are not U.S. citizens\u201d must be escorted and supervised by \u201capproved organizational personnel who are fully cleared, have appropriate access authorizations, and are technically qualified,\u201d the guidelines state.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"43.0\">The government at the time specified the intent of the recommendation: to deny \u201cindividuals who lack appropriate security clearances &#8230; or who are not U.S. citizens, visual and electronic access to\u201d sensitive government information.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"44.0\">But escorts in the cloud wouldn\u2019t necessarily be able to meet that goal, given the gap in technical expertise between them and the Microsoft counterparts they would be taking direction from.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"44.1\">That imbalance, though, was baked into the escorting model.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"45.0\">Erickson, the former Microsoft engineer who worked on the model, told ProPublica that escorts are \u201csomewhat technically proficient,\u201d but mainly are \u201cjust there to make sure the employees don\u2019t accidentally or intentionally view\u201d passwords, customer data or personally identifiable information. \u201cIf there are problems with the underlying\u201d cloud services, \u201cthen only the people who work on those services at Microsoft would have the requisite knowledge to fix it,\u201d he said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"46.0\">Advanced threats from foreign adversaries weren\u2019t on the radar for Erickson, who said he didn\u2019t \u201chave any reason to suspect someone more just based on their country of origin.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"46.1\">\u201cI don\u2019t think there is any extra threat from Microsoft employees based in other countries,\u201d he said.<\/p>\n<p>        <span class=\"attribution__credit\"><br \/>\n        <span class=\"a11y\">Credit: <\/span><br \/>\n        Illustration by Andrea Wise\/ProPublica. Source images: Bevan Goldswain\/Getty Images, kontekbrothers\/Getty Images, amgun\/Getty Images.<br \/>\n    <\/span><\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"48.0\">Pradeep Nair, a former Microsoft vice president who said he helped develop the concept from the start, said that the digital escort strategy allowed the company to \u201cgo to market faster,\u201d positioning it to win major federal cloud contracts. He said that escorts \u201ccomplete role-specific training before touching any production system\u201d and that a variety of safeguards including audit logs, the digital trail of system activity, could alert Microsoft or the government to potential problems.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"49.0\">\u201cBecause these controls are stringent, residual risk is minimal,\u201d Nair said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"50.0\">But legal and cybersecurity experts say such assumptions ignored the massive cyber threat from China in particular. Around the time that Microsoft was developing its escort strategy, an attack attributed to Chinese state-sponsored hackers resulted in the largest breach of U.S. government data up to that point. The theft initially targeted a government contractor and eventually compromised the personal information of more than 22 million people, most of them applicants for federal security clearances.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"51.0\">Chinese laws allow government officials there to collect data \u201cas long as they\u2019re doing something that they\u2019ve deemed legitimate,\u201d said Jeremy Daum, senior research fellow at the Paul Tsai China Center at Yale Law School. Microsoft\u2019s China-based tech support for the U.S. government presents an opening for espionage, \u201cwhether it be putting someone who\u2019s already an intelligence professional into one of those jobs, or going to the people who are in the jobs and pumping them for information,\u201d Daum said. \u201cIt would be difficult for any Chinese citizen or company to meaningfully resist a direct request from security forces or law enforcement.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"52.0\">Erickson acknowledged that having an escort doesn\u2019t prevent foreign developers \u201cfrom doing \u2018bad\u2019 things. It just allows for there to be a recording and a witness.\u201d He said if an escort suspects malicious activity, they will end the session and file an incident report to investigate further.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"53.0\">How much of this information federal officials understood is unclear.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"54.0\">A Microsoft spokesperson said the company described the digital escort model in the documents submitted to the government as part of cloud vendor authorization processes. However, it declined to provide those records or to tell ProPublica the exact language it used in them to describe the escort arrangement, citing the potential security risk of publicly disclosing it.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"55.0\">In addition to a third-party auditor, Microsoft\u2019s documentation theoretically would have been reviewed by multiple parties in the government, including FedRAMP and DISA. DISA said the materials are \u201cnot releasable to the public.\u201d The General Services Administration, which houses FedRAMP, did not respond to requests for comment.<\/p>\n<h3>The \u201cRight Eyes\u201d for the Job?<\/h3>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"57.0\">In June 2016, Microsoft announced that it had received FedRAMP authorization to work with some of the government\u2019s most sensitive data. Matt Goodrich, then FedRAMP director, said at the time that the accreditation was \u201ca testament to Microsoft\u2019s ability to meet the government\u2019s rigorous security requirements.