
Microsoft’s little-known “digital escorts” program allowed foreign engineers in China to service the U.S. government’s sensitive computer systems — until reporter Renee Dudley found out about it.
Loading summary
Jessica Lessenhop
ProPublica Investigative journalism in the public interest. I have, like most people, I assume a pretty healthy fear of getting hacked. Even saying that out loud makes me nervous, like I'm speaking it into existence. But it's become this fact of our online lives. I've gotten three alerts this year about my personal information being hacked. Nobody's hacking me. To be clear, I'm not important or rich enough for that. People are hacking the big companies I trusted to keep my information safe. And there's seemingly nothing I can do about it. Nothing except complain.
Renee Dudley
Everybody loves to complain about Microsoft.
Jessica Lessenhop
Really?
Renee Dudley
Yeah.
Jessica Lessenhop
This is my ProPublica colleague who does a lot more than complain when she learns about a big hack.
Renee Dudley
I'm Renee Dudley and I am a cybersecurity and technology reporter at ProPublica.
Jessica Lessenhop
Lately Renee's been more like our Microsoft reporter.
Renee Dudley
Techies have long held that Microsoft is a legacy company with weaknesses that are just waiting to be exploited by hackers.
Jessica Lessenhop
Microsoft is one of the world's biggest companies and a major supplier of technology to one very important customer.
Renee Dudley
The federal government is actually one of Microsoft's biggest, if not its biggest customer, and has been for years.
Jessica Lessenhop
The Pentagon uses Microsoft for email calendars, storing files, and Microsoft's weaknesses that everyone loves to complain about, they've already been exploited by our biggest cyber adversaries. Like in 2017 we learned North Korean hackers targeted 150 countries including the US and the UK creating mayhem in the British health service. In 2020 we learned Russian hackers got access to reams of sensitive US government data. And then there's China, our most active and persistent cyber threat. In 2023, Chinese government backed hackers were able to get their hands on about 60,000 State Department emails from Microsoft Outlook. Congress held a hearing where a Microsoft executive took responsibility for the hack and promised to address security weaknesses. All of this is why Renee was surprised when she was on the phone with a Microsoft contact of hers and they told her something kind of wild.
Renee Dudley
A Microsoft source told me, sort of apropos of nothing. We've been talking about this other story. They said there's some crazy stuff going on. You wouldn't believe this, but Microsoft is running IT support and service for the Defense Department through China. And I was like, what are you talking about?
Jessica Lessenhop
What they were basically saying is anytime the government's Microsoft products needed updating or fixing, there was a chance that engineers in China were the ones doing it, meaning engineers there could have access to the US government sensitive files.
Renee Dudley
My initial reaction was this cannot be True, because it just sounds so far fetched. I mean, I know that Microsoft has global operations. I know that it's a massive tech company, they've got workers all over the globe. But I'm also by this point familiar with the Defense Department's rules that prohibit non US citizens from working on highly sensitive information that we would not want our enemies to know. Military secrets and the like.
Jessica Lessenhop
These are secrets the Chinese government is actively trying to get at. What if they didn't have to hack into our systems? What if we were handing over our secrets, or at least our cyber weaknesses on a silver platter to Chinese citizens? Chinese citizens who could be compelled by the Chinese Communist Party to hand them over? Given Microsoft's track record and her past reporting on the company, Renee thought maybe there's something to this. So she asked around to see if she could find anyone else who may know anything about this and came across a very interesting comment on LinkedIn talking about this very thing.
Renee Dudley
It was by this guy named Tom Shiller.
Jessica Lessenhop
Rene called him up and Tom told her that he'd done some work with a contractor for Microsoft and he'd learned that sure enough, Microsoft was using their engineers employed in China to serve as sensitive government systems. What's more, Tom said he'd seen how it was happening up close. He said the China based engineer could get around the US Government's rules by having a US citizen escort them.
Renee Dudley
He finds out about this system that he referred to as digital escorting.
Jessica Lessenhop
When you just hear the term digital escort, like what was your first thought?
Renee Dudley
What's he talking about? And then as soon as we hang up, I start googling and quickly realize I'm probably gonna get flagged by HR and IT for untoward searches on my work computer.
Jessica Lessenhop
Because it is, to be explicit, a little, possibly, I don't know, porny, a
Renee Dudley
little racy, you know, the results that I was getting weren't what I was expecting.
