The ICC's Chief Prosecutor Got Locked Out of His Own Email — Then the Court Moved 1,800 Workstations Off Microsoft

In May 2025, Karim Khan — the Chief Prosecutor of the International Criminal Court — lost access to his own Outlook account. Six months later, the Court he works for had migrated roughly 1,800 workstations off Microsoft 365 entirely, onto an open-source suite built by a German state-owned company. Microsoft spent the months in between denying it had done anything, then in February 2026 had to ask the UK Parliament to correct testimony one of its own executives had given about the incident.
Most coverage of this story files it under "CLOUD Act risk." That's not quite right, and the actual mechanism is worth understanding precisely — because it's a different, and in some ways sharper, threat model than the one most EU vendor-risk checklists are built around.
What actually happened, in order
February 6, 2025 — President Trump signed Executive Order 14203, "Imposing Sanctions on the International Criminal Court". The order invokes the International Emergency Economic Powers Act (IEEPA), the National Emergencies Act, and Section 212(f) of the Immigration and Nationality Act, declaring that ICC efforts to "investigate, arrest, detain, or prosecute" people the order calls "protected persons" (US citizens, military personnel, and citizens of NATO/major non-NATO allies, among others) constitute "an unusual and extraordinary threat to the national security and foreign policy of the United States." It authorizes blocking the US property of designated individuals and suspending their US entry.
February 10, 2025 — The Treasury Department published the order's annex. Human Rights Watch reported that it named exactly one person: "Karim Khan, Prosecutor of the ICC" — the first individual designated under the new order.
May 2025 — Khan lost access to his Microsoft-hosted email. The Associated Press first reported it; Khan reportedly moved to Swiss-based Proton Mail to keep working. Microsoft's own account of what happened conflicts with this: Techzine reported that Microsoft President Brad Smith said the company "remained in contact with the ICC to keep services up and running" and denied suspending anything — implying the ICC itself made the access change, not Microsoft.
October 30–31, 2025 — Handelsblatt first reported that the ICC had decided to replace Microsoft 365 entirely. The Register confirmed the ICC acknowledged the migration on request, though a spokesperson declined to elaborate. Microsoft's on-record response at the time: "We value our relationship with the ICC as a customer and are convinced that nothing impedes our ability to continue providing services to the ICC in the future."
November 7–14, 2025 — Further reporting filled in scope. Open Source For You reported roughly 1,800 workstations affected, moving to openDesk — a suite combining Collabora Online (documents), the Open-Xchange App Suite (email/calendar), and Nextcloud (file storage), hosted under European legal jurisdiction. Heise independently confirmed the same ~1,800-workstation figure via separate Handelsblatt sourcing. The EU Commission's own Interoperable Europe Portal logged the ICC spokesperson's confirmation on November 14, 2025, and framed the move explicitly as addressing "critical dependency in IT" in favor of solutions offering "transparency, customisability and independence."
February 18, 2026 — The saga's most recent turn: The Register reported that Microsoft asked the UK's House of Commons Business and Trade Committee to correct testimony given by Hugh Milward, Microsoft's senior director of corporate, external and legal affairs, who had told the committee it was the ICC — "not Microsoft" — that decided to turn off Khan's email. The committee's own published transcript records Milward's evidence as originally spoken, with no correcting note appended — leaving the "who actually flipped the switch" question formally unresolved fourteen months after the fact.
Why "CLOUD Act case" is the wrong label
It's an understandable shorthand, but it blurs two legally distinct US mechanisms that EU developers should be able to tell apart, because they trigger under different conditions and demand different mitigations.
The CLOUD Act (2018) lets US law enforcement compel a US-headquartered provider to hand over data it controls, regardless of where the servers physically sit. The risk it creates is disclosure: a US court order can reach data hosted in Frankfurt if the parent company is American. This is the mechanism behind most "is my SaaS vendor US-owned" vendor-risk checklists, including our own indie-developer framework.
What actually happened to Khan's account is different. It's sanctions law — specifically IEEPA-based OFAC designation. As one legal analysis of the case at EJIL:Talk put it, "US 'persons' (which includes a 'corporation, group, subgroup, or other organization') cannot fall under sanctions themselves. Yet they cannot provide services to sanctioned foreign person(s) lest they face substantial civil and criminal penalties." Once Khan was on OFAC's designated-persons list, any US company — including Microsoft — was legally barred from transacting with him without a specific license, on pain of criminal exposure for the company itself. National Law Review's legal explainer confirms the order blocks the designated person's US-reachable property and imposes travel restrictions, with the Treasury Secretary required to report on additional designees within 60 days — a mechanism built to expand, not a one-off.
The distinction matters because the risk profile is opposite in an important way:
| CLOUD Act | IEEPA / OFAC sanctions | |
|---|---|---|
| What's at risk | Data gets disclosed to US authorities | Service gets cut off entirely |
| Who triggers it | A US court order tied to an investigation | The executive branch designating a person or entity |
| What EU hosting fixes | Nothing — parent-company jurisdiction is what matters, not server location | Nothing — same reasoning, plus the vendor itself faces criminal liability for continuing to serve you |
| What actually mitigates it | A vendor with no US parent entity | A vendor with no US parent entity, and not depending on your own legal/political exposure as a customer |
| Contractual protection | SLA terms rarely address this explicitly | Force majeure / legal-compliance clauses typically let the vendor terminate immediately, no cure period |
A sanctions freeze is arguably the sharper of the two for one reason: a CLOUD Act disclosure order still leaves your service running while your data gets read by someone else. A sanctions designation can turn your provider off overnight, with the provider's own general counsel actively motivated to comply fast, because they are the one facing criminal exposure if they don't. Khan didn't lose confidentiality — he lost access, full stop, in the middle of doing his job.