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"58.0\">Around the same time, Microsoft put the escort concept into practice, engaging contacts from defense giant Lockheed Martin to hire cloud escorts, two people involved in the contract told ProPublica.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"59.0\">A project manager, who asked for anonymity to describe confidential discussions, told ProPublica that they were skeptical of the escort arrangement from the start and voiced those feelings to their Microsoft counterpart. The manager was especially concerned that the new hires would not have the \u201cright eyes\u201d for the job given the relatively low pay set by Microsoft, but the system went ahead anyway.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"60.0\">Lockheed Martin referred questions to Leidos, a company that took over Lockheed\u2019s IT business following a merger in 2016. Leidos declined to comment.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"60.1\">As Microsoft captured more of the government\u2019s business, the company turned to additional subcontractors, typically staffing companies, to hire more digital escorts.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"61.0\">Analyzing profiles on LinkedIn, ProPublica identified at least two such firms: Insight Global and ASM Research, whose parent company is consulting giant Accenture. While the scope of each firm\u2019s business with Microsoft is unclear, ProPublica found more workers identifying themselves as digital escorts at Insight Global, many of them former military personnel, than at ASM. ASM and Accenture did not respond to requests for comment<\/p>\n<h3>Concerns About China<\/h3>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"63.0\">Some Insight Global workers recognized the same problem as the former Lockheed manager: a mismatch in skills between the U.S.-based escorts and the Microsoft engineers they are supervising. The engineers might briefly describe the job to be completed \u2014 for instance, updating a firewall, installing an update to fix a bug or reviewing logs to troubleshoot a problem. Then, with limited inspection, the escort copies and pastes the engineer\u2019s commands into the federal cloud.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"64.0\">\u201cThey\u2019re telling nontechnical people very technical directions,\u201d the current Insight Global escort said, adding that the arrangement presents untold opportunities for hacking. As an example, they said the engineer could install an update allowing an outsider to access the network.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"65.0\">\u201cWill that get caught? Absolutely,\u201d the escort told ProPublica. \u201cWill that get caught before damage is done? No idea.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"66.0\">The escort was particularly concerned about the dozens of tickets a week filed by workers based in China. The attack targeting federal officials in 2023 \u2014 in which Chinese hackers stole 60,000 emails \u2014 underscored that fear.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"67.0\">The federal Cyber Safety Review Board, which investigated the attack, blamed Microsoft for security lapses that gave hackers their opening. Its published report did not mention digital escorts, either as playing a role in the attack or as a risk to be mitigated. Sherman, the former chief information officer for the Defense Department, and Coker, the former intelligence official, who both also served as members of the CSRB, told ProPublica that they did not recall the board ever discussing digital escorting, which they said they now consider a major threat. The Trump administration has since disbanded the CSRB.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"68.0\">In its statement, Microsoft said it expects escorts \u201cto perform a variety of technical tasks,\u201d which are outlined in its contracts with vendors. Insight Global said it evaluates prospective hires to ensure they have those skills and trains new employees on \u201call applicable security and compliance policies provided by Microsoft.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"69.0\">But the Insight Global employee told ProPublica the training regimen doesn\u2019t come close to bridging the knowledge gap. In addition, it is challenging for escorts to gain expertise on the job because the type of work they oversee varies widely. \u201cIt\u2019s not possible to get as trained up as you need to be on the wide array of things you need to look at,\u201d they said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"70.0\">The escort said they repeatedly raised concerns about the knowledge gap to Microsoft, over several years and as recently as April, and to Insight Global\u2019s own attorneys. They said the digital escorts\u2019 relative inexperience \u2014 combined with Chinese laws that grant the country\u2019s officials broad authority to collect data \u2014 left U.S. government networks overly exposed. Microsoft repeatedly thanked the escort for raising the issues while Insight Global said it would take them under advisement, the escort said. It is unclear whether Microsoft or Insight Global took any steps to address them; neither company answered questions about the escort\u2019s account.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"71.0\">In its statement, Microsoft said it meets regularly with its contractors \u201cto discuss operations and surface questions or concerns.\u201d The company also noted that it has additional layers of \u201csecurity and monitoring controls\u201d including \u201cautomated code reviews to quickly detect and prevent the introduction of vulnerabilities.