Microsoft and Google collaborated to take down RedVDS, a cybercrime marketplace providing virtual machines used in phishing and business email compromise campaigns causing estimated losses of $66 million, highlighting the effectiveness of real-time shared threat intelligence.

  • RedVDS sold virtual machines for launching cyberattacks starting at $24 monthly.
  • Over 130,000 organizations targeted and 191,000 Microsoft accounts compromised between Sept-Dec 2025.
  • Global Signal Exchange enabled coordinated disruption across multiple jurisdictions.

What happened

Microsoft and Google worked together to dismantle RedVDS, an online marketplace that sold virtual machines used to facilitate cybercrime, including phishing and business email compromise schemes. These virtual machines were often deleted quickly after use, making them difficult to trace. The takedown involved seizing RedVDS domains and servers with support from law enforcement in Germany and Europol.

This cooperative action was supported by the Global Signal Exchange (GSE), a secure threat intelligence-sharing platform founded in the UK by Google and other partners. Microsoft's Digital Crimes Unit monitored RedVDS closely before court orders in the UK and US led to the seizure actions earlier in 2026, with Google suspending related accounts on its networks.

Why it matters

RedVDS played a significant role in a cybercrime ecosystem that caused around $66 million in losses to businesses and individuals. By offering cheap, scam-ready virtual machines for as little as $24 per month, RedVDS lowered the barrier to entry for cybercriminals to launch complex attacks, including phishing campaigns targeting Microsoft accounts.

The scale of the threat was vast, with over 130,000 organizations targeted and nearly 200,000 Microsoft email accounts compromised in a short period during 2025. This takedown not only disrupts a major fraud network but also demonstrates how real-time information sharing through platforms like GSE is crucial for combating increasingly sophisticated cybercrime supply chains.

What to watch next

Microsoft, Google, and other partners in the Global Signal Exchange, such as Meta and Amazon, plan to continue leveraging shared intelligence to identify and dismantle cybercriminal infrastructure. This model emphasizes collaboration across private sector security teams and international law enforcement to address fraud that transcends borders and organizational boundaries.

Observers should monitor how the GSE platform evolves and the impact of its intelligence-sharing capabilities on future cybercrime disruptions. Additional actions against similar marketplaces or scams, such as tech support impersonations, are likely to follow as these trusted networks improve threat detection and response times.

Source assisted: This briefing began from a discovered source item from TechRadar. Open the original source.
How SignalDesk reports: feeds and outside sources are used for discovery. Public briefings are edited to add context, buyer relevance and attribution before they are published. Read the standards

Related briefings