SecurityBrief New Zealand - Technology news for CISOs & cybersecurity decision-makers
New Zealand
Microsoft & Google use shared exchange to hit RedVDS

Microsoft & Google use shared exchange to hit RedVDS

Wed, 16th Sep 2026 (Today)
Sean Mitchell
SEAN