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"72.0\">\u201cMicrosoft assumes anyone that has access to production systems, regardless of location or role, can pose a risk to the system, whether intentionally or unintentionally,\u201d the company said in its statement.<\/p>\n<h3>Another Warning, a Growing Risk<\/h3>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"74.0\">Last year, about three months after government investigators released their report on the 2023 hack into U.S. officials\u2019 emails, a former Insight Global contractor named Tom Schiller contacted a Defense Department hotline and wrote to several federal lawmakers to warn them about digital escorting. He had become familiar with the system while briefly working for the company as a software developer. By last July, Schiller\u2019s complaints wound their way to the Defense Information Systems Agency Office of the Inspector General. Schiller told ProPublica that the office conducted a sworn interview with him, and separately with three others connected to Insight Global. In August, the inspector general wrote to Schiller to say it had closed the case.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"75.0\">\u201cWe conducted a preliminary analysis into the complaint and determined this matter is not within the avenue of redress by DISA IG and is best addressed by the appropriate DISA management,\u201d the assistant inspector general for investigations said in the letter. \u201cWe have referred the information you provided to management.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"76.0\">A spokesperson for the inspector general \u2014 whose office is supposed to operate independently in order to investigate potential waste, fraud and abuse \u2014 told ProPublica they were not authorized to speak about the issue and directed questions to DISA public affairs.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"77.0\">\u201cIf the public information office contacts me and wants to collaborate to formulate a response through their office, I\u2019ll be more than happy to do that,\u201d the spokesperson said. \u201cBut I will not be responding to any kind of media request concerning OIG business without speaking with the public information office.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"78.0\">DISA public affairs did not answer questions about the matter. After a spokesperson initially said that he couldn\u2019t find anyone who had heard of the escort concept, the agency later acknowledged in a statement to ProPublica that escorts are used \u201cin select unclassified environments\u201d at the Defense Department for \u201cadvanced problem diagnosis and resolution from industry subject matter experts.\u201d Echoing Microsoft\u2019s statement, it continued, \u201cExperts under escort supervision have no direct, hands-on access to government systems; but rather offer guidance and recommendations to authorized administrators who perform tasks.\u201d<\/p>\n<p>\n                <strong class=\"story-promo__hed\">Microsoft\u2019s \u201cDigital Escort\u201d Program Could Leave Sensitive Government Info Vulnerable to Espionage. Here\u2019s What to Know.<\/strong>\n                            <\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"80.0\">It is unclear what, if any, discussions have taken place among Microsoft, Insight Global and DISA, or any other government agency, regarding digital escorts.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"80.1\">But David Mihelcic, DISA\u2019s former chief technology officer, said any visibility into the Defense Department\u2019s network poses a \u201chuge risk.\u201d<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"80.2\">\u201cHere you have one person you really don\u2019t trust because they\u2019re probably in the Chinese intelligence service, and the other person is not really capable,\u201d he said.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"81.0\">The risk may be getting more serious by the day, as U.S.-China relations worsen amid a simmering trade war \u2014 the type of conflict that experts say could result in Chinese cyber retaliation.<\/p>\n<p data-pp-blocktype=\"copy\" data-pp-id=\"82.0\">In testimony to a Senate committee in May, Microsoft President Brad Smith said the company is continually \u201cpushing Chinese out of agencies.\u201d He did not elaborate on how they got in, and Microsoft did not respond to follow-up questions on the remark.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>ProPublica is a nonprofit newsroom that investigates abuses of power. Sign up to receive our biggest stories as soon as they\u2019re published. Reporting Highlights Chinese Tech Support: Microsoft is using engineers in China to help maintain the Defense Department\u2019s computer systems \u2014 with minimal supervision by U.S. personnel. Skills Gap: Digital escorts often lack the<\/p>\n","protected":false},"author":1,"featured_media":11051,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[55],"tags":[4261,1111,2129,280,1136,4260,3804,4262,1563,247],"class_list":{"0":"post-11050","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-social-issues","8":"tag-chinese","9":"tag-data","10":"tag-defense","11":"tag-dept","12":"tag-digital","13":"tag-escorts","14":"tag-expose","15":"tag-hackers","16":"tag-microsoft","17":"tag-propublica"},"_links":{"self":[{"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=\/wp\/v2\/posts\/11050","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=11050"}],"version-history":[{"count":0,"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=\/wp\/v2\/posts\/11050\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=\/wp\/v2\/media\/11051"}],"wp:attachment":[{"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=11050"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=11050"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/naijaglobalnews.org\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=11050"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}