Microsoft’s Digital Crimes Unit has disrupted a major cyber-crime-as-a-service network – RedVDS – after it obtained court orders in the UK and Florida.
This coordinated major legal action between the US and the UK Microsoft’s DCU has taken; it relied on the UK legal system as the RedVDS infrastructure was hosted on a UK-based provider, with many of the networks’ victims also residing in the UK.
RedVDS provided threat actors with disposable virtual computers that could be used to securely expand their operations for as little as £18 a month.
In its investigation, DCU estimated that the cyber-criminals using RedVDS compromised over 191,000 organisations since September 2025, profiting at least $40m in just the uS.
Threat actors used RedVDS for a range of cyber-crime, from phishing scams to fraudulent infrastructure, and but seemed to be most proficient at business email compromise.
RedVDS was also often used in conjunction with AI to better identify multiple targets and to enhance phishing lures, and create deepfakes for scams.
The use of RedVDS appears prolific. with over 2,600 distinct RedVDS virtual machines sending an average of one million phishing message per day to Microsoft customers alone.
The subscription service appears to be fuelling cyber-crime hitting a range of sectors, from real estate to construction, manufacturing, healthcare, education, logistics, and legal services.
Taking down this cyber-crime service syndicate involved working with Europol’s European Cybercrime Centre, as well as support from the German cyber-crime and criminal authorities.
Recommended
- UK Scam and Fraud Complaints Reach Record Highs
- Fraud-as-a-Service Driving ‘Mega’ Cyber-attacks
- ICO: Data Protection Not An Excuse When Tackling Scams, Fraud
“Cyber-crime today is powered by shared infrastructure, which means disrupting individual attackers is not enough,” Steven Masada, assistant general counsel, Microsoft’s Digital Crimes Unit, said.
“Through this coordinated action, Microsoft has disrupted RedVDS’s operations, including seizing two domains that host the RedVDS marketplace and customer portal, while also laying the groundwork to identify the individuals behind them.”





