In late 2024, ProPublica reporter Renee Dudley got an eye-opening tip from a new source. Microsoft, the largest provider of IT services to the federal government, was “rerouting support and a lot of functionality through China to save money.”
This person said they knew nothing else about the matter, which they had heard from someone inside Microsoft. It sounded preposterous. Federal agencies have strict security requirements mandating that only U.S. citizens or permanent residents have access to sensitive computer systems. Moreover, top intelligence officials had called China the “most active and persistent cyber threat” to the U.S. government. The risk wasn’t just theoretical. Chinese state-sponsored hackers had recently infiltrated federal computer systems.
While the tip seemed unbelievable, Dudley also knew that Microsoft had a history putting corporate profit over customers’ security. In 2024, she exposed how the tech giant had for years ignored internal warnings about a weakness in a widely used product, fearful that addressing it would cost the company lucrative government contracts. As ProPublica reported then, Russian hackers would go on to exploit that very flaw in one of the largest cyberattacks to ever strike the federal government.
So Dudley worked the tip, calling existing sources in tech and the government and finding new ones. What she discovered in 2025 shook the Pentagon, exposed a national security crisis and changed U.S. policy.
Microsoft was indeed using China-based engineers to maintain Defense Department computer systems — a practice that flouted federal policy and left some of the nation’s most sensitive data vulnerable to hacking from its leading cyber adversary.
The arrangement relied on U.S. citizens with security clearances to oversee the foreign employees’ work. But Dudley found that these “digital escorts” often lacked the technical expertise to fully understand and police what the China-based engineers, with far more advanced skills, were actually doing. The system, which had been in place for nearly a decade, created the opportunity for hacking and espionage.
In 2026, Dudley explored how such a serious threat could escape federal detection for so long. She found the government’s cybersecurity and risk management program, known as FedRAMP, to be weak, with regulators deferring to Microsoft even in the face of serious concerns about the integrity of its products. “This is not security,” one prominent expert said of ProPublica’s findings. “This is security theater.”
The pioneering work, which took readers inside the high-stakes review of a widely-used cloud offering, revealed the government’s significant shortcomings in evaluating new technology — a troubling finding given the rapid adoption of cloud-based artificial intelligence among federal agencies.