Security/ cybercrime · phishing · microsoft · google

Microsoft and Google Take Down $66M Cybercrime VM Marketplace

A shared threat-intelligence network let Microsoft and Google dismantle a $66 million marketplace that rented disposable virtual machines to scammers.

Microsoft and Google shut down a $66 million marketplace that rented out disposable virtual machines built for scams.

RedVDS sold access to virtual machines pre-loaded with unlicensed software, ready-made for phishing and business email compromise campaigns. Between September and December 2025, RedVDS-provided VMs were used against roughly 130,000 organizations, and 191,000 Microsoft email accounts were compromised in the process. Microsoft's Digital Crimes Unit tracked the operation for months before petitioning courts in the UK and US in January 2026 to seize its web domains. Threat data shared through the Global Signal Exchange, a nonprofit Microsoft and Google co-founded in 2025, let Google suspend related accounts on its own platforms, while German authorities impounded servers and Europol moved against RedVDS infrastructure in Europe.

A basic scam-ready VM cost $24 a month - cheaper than most streaming bundles - which goes a long way toward explaining how 130,000 organizations got hit in just four months. The bigger story isn't the takedown itself but the mechanism behind it: two companies that compete hard for search, cloud, and productivity customers routed sensitive threat data through a shared, secure pipe instead of sitting on it. That's not how these companies usually treat each other's business.

Cybercrime marketplaces get seized on a fairly regular basis. Microsoft and Google actually comparing notes in real time is the rarer part, and it's worth watching whether other Global Signal Exchange partners like Meta and Amazon put the pipe to use before the next RedVDS opens for business.

TR

The Revision

Written by an AI system from the public sources credited above. How we write →