Jessica Lessenhop
Digital escorting. She didn't understand exactly what that meant. It was a strange term. And it came to her from Tom, who turned out to be a bit of an unusual source.
Renee Dudley
He was a little bit of a conspiracy theorist, to put it mildly.
Jessica Lessenhop
Tom was describing digital escorting as part of something very nefarious. He called it a, quote, cyber 9, 11. He theorized that Microsoft was collaborating with the Communist Party of China, calling it the, quote, prelude to World War three. But given all the successful cyber attacks from the Chinese government over the years, this lead seemed like it was too big not to investigate.
Renee Dudley
It was shortly after this conversation that I found A real piece of evidence on the Internet that made me realize, I think, that both the original tipster and Tom Schiller are onto something here.
Jessica Lessenhop
I'm Jessica Lessenhop, this is Paper Trail. Renae started her reporting journey in a pretty basic place, searching the term digital escort.
Renee Dudley
I sort of just kind of go to town on Google to see if there's any mention of this whatsoever. And I did come across this job
Jessica Lessenhop
ad, a job ad hosted by a company called Insight Global. It's the same one that Tom Shiller had done work for.
Renee Dudley
They're looking for a digital escort.
Jessica Lessenhop
They're willing to pay 18 to $28 an hour.
Renee Dudley
And the description of the job almost exactly matched what Tom Shiller described it as.
Jessica Lessenhop
The job ad spelled out the exact skills and requirements for a so called digital escort, which again, to be clear, were not like onlyfans skills. They were computer skills. But strangely, it didn't seem like a suitable candidate needed to be a tech wizard. Most of the tech skills listed were just nice to have.
Renee Dudley
The main prerequisite was that you have to have a security clearance.
Jessica Lessenhop
So right away it seemed like, okay, digital escorting was probably a thing. Renee's next question was, who were these people working as digital escorts? She knew they had to be US Citizens, since that's a requirement for a security clearance. But what exactly was their job?
Renee Dudley
So I started working with Doris Burke, our brilliant research reporter here at ProPublica. She's a wizard at LinkedIn, and I asked her if she could find me everybody who's ever worked at Insight Global and everybody on LinkedIn who has the term digital escort listed anywhere in their profile.
Jessica Lessenhop
One of the things I love about this story is that I think people love to dunk on LinkedIn as being possibly one of the most obnoxious social media sites out there. Just because it's like people like hyping themselves up and fishing for work and just kind of in some ways being their worst online selves.
Renee Dudley
That's gold. That's gold to me. Let me hear about every detail of what you've done as a digital escort.
Jessica Lessenhop
So Doris put together an Excel spreadsheet of all these people. The list of people ended up being over 100 names long. And the majority of those people had recently come out of the military.
Renee Dudley
They had a security clearance already from their prior employment. From what I understand about the security clearance process, it makes it easier for the next employer if you've already been through the process.
Jessica Lessenhop
Renee reached out to all her leads and eventually someone got back to her
Renee Dudley
Somebody who was actually a current digital escort at Insight Global.
Jessica Lessenhop
Renee got on the phone with this living, breathing digital escort. They were a bit hesitant to speak with her, but also didn't seem surprised that a reporter had reached out to them.
Renee Dudley
They were sort of waiting for a call like this.
Jessica Lessenhop
They'd been concerned about the work they'd been doing for a while. This person described what a day in the life of a digital escort was like. A digital escort leaps into action when there's a problem. Like let's say one of the government's Microsoft programs needs a software update behind the scenes, unseen by the users at the US government. It's not just one person who responds, it's two people. The US based digital escort who is there to chaperone a foreign based engineer. The real live digital escort confirmed to Renee on the phone that many of the engineers they work with are based in China. So a China based engineer and the US based escort are on the case.
Renee Dudley
They meet together on a Microsoft Teams chat.
Jessica Lessenhop
The China based engineer is the one who knows how to fix the problem. On their end. They produce a block of code to solve it and send it over to the digital escort in the US the digital escort then just copy pastes it
Renee Dudley
and applies it to the Defense Department network.
