Bonum Certa Men Certa

Ron Wyden: Microsoft Should be Held Accountable for Security Breaches (He Has Said This for Years Already, It Never Happens)

posted by Roy Schestowitz on Sep 11, 2025,
updated Sep 11, 2025

Ronald Lee Wyden

Suppose I leave a door open and thousands of cockroaches run in for a period of several hours. Whose fault is it? The cockroaches' fault? Or mine? Suppose I also leave food in the hallway, attracting them in.

Now take Microsoft: it takes two parties to make systems and databases (with personal information) vulnerable, i.e. doomed to be penetrated. Microsoft makes the holes, then someone deploys the holes. Forget about blaming "China" and "Russia". There's no extradition prospect and holding Russians accountable in much of the world is complicated, more so if they reside and stay in Russia. In the fake news reports, many so-called (self-described) "journalists" help Microsoft by deflecting the blame, passing culpability from Microsoft to "China" and "Russia" (knowing they cannot be held accountable). Sometimes they instead blame "Iran" and "North Korea". Microsoft, the culprit, then paints itself as the "victim" of those "rogue" nations. What a reversal of reality! Some of those phony "journalists" (PR bunnies) then paint Microsoft as the expert or saviour. That's just grotesque.

Now consider this new report, "Appeal court orders release of convicted psychotherapy centre database hacker" (who cannot pay and whose imprisonment costs the state money).

"If the court reduces his sentence," it says, "there's a risk that Aleksanteri Kivimäki will have spent too much time in prison — and then be able to demand compensation from the state."

So taxpayers will pay him even more? This is what Yle says, we're not making it up:

Appeal court orders release of convicted psychotherapy centre database hacker

How was this database compromised? Whose fault was it?

Was this Windows TCO, as usual?

"The United States has placed an $11 million bounty on Volodymyr Tymoshchuk, a Ukrainian man wanted for his involvement with a string of ransomware cybercrimes," says [1]. Here's another example of Windows TCO: "Akira is also poking holes in SonicWall SSLVPN misconfigurations, abusing all of these security risks to gain access to vulnerable devices and conduct ransomware attacks" [2] and Ron "Wyden, whose staff interviewed or spoke with Ascension and Microsoft staff as part of the senator’s oversight," [3] wants "the Federal Trade Commission (FTC) investigate and hold Microsoft responsible for its gross cybersecurity negligence" [4]. There are other Windows TCO stories in today's news [5] and it seems the US government is willing to spent a lot of taxpayers' money chasing someone who cannot pay it back [6] "after allegedly orchestrating ransomware operations" (Windows TCO).

This does not make any sense. So a lot of money is lost and then they want to spend more money without ever holding the principal culprits (who are rich) responsible.

"He is only 1 of n perpetrators," an associate said of the one who was put in prison (and might soon get more money from the state), plus "they still have not identified and prosecuted those involved in deploying Microsoft products into a production environment and thus laying the groundwork for his break-in."

The associate added that "the recent letter by Senator Wyden could form the basis for an article or two" because "Wyden's letter and the related article are in [Daily] Links," and moreover reproduced again below.

Wyden has been talking about this for a very long time. But it never happens. Microsoft and Bill Epsteingate seem to have bribed enough US politicians to look the other way or write birthday cards to Bill's mate.

When will we see Microsoft being compelled to pay multi-billion-dollar fines for its shoddy security? Negative media coverage isn't a fine and it does nothing to compensate Microsoft's billions of victims.

Related/contextual items from the news:

  1. U.S. places $11 million bounty on Ukrainian ransomware mastermind — Tymoshchuk allegedly stole $18 billion from large companies over 3 years

    The United States has placed an $11 million bounty on Volodymyr Tymoshchuk, a Ukrainian man wanted for his involvement with a string of ransomware cybercrimes. Tymoshchuk faces severe federal charges for his part in reportedly masterminding the theft of a combined $18 billion over a three year period.

