A whistleblower, a former Microsoft employee, claims that the company prioritized profit over security, ignoring his warnings about a critical flaw in one of its products, which was later exploited by Russian hackers in a major cyberattack. The flaw, discovered in 2016, allowed attackers to masquerade as legitimate employees and access sensitive data without tripping alarms. Microsoft allegedly dismissed the warnings to avoid jeopardizing a potential multibillion-dollar deal with the federal government. The company's security culture has been criticized, with some arguing that it prioritizes profit over security.