Jessica Lessenhop
But on the phone with Rene, the real live digital escort explained the problem with that. The US based digital escort has way fewer tech skills than the China based engineer. So when they paste that code into the DoD systems or Renee's source said,
Renee Dudley
you know, me and my colleagues, we've got some tech background, but we just don't have the expertise to know what we're looking at here. We're flying blind. We're assuming that we're inputting into the Defense Department is safe, but we really have no idea.
Jessica Lessenhop
All of this so that they can follow the government's rule that you have to be a U.S. citizen or permanent resident or to handle sensitive data, it's just like a little. It's like a little workaround.
Renee Dudley
It's a workaround.
Jessica Lessenhop
It's a little workaround that actually, when you interrogate it like you did, actually completely violates the spirit and the intent of the government's rule.
Renee Dudley
Yes,
Jessica Lessenhop
this workaround seemed like a huge vulnerability. Who knows if it had already been exploited. If you were a foreign spy, you'd definitely want to be riding along with a US based digital escort. You could take advantage of the escort's lack of knowledge and do something nefarious. Instead of creating code that fixes the problem, they could have the escort unknowingly insert a bug.
Renee Dudley
Now, I understand the logistics of how. How this actually practically goes down.
Jessica Lessenhop
What's going through your mind at this point in the reporting?
Renee Dudley
I'm thinking, who came up with this and does the government even know? And if they do, who approved it and when and how and why?
Jessica Lessenhop
That's next.
Megan
Hi, I'm Megan. I work in membership at ProPublica. I want to tell you a bit about the newsroom that makes this podcast. The first thing you should know is that we're a nonprofit, which means we have no owner, no corporate interests or government funding, and we have no paywall. So everything we publish, including this podcast, is free. Our business model protects our independence. We're not beholden to benefactors. Funders have no say in what we cover. Our reporters have the freedom to investigate the most powerful people and institutions in this country and follow the facts wherever they lead. Right now, a lot of the news industry is being reshaped by political influence, profit motive, and financial pressure. But ProPublica is different. It's investigative journalism for the people, not for profit. Find out more@proPublica.org info.
Narrator (Occupy segment)
For almost two months, a group of anarchists camped out in a tiny park in New York City and turned it into an anti capitalist village. You might know it as Occupy Wall street, But that was 15 years ago. And today we return to that park to ask what happens when ordinary people harness collective power and try to change the world. From future hindsight, this is Occupy an unfinished uprising. Listen, wherever you get your podcasts.
Jessica Lessenhop
At this point, Rene was pretty sure that digital escorts were real, that they were working beside China based engineers on computer systems with sensitive government information. She'd confirmed it with a digital escort who worked for a company that contracted with Microsoft. But she hadn't confirmed any of this with anyone at Microsoft. So she checked in with her contacts who used to work there, people who'd helped her on previous stories, who she considered reliable and trustworthy.
Renee Dudley
I described to them this new information that I have, and they're shook. They're sort of in disbelief. They just said, no way. You know, there's just no way. I don't want to shoo you off a topic. You know, I know this is your job. I'm not trying to defend Microsoft, but there is just no way that this is happening. And I said, well, I don't know what to tell you because I got this job ad and, you know, I've talked to somebody and like, this is happening, you know.
Jessica Lessenhop
Renee thought she had to find the receipts, some kind of documented evidence of the existence of this thing.
Renee Dudley
So that brings us to Doris, who had this idea to check the patents.
Jessica Lessenhop
Doris, the research reporter who'd helped Renee search LinkedIn. Patents are publicly accessible documents that companies file to protect their inventions. She wasn't really sure what exactly to look for, but she took a shot in the dark.
Renee Dudley
She put Microsoft and escort into the U.S. patent Office search bar, and lo and behold, they've got a few patents related to digital escorts. And so it confirmed that people knew about it and that this was a real thing in the company.
Jessica Lessenhop
And the most exciting part to Renee
Renee Dudley
had the list of inventors.
Jessica Lessenhop
These were Microsoft employees, past and present, who all had to know about digital escorting.
Renee Dudley
And so I just start going down the list of people.
Jessica Lessenhop
She reached out and a few of them got back to her. They helped answer a question for Renee. Why and how did Microsoft even come up with this?
Renee Dudley
It goes back to the very beginning of the government's use of the cloud.
