Cybersecurity News and Headlines
  • All Technology
  • AI
  • Autonomy
  • B2B Growth
  • Big Data
  • BioTech
  • ClimateTech
  • Consumer Tech
  • Crypto
  • Cybersecurity
  • DevOps
  • Digital Marketing
  • Ecommerce
  • EdTech
  • Enterprise
  • FinTech
  • GovTech
  • Hardware
  • HealthTech
  • HRTech
  • LegalTech
  • Nanotech
  • PropTech
  • Quantum
  • Robotics
  • SaaS
  • SpaceTech
AllNewsDealsSocialBlogsVideosPodcastsDigests

Cybersecurity Pulse

EMAIL DIGESTS

Daily

Every morning

Weekly

Sunday recap

NewsDealsSocialBlogsVideosPodcasts
CybersecurityNewsRedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement
RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement
Cybersecurity

RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

•January 14, 2026
0
SecurityWeek
SecurityWeek•Jan 14, 2026

Companies Mentioned

Microsoft

Microsoft

MSFT

Cloudflare

Cloudflare

NET

Why It Matters

The disruption curtails a low‑cost infrastructure that fuels large‑scale phishing and business‑email compromise, protecting millions of users and reducing financial losses. It also showcases the growing power of public‑private partnerships in dismantling cybercrime‑as‑a‑service ecosystems.

Key Takeaways

  • •RedVDS sold VDS for $24 monthly subscription.
  • •$40 million fraud losses linked to RedVDS in US.
  • •2,600 VMs sent one million phishing emails daily.
  • •191,000 Microsoft accounts compromised across 130,000 organizations.
  • •Microsoft seized domains, servers, and disrupted payment networks.

Pulse Analysis

RedVDS exemplifies the evolution of cybercrime‑as‑a‑service, offering cheap, ready‑to‑use Windows virtual dedicated servers that lower the barrier for threat actors. By cloning a single Windows Server 2022 image, the operators created a fingerprint that allowed Microsoft to track 2,600 active machines sending roughly one million phishing emails each day. This scale amplified business‑email compromise campaigns, generating $40 million in U.S. losses and exposing over 191,000 Microsoft accounts across a broad industry spectrum.

The coordinated takedown underscores how tech giants and law‑enforcement agencies can jointly cripple illicit infrastructure. Microsoft’s seizure of RedVDS domains, customer portals, and payment channels, coupled with legal actions in the United States and the United Kingdom, mirrors the recent disruption of the RaccoonO365 service. These moves not only dismantle the immediate threat but also send a deterrent signal to other cybercrime‑as‑a‑service operators that their revenue streams are vulnerable to swift, cross‑border enforcement.

For enterprises, the RedVDS case highlights the importance of advanced telemetry and threat‑intelligence integration. Detecting common VM images or certificate anomalies can reveal hidden malicious infrastructure before large‑scale attacks materialize. Organizations should bolster email security, enforce multi‑factor authentication, and monitor for atypical remote‑access tools. As cybercriminals increasingly leverage commoditized services and AI‑enhanced tools, continuous collaboration between the private sector and regulators will be essential to stay ahead of the evolving threat landscape.

RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement

Read Original Article
0

Comments

Want to join the conversation?

Loading comments...