Microsoft and Google Dismantled RedVDS Cybercrime Ring
The coordinated takedown disabled a marketplace that compromised over 190,000 email accounts in 2025.
Updated on Sept. 21, 2026 in Cybersecurity

Live Poll
Do you trust that large technology companies adequately protect your accounts from cybercrime threats?
In January 2026, Microsoft and Google dismantled the RedVDS cybercrime marketplace by seizing web domains and impounding servers in Germany. The platform provided infrastructure for phishing and business email compromise attacks.
Why it matters
The takedown highlights the effectiveness of private-sector threat intelligence sharing through the Global Signal Exchange. This collaboration directly disrupted a hub that facilitated automated cyberattacks on a massive scale.
RedVDS sold virtual machines configured for malicious activity at a cost of $24 per month. The platform facilitated automated attacks that targeted 130,000 organizations between September and December 2025.
The players
Microsoft
A global technology company providing cloud computing, productivity software, and threat intelligence through its Digital Crimes Unit.
An international search and cloud services provider that collaborated to suspend accounts linked to the malicious marketplace.
Europol
The European Union law enforcement agency that executed the physical seizure of infrastructure in Germany.
Global Signal Exchange
A UK-based non-profit founded in 2025 to facilitate the cross-organizational sharing of threat intelligence data.
The details
Microsoft Digital Crimes Unit — an internal team that tracks and disrupts cybercrime networks — monitored the marketplace to identify the backend infrastructure. By leveraging threat data shared through the Global Signal Exchange, a UK-based non-profit, the companies coordinated with Europol to seize control of server architecture and web domains in the United States and Germany. These actions effectively cut off the virtual machines used for business email compromise, a technique where attackers impersonate corporate entities to solicit fraudulent payments.
Timeline
September to December 2025: RedVDS targeted 130,000 organizations and compromised 191,000 email accounts.
2025: The Global Signal Exchange was co-founded.
January 2026: Microsoft applied to seize the RedVDS web domains.
The Tech Race
The operation validates the collaborative model championed by the Global Signal Exchange as a primary defense against scalable cybercrime. It marks a shift away from isolated corporate responses toward unified, multi-platform intervention against infrastructure-as-a-service providers.
The disruption of RedVDS reduces the prevalence of automated phishing campaigns that target corporate and individual email accounts. Users should continue to monitor account activity and enable multi-factor authentication to protect against residual risks associated with compromised credentials.
The takeaway
This operation shows that disrupting the underlying infrastructure of cybercrime is more effective than mitigating individual attacks. Readers should monitor future threat reports from the Global Signal Exchange to see if similar coordinated takedowns impact other high-volume marketplace platforms.
Further reading
For more context on how industry leaders monitor and mitigate digital threats, visit our Cybersecurity section.
Live Poll
Do you trust that large technology companies adequately protect your accounts from cybercrime threats?