  2. Akira ransomware crims abusing trifecta of SonicWall flaws

    Akira is also poking holes in SonicWall SSLVPN misconfigurations, abusing all of these security risks to gain access to vulnerable devices and conduct ransomware attacks, according to a Rapid7 warning on Wednesday.

  3. Wyden calls on FTC to investigate Microsoft for ‘gross cybersecurity negligence’ in protecting critical infrastructure

    Wyden, whose staff interviewed or spoke with Ascension and Microsoft staff as part of the senator’s oversight, said the attack “perfectly illustrates” the negative consequences of Microsoft’s cybersecurity policies.

  4. Letter from Senator Wyden to FTC Chair Andrew Ferguson

    I write to request that the Federal Trade Commission (FTC) investigate and hold Microsoft responsible for its gross cybersecurity negligence, resulting in ransomware attacks against critical infrastructure, including U.S. health care organizations, which have caused enormous harm to health care providers, put patient care at risk, and continues to threaten U.S. national security.

  5. S-bank fined €1.8m for lax data security

    The Office of the Data Protection Ombudsman has issued a warning and an administrative penalty of 1.8 million euros to S-Bank for a data security breach in the bank's identification service in 2022.

    The decision is not yet legally binding, as it may still be appealed to an administrative court.

  6. US indicts alleged ransomware boss tied to $18B in damages

    A Ukrainian national faces serious federal charges and an $11 million bounty after allegedly orchestrating ransomware operations that caused an estimated $18 billion in damages across hundreds of organizations worldwide.

Other Recent Techrights' Posts

Richard Stallman's Talk at Georgia Tech is Just 2 Days Away
We're still curious to see how malicious people (or trolls) in social control media will try to slant his talk as "bad"
The "Alicante Mafia" - Part VII - The Industrial Actions Began Yesterday, Here's Why
The "Alicante Mafia" might not last much longer
openai.com Traffic Said to Have Fallen 50% in the Past Three Months, Reports Say It Nearly Ran Out of Money to Borrow
After the slop frenzy all we'll have left is environmental destruction
 
