Microsoft automatically suspended developer accounts used by several high-profile projects — including WireGuard, VeraCrypt, MemTest86, and Windscribe — after they did not complete a mandatory Windows Hardware Program verification process, cutting off their ability to sign drivers, submit releases, and publish Windows builds. Developers said the suspensions arrived without clear warning or explanation and left them unable to reach effective human support, disrupting normal release processes for software relied on by security- and privacy-conscious users.
WireGuard creator Jason Donenfeld said the lockout prevented him from shipping updates to Windows users and warned that a future critical flaw could leave users exposed until access was restored, although he said no such vulnerability currently exists. Microsoft said the suspensions were tied to account verification requirements introduced in 2024 and later acknowledged that suspended partners could no longer submit releases; after public reporting, company executives said the issue would be addressed, and affected developers including VeraCrypt and Windscribe reported that Microsoft had begun outreach to help restore access.

See attribution, scope, and your downstream exposure.
8 events from the most recent confirmed update back to the earliest known activity.
Microsoft introduced a temporary fast-track process to restore access for recently suspended Windows Hardware Program accounts after complaints from affected developers. Under the process, developers must open a support case with a business justification, and Microsoft may reinstate access while remaining verification issues are resolved.
Following media attention, Microsoft Vice President Scott Hanselman said the problem would be addressed. Jason Donenfeld said he had finally made contact with Microsoft, while VeraCrypt and Windscribe also confirmed outreach to help restore access.
After the issue drew attention, Microsoft said the suspensions were automated and linked to the mandatory account verification process. The company also clarified that suspended accounts could no longer submit releases.
Reporting showed that VeraCrypt, Windscribe, and MemTest86 were also affected by Microsoft account suspensions, temporarily blocking their ability to publish Windows builds and security updates. Developers said they received little explanation and struggled to reach Microsoft support.
WireGuard creator Jason Donenfeld disclosed that Microsoft had locked him out of the developer portion of his account, stopping him from signing drivers and shipping WireGuard updates to Windows users. He said he had received no notification before the suspension and warned this could delay urgent security fixes if one were needed.
Accounts that had not completed the required Windows Hardware Program verification since April 2024 were automatically suspended, preventing some developers from signing drivers and submitting Windows releases. Affected projects included WireGuard, VeraCrypt, MemTest86, and Windscribe.
Microsoft started enforcing mandatory identity verification for Windows Hardware Program partners on 2025-10-16, giving accounts 30 days to comply before suspension. This enforcement step set up the later automatic lockouts of unverified developer accounts.
Microsoft announced a mandatory verification process for Windows Hardware Program partner accounts. The company said accounts that did not complete verification would be automatically suspended after 30 days.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
7 references tracked. Mallory keeps watching after this page renders.
bleepingcomputer.com
Open sourceghacks.net
Open sourcezdnet.fr
Open sourcecybersecuritynews.com
Open sourceinfoworld.com
Open sourcebleepingcomputer.com
Open sourcetechcrunch.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.