Who else is exposed — and why "EU-hosted" alone doesn't help
The ICC is an unusually visible case because a head of state's government sanctioned a sitting international prosecutor by name. But the underlying mechanism generalizes to anyone whose organization, customers, or mission puts them at odds with US foreign policy at a given moment: human rights NGOs, journalists covering sanctioned regimes, law firms representing sanctioned clients, and increasingly any entity that becomes a target of a fast-moving executive order. None of that requires being a household name — OFAC's SDN list runs to thousands of entries, and the ICC episode shows how quickly a newly designated individual's daily tools can disappear.
Crucially, choosing a US hyperscaler's EU region does not fix this. If the vendor is a US-incorporated legal entity, that entity remains bound by IEEPA and OFAC rules regardless of which data center runs the workload — the constraint lives at the corporate-entity level, not the infrastructure level. This is the same jurisdiction logic Airbus acted on when it moved 900 applications off AWS, just triggered by a different legal mechanism than the CLOUD Act exposure that decision was about.
A three-question vendor-risk framework beyond "where is my data hosted"
Most EU sovereignty checklists stop at data residency. The ICC case is a clean argument for going one step further:
- Where is the data stored? (Residency — necessary, but this case shows it's not sufficient. Khan's mailbox residency was irrelevant to whether Microsoft could keep serving him.)
- What is the vendor's legal jurisdiction of incorporation, and does it have a US parent? This is the question that actually determines both CLOUD Act and sanctions exposure. A vendor incorporated and controlled entirely within the EU, with no US parent entity, is structurally outside both mechanisms — not because of a policy promise, but because IEEPA and the CLOUD Act only reach "US persons."
- Does your own organization or customer base carry elevated sanctions/export-control exposure? This is the question the CLOUD Act framework doesn't ask at all. If your product serves journalists, NGOs, sanctioned-jurisdiction diaspora communities, or anyone whose work could plausibly intersect a future executive order, your vendor's incorporation status matters even more than usual — because unlike a CLOUD Act disclosure order (which needs an active investigation), a sanctions designation can arrive with no advance notice and force an immediate compliance-driven shutdown on the vendor's side.
What openDesk actually is, for developers evaluating the same move
Beyond the geopolitics, the ICC's chosen replacement is worth a closer look for anyone considering a similar self-hosted stack. openDesk is developed by ZenDiS (Center for Digital Sovereignty), a company wholly owned by the German federal government, originating from a Federal Ministry of the Interior initiative and launched as a product in October 2024. It bundles three separately maintained open-source projects rather than building a monolith from scratch: Collabora Online for document editing, the Open-Xchange App Suite for email and calendaring, and Nextcloud for file storage and sharing — each independently self-hostable, and each with an existing track record outside the openDesk bundling. Heise's reporting notes other German public bodies (the Public Health Service, and the Armed Forces under a separate framework agreement) have adopted the same stack, suggesting the ICC's move slots into a broader public-sector pattern rather than a one-off reaction.
For a small team, the practical takeaway isn't "go deploy openDesk" — it's that every component in that stack (Nextcloud, Collabora, Open-Xchange) is independently self-hostable on ordinary EU infrastructure, without waiting for a national digital-sovereignty agency to bundle it for you. If your organization's risk profile includes the sanctions-exposure question above, a self-hosted stack on an EU-incorporated PaaS removes the vendor-entity variable from the equation entirely — the same logic sota.io applies to hosting the application layer itself.
The unresolved thread
Fourteen months after Khan's account went dark, the basic factual question — did Microsoft cut the connection, or did the ICC do it under duress — remains formally unsettled in the public record. Microsoft's own witness told UK Parliament one version; Microsoft's leadership later asked for that testimony to be corrected without providing a replacement account of what happened. For a case study in vendor risk, that's the most useful detail of all: even the affected parties can't produce an agreed timeline of who did what to whom, which is exactly the kind of uncertainty a sanctions-exposed customer cannot afford to discover for the first time during an actual incident.
See also
- EU Cloud Sovereignty for Indie Developers: What the CLOUD Act Actually Means for Your Stack — the jurisdiction framework this post builds on
- Airbus's AWS Exit: What Enterprise Cloud Sovereignty Means for Developers — the same "US parent entity, not server location" logic applied to a CLOUD Act-driven decision
- Coolify vs sota.io: EU-Incorporated PaaS Without the CLOUD Act Story — what "no US parent" looks like in practice for a hosting vendor
EU-Native Hosting
Ready to move to EU-sovereign infrastructure?
sota.io is a German-hosted PaaS — no CLOUD Act exposure, no US jurisdiction, full GDPR compliance by design. Deploy your first app in minutes.