Jessica Lessenhop
The cloud. It used to be that the government would store and process its own data on its own servers. Kind of like how you used to have to keep all your documents or photos on a hard drive. But then the cloud came along. People like me started using Google and Dropbox to store my photos and documents. And the government was eager to move to the cloud too. Microsoft really wanted them to move to its cloud. So they struck a deal, well, several deals, to move a lot of the government's data and computing to Microsoft's cloud services.
Renee Dudley
And it's no longer going to be on a US owned and controlled server. It's in a server in a massive data center, you know, controlled, owned and operated by Microsoft.
Jessica Lessenhop
This meant IT support for the cloud would also have to come from Microsoft employees. Microsoft's engineers were already trained to work on the cloud. It's just that many of them weren't US citizens or even based in the US but when the government gave Microsoft its rules that only US Citizens and permanent residents could work on its sensitive files, former employees told Renee that was easier said than done.
Renee Dudley
Microsoft told the government, that's going to be really expensive to hire a slew of US based engineers that they get security clearances for to do nothing but maintain government systems. What else can we do?
Jessica Lessenhop
So Microsoft and the government are going back and forth to trying to make this work. And the idea comes up for a workaround. Digital escorting. Microsoft's global engineers would do the bulk of the work, writing the actual code, but they'd hire digital escorts with the right clearances to be the hands on the keyboard. Renee talked to one Microsoft employee who said that an executive at the company ran with it.
Renee Dudley
The corporate vice president over Microsoft's cloud platform just embraces the idea, you know, this is great. This will help us scale up. And from the discussions that I had, the people who were working on the digital escort concept, they weren't thinking about the worst case scenario. I talked to this one engineer and he said, I don't have any reason to suspect someone more just based on their country of origin.
Jessica Lessenhop
Which fair enough, like country of origin is not a reason to automatically assume bad intent.
Renee Dudley
No. However, the US has rules for who can and cannot access this highly sensitive data.
Jessica Lessenhop
In the worst case scenario, Microsoft's China based engineers could be coerced by the Communist party of China to insert a bug to bring down the US government's computer systems. But it didn't seem like Microsoft was thinking about that scenario.
Renee Dudley
They were not thinking like a investigative reporter or a conspiracy theorist.
Jessica Lessenhop
Tom Shiller, the person who first tipped her off to the existence of digital escorts, had a bit of an affection for conspiracy, but he'd been onto something.
Renee Dudley
Although we were coming to this from different, probably worldviews, the common ground, I think that investigative reporters have with conspiracy theorists is that we have the ability to imagine the worst possible outcome of something. What's the worst that could happen to people? What are the consequences? And that view that you don't have any reason to suspect someone because they're based in another country. National security experts that I talk to about this, they see that as naive. I spoke with Harry Coker, who was a former senior executive at both the CIA and the National Security Agency.
Harry Coker
I would look at that as an avenue to extremely valuable access if I were an operative. Right. And we need to be very concerned
Renee Dudley
about that and said if the roles
Harry Coker
were reversed, we would love to have had access like that.
Renee Dudley
Yeah. The U.S. intelligence community would love to have this kind of setup for spying on China. Coker also basically raised the point of, you know, gee, I wonder if this is the reason for all of these attacks that we've faced over the past few years from China. I mean, who can say? But it, you know, he raised that point. Yeah.
Jessica Lessenhop
It just seemed like an awfully nice opportunity.
Renee Dudley
Yeah.
Jessica Lessenhop
Renee finally reached out to the Microsoft press office with the mountain of evidence she'd compiled and they confirmed that, yes, the program did in fact exist. But the company defended itself, saying that global workers didn't have direct access to the systems and that the escorts were given training on how to protect sensitive data. Plus they said they were following all the government's requirements.
Renee Dudley
One of their defenses of the arrangement is, this is government approved. This is US Government approved.
Jessica Lessenhop
If that was true, who approved it and why? Renee knew it must have been someone in the Defense Information Systems Agency. DISA for short. It's essentially the Department of Defense's IT agency. They're the ones who maintain the rules around the cloud for the department.
Renee Dudley
So she calls them PR people that I'm dealing with. You know, they'd never heard of it, seem skeptical. I'm kind of shuffled between a couple different communications people.
Jessica Lessenhop
Days go by, and eventually one of the PR contacts tells her that really nobody in the department knows what she's talking about.
