How Microsoft and Google Shut Down a $66M Cybercrime VM Marketplace

Discover how Microsoft and Google collaborated via the Global Signal Exchange to dismantle RedVDS, a cybercrime marketplace selling scam-ready virtual machines.

How Microsoft and Google Shut Down a $66M Cybercrime VM Marketplace
Sarah Collins

Sarah Collins

Computing Editor

Specializes in PCs, laptops, components, and productivity-focused computing tech.

What Was RedVDS and Why Did It Matter?

RedVDS operated as a cybercriminal marketplace that rented virtual machines (VMs) loaded with unlicensed software to fraudsters. These VMs enabled cyberattacks such as phishing and business email compromise, offering quick deployment and easy deletion to avoid detection. Between September and December 2025, RedVDS-facilitated attacks targeted over 130,000 organizations, compromising nearly 200,000 Microsoft email accounts. Access began at as low as $24 per month, creating a lucrative underground service that caused an estimated $66 million in losses.

Why Did Collaboration Between Tech Giants Make a Difference?

Microsoft, Google took down $66 million cybercrime marketplace that sold  virtual machines with free software | TechRadar
Microsoft, Google took down $66 million cybercrime marketplace that sold virtual machines with free software | TechRadar

Microsoft and Google partnered through the Global Signal Exchange (GSE), a secure platform created to share threat intelligence in real time. This sharing enabled both companies to trace suspicious accounts and operations linked to RedVDS rapidly. Microsoft’s Digital Crimes Unit spearheaded the investigation and achieved legal domain seizures in the UK and US. Google followed by suspending related accounts on its platforms. Additionally, European law enforcement seized RedVDS servers, further crippling the operation.

This level of cross-company and cross-border cooperation was crucial because cybercrime ecosystems often span multiple organizations and jurisdictions. No single entity would have the full picture or leverage to intervene effectively alone.

What Does This Mean for Cybercrime Defenses?

The takedown highlights how sharing real-time threat data can dismantle large-scale criminal infrastructures. Beyond simply reacting to attacks, coordinated data exchange helps organizations detect patterns, identify criminal infrastructure, and mobilize resources quickly. For users and organizations, this underscores the growing importance of collaborations among technology companies and law enforcement as a frontline defense against evolving cybercrime marketplaces.

At the same time, it shows that attackers are innovating by offering easy-to-use services such as ready-made VMs for cybercriminals. This requires defenders to continuously enhance monitoring and enforcement capabilities.

Takeaway: Collaboration Is Key to Fighting Cybercrime Marketplaces

The swift disruption of RedVDS was made possible by Microsoft and Google’s strategic use of a secure threat intelligence platform, demonstrating that shared visibility across complex cybercrime supply chains is essential to effective defense. Organizations should remain vigilant, support information-sharing initiatives, and recognize that fighting sophisticated attacks is a collective effort that crosses corporate and national boundaries.

React to this story

Related Posts