Links 21/01/2026: "Snap Settles Lawsuit on Social Media Addiction" and Attempts in the US to Revive Software Patents
Links for the day
Links 21/01/2026: Microsoft 'Open' 'Hey Hi' in More Trouble, US Has "Brown Shirts" Problem
Links for the day
Yesterday Afternoon The Register MS Published Paid Microsoft SPAM Disguised as an Article About "AI PCs"
The Register MS cannot help itself, can it? [...] Follow the money.
Microsoft's XBox is in Effect Dead Already, Now It's a Streaming and Advertising Platform
Expect many layoffs soon
EPO's Web Site Misused for Propaganda About Illegal Kangaroo Courts to Distract From EPO Scandals and Judicial Crisis in Europe
UPC is illegal and unconstitutional
Gemini Links 21/01/2026: Edible Circuits and "Sayonara HTTP"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Tuesday, January 20, 2026
IRC logs for Tuesday, January 20, 2026
IBM Hides Its Own Destruction (and Red Hat's)
It's like scenes out of '1984', which is what a now-famous advertisement from Apple compared IBM to
LLM Slop Not Dead Yet, Examples of Slop About "Linux"
We wish to see the totals down to zero
Links 20/01/2026: Cheeto Blackmails France Into 'Peace' While Looking to Annex EU, Mass Layoffs in Capgemini (Microsoft Reseller/Promoter) in France
Links for the day
Gemini Links 20/01/2026: Boxing and "Inbox Zero" Success
Links for the day
Windows and Slop Declining While Microsoft Silences Critics
Microsoft tries to suppress facts while faking 'demand' by imposing slop on everybody, everywhere
IBM Kills OzLabs, Signalling An Attack on Free Software (a Sign for Red Hat)
ibiblio also appears to have died (or experiences critical issues)
Red Hat Vice President Leaving After Nearly Two Decades
IBM's culture of secrecy is not compatible with Free software
Links 20/01/2026: "ChatGPT Health" (Latest Distraction From Being Insolvent) Flops and Raises Concerns, "The U.S. Military Faces a Reckoning on Greenland"
Links for the day
Rudeness and Vulgarity Won't Stop Journalism About Free Software
we seem to be on the right path
Readers Pleased With Layout Changes
Two days ago we began improving clarity and accessibility in the site
IBM Plans for Layoffs Becoming Clearer With "Employee Reviews"
Of course this impacts Red Hat as well
IBM is Outsourcing Red Hat's Fedora to Slop to 'Save Money'
If IBM cared about quality rather than alleged "cost savings" (cutting corners), it would assign more IBM staff to Fedora, but instead the exact opposite happened, with the likes of Cotton and Miller removed from the project
European Patent Office (EPO) Industrial Actions Formally Start in Two Hours
As per the latest (revised) action plan, today workers will slow down their work and limit patent grants
Microsoft Under Fresh Investigation by the Italian Competition Authority
In 2025 we kept a running tally of 30,000+ Microsoft layoffs, so 40k this year would not be unthinkable
The "Alicante Mafia" - Part VI - More Strikes Planned at the EPO, Starting This Month
Yesterday we said that friends of Berenguer or inside Berenguer's circle may have left
Gemini Links 20/01/2026: New Tea, Using a Roku at a Hotel, and "Voltage-Based Power Management for Any Raspberry Pi"
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Monday, January 19, 2026
IRC logs for Monday, January 19, 2026
If You Don't Want "Linux" to Become "Windows", Then Follow GNU
GAFAM isn't a friend of Linux; it's only a user in the same sense clients are "users" of a brothel
Links 19/01/2026: National Broadcasters on World or Local Affairs Up to a Week Ago
Links for the day
Gemini Links 19/01/2026: Game Boy and "The Lounge" (IRC) for the Elderly
Links for the day
Slopfarms in Google News (at Least Three Today) With Fake 'Articles' About "Linux"
Google itself is trying to promote its own slop ("Overview") at the expense of original and credible sources
Links 19/01/2026: ChatGPT’s Defects and The Guardian on Why So-called "AI Companies Will Fail"
Links for the day
This is What the Slop Bubble Popping Can Look Like
Maybe not an overnight collapse, but getting there gradually
IBM Quiet About Its Plan for Red Hat Amid Accelerated Bluewashing
Something is going on at Red Hat
The "Alicante Mafia" - Part V - It Seems Like Some People Are Already Leaving "The Mafia"
they have a rough idea of what's coming
Microsoft Means War, Microsoft is on the Side of ICE
Microsoft, people-ready
More Confirmatory Rumours Regarding "Massive" Red Hat Layoffs
Ecosystem and sales said to be targeted
Proprietary UNIX is What We'll Have If IBM Red Hat Gets Its Way
IBM Red Hat wants to control everything, even if that means killing everybody
Free Software in Times of Peace (and Times of War, Too)
GAFAM and IBM are war companies
Founder of GNU/Linux (RMS) Speaks in US University (College) This Week
The auditorium has very high capacity and this is his "college comeback" talk in the United States
Office Meetings Are Most Useful to the Least Productive Workers
In my "office life" days I really didn't like meetings
LinuxSecurity and Linuxiac Are Still Slopfarms, Even Anthony Pell Does It
We suppose waiting another month or another year won't change a thing
Claim That the Board of Directors at IBM Isn't Happy With How the Company is Run
IBM tries to project an image of strength to the whole world, especially to its clients
Links 18/01/2026: Legal Trouble for xAI, Climate Concerns, Data Breaches and More
Links for the day
'Vibe Coding', Chatbots, and Other Bots (e.g. "Agents" Disguised as "Superintelligence") Aren't Saving You Time
False marketing, FOMO marketing tactics
Gemini Links 19/01/2026: Analog Cameras and Plucker in 2026, US Losing Acceptability in Europe
Links for the day
Over at Tux Machines...
GNU/Linux news for the past day
IRC Proceedings: Sunday, January 18, 2026
IRC logs for Sunday, January 18, 2026