Renee Dudley
He told me he'd reached out to more than three dozen people within DISA in his attempt to get information. And his quote was, literally, no one seems to know anything about this. So I don't know where to go from here. I'm thinking, even if nobody there now knows anything about this, there must be some paper trail, if you will.
Jessica Lessenhop
Hey, that's the name of the show,
Renee Dudley
of the existence of this thing.
Jessica Lessenhop
So Renee went back to Microsoft and told them the government is still saying they have no idea what this is. She says, surely there has to be some sort of document showing the government approved this. Right? Where could she find that proof?
Renee Dudley
Microsoft goes back to the drawing board and they get back to me to say, okay, we know where the paper trail is.
Jessica Lessenhop
The company tells Renee they have to periodically submit plans to show how they'll meet the government's requirements. And then the government has to accept them.
Renee Dudley
There's this report called the ccsrgssp. The ccsrgssp. And I'm like, okay, just rolls right off the tongue. Rolls right off the tongue. The Cloud Computing Security Requirements Guide System Security Plan.
Jessica Lessenhop
Microsoft tells Renee to go back to the government and tell them to look there. In the CCRGSSP thing, I go back to disa.
Renee Dudley
I said in this report, do a control find for escort, and you will see what Microsoft is talking about and that I'm talking about. And so a few more days go by and they provide a statement acknowledging the existence of digital escorts.
Jessica Lessenhop
In the statement, DISA said that foreign engineers didn't have, quote, direct hands on access to government systems and only provided recommendations. And they said cloud service providers like Microsoft were required to vet their specialists. I think there's so many things about this that are remarkable, including that what you managed to do here is prove that the government said yes to something without seemingly institutionally having any memory of that.
Renee Dudley
Yeah, this went across four different presidential administrations. This went through Obama, Trump 1, Biden and Trump 2 without anybody really raising an eyebrow about it.
Jessica Lessenhop
So this is kind of a nonpartisan screw up.
Renee Dudley
Yes. I will say, just as a matter of fairness, I didn't know then this came out later. I got a copy of that CCRG ssp. I actually got a copy of it and I could see what Microsoft actually told the government. And there was no mention of foreign engineers being used and definitely no mention of China.
Jessica Lessenhop
What Microsoft did describe in the document was a system of quote, escorted access. But that document wasn't clear about how it would all work.
Renee Dudley
Maybe nobody in the government had that conspiratorial mindset to assume the worst that the person being escorted could be a Chinese spy.
Jessica Lessenhop
Renee published the story about this Digital Escorts program.
Renee Dudley
ProPublica published findings of an investigation they conducted into a Microsoft computer system our Department of Defense uses to store sensitive information in cloud based storage.
Jessica Lessenhop
China's potential into DoD systems appears to be Microsoft employees based in China operating under oversight of under trained US based supervisors. And she says the story gets the fastest response she's ever gotten in her journalistic career.
Renee Dudley
It was pretty swift. I think there was just an immediate recognition of this is low hanging fruit for espionage. And this is something that we need to address right away. Members of Congress were posting online about it and directly asking Defense Secretary Pete Hegseth to do something about this. And by the end of the week that this story published, he had released a video directly addressing this situation. This is obviously unacceptable, especially in today's digital threat environment. Now this story was published on a Tuesday and on Friday Microsoft said it had stopped using China based engineers to support Defense Department cloud systems. I want to thank all those Americans
Jessica Lessenhop
out there in the media and elsewhere who raised this issue to our attention so we could address it.
Renee Dudley
The media meaning you, the media meaning me.
Jessica Lessenhop
And Secretary Hegseth is not a huge fan of the media writ large.
Renee Dudley
So it was a surprising end. To the week.
Jessica Lessenhop
After Rene's reporting was released, the Defense Department also opened up an investigation looking into whether any of Microsoft's China based engineers had compromised the government's national security. The Pentagon told her they can't comment on whether it turned up anything. But a few months after Rene's story came out, President Trump signed into law a measure that bans anyone based in China and other adversarial countries from accessing the Pentagon's Cloud systems. What about Tom Shiller, the guy who tipped you off to all of this? What was his response to all this?
Renee Dudley
Tom Shiller was delighted. This was the reaction that he'd been trying to get from the federal government for years. But I would say his delight was somewhat metered because I hadn't done enough to connect the dots between this situation and Barack Obama and Joe Biden. So, you know, can't please them all.
Jessica Lessenhop
Tom, thank you so much for joining me tonight. It's a pleasure to have you here.
Renee Dudley
Schiller went on to Laura Loomer's show
Jessica Lessenhop
of this hidden, dark, deep secret, a relic of the administration of Barack Hussein Obama. So I just want to give you the podcast. Loomer Unleashed featured Tom Schiller the Friday after Renee's story published.
Harry Coker
And it was Barack Obama's name and signature on all of it. He was the person that authorized everything, all of it, across the board. Nobody else, just him.
Renee Dudley
He got to air his conspiracies for two hours on Laura Loomer's show.
Jessica Lessenhop
So the agreements, conspiracies are different from journalism. The difference is facts. As a journalist, I am desperate to get the facts right. Our whole job is to uncover hidden facts and then we check them and then check them again and again and again and again. It's the root cause of my chronic insomnia. Which is all to say Renee did not find factual proof to back up the conspiracies Tom Schiller talked about on Laura Loomer's show.
Harry Coker
I think Microsoft and the Chinese government are in collaboration on this. I think that something nefarious is afoot.
Jessica Lessenhop
And just to be clear, like if you were able to prove what he was saying, like, oh, there actually is incredibly nefarious intent on the part of the Obama administration or the Biden administration or both administrations. Like, if you had proved that, you would have. But that's just not where the facts took you.
Renee Dudley
Of course, we just follow the facts where they take us and the evidence where it takes us. And that's what I did here.
Jessica Lessenhop
Renee continues to report on Microsoft and the government's adoption of private sector technology, including the rush to adopt artificial intelligence systems from private companies in sensitive settings.
Renee Dudley
In the AI age, there are seemingly fewer and fewer guardrails and the same concerns exist. You know, can I trust the company to do right by the public when it comes to the handling of this data? And story after story we've shown how Microsoft, but I would say corporations in general will prioritize their own profit over the needs and security of their customers and that makes a lot of people worry.
Julia Longoria
This episode was produced by Sabi Robinson and me, Julia Longoria Editing by Katherine Wells Sound design and mixing by David Herman Music by Julian Sartorius, Filippo Ansaldi and Simone Sims Longo, with additional music by Epidemic Sound. Our team also includes Gabrielle Burbe and Emma Tolkoff. Insight Global, the company that posted the job ad Rene found, said in a statement that it evaluates the technical capabilities of of all hires to make sure they have the right skills for the job and that they provide training on Microsoft policies. Microsoft says that security is a top priority. For full responses from Microsoft, Insight Global and the US Government, follow links to Renee's reporting in the show Notes. See you next time.
Megan
Hi, I'm Megan, I work in membership at ProPublica. I'm here because we're a non profit newsroom without a paywall, so everything we publish, including this podcast, is free. Our newsroom is also free from meddling owners, free from corporate interests and free from political pressure. Our business model protects our independence so nobody outside of our newsroom has power over what we publish and our reporters have the freedom to follow the facts wherever they lead, no matter whom they upset. We expose abuses of power because when the facts are clear, people can make real change. Help keep our journalism free and fearless for everyone. Give now@proPublica.org donate.
Host: Jessica Lussenhop (ProPublica)
Guest/Reporter: Renee Dudley
Release Date: July 9, 2026
This episode of Paper Trail explores ProPublica reporter Renee Dudley's investigation into a little-known Microsoft practice called "digital escorting." The episode exposes how this workaround—developed to satisfy U.S. government security rules—ended up introducing a sweeping vulnerability to Pentagon computer systems by allowing engineers based in China to participate in the upkeep of highly sensitive government IT infrastructure. The story traces how the vulnerability was discovered, confirmed, and ultimately changed Defense Department (DoD) policy, while also examining the blurry line between conspiracy and investigative journalism.
This episode demonstrates the power of dogged investigative journalism to uncover hidden, consequential risks in government use of private technology. The “digital escort” workaround, intended as a bureaucratic patch, proved a serious national security blind spot—one that no administration caught but changed swiftly once exposed. The reporting also powerfully illustrates the boundary between fact-based investigation and conspiracy, showing the immense public value in uncovering uncomfortable truths.
For the full story and supporting documents, see Renee Dudley’s published reporting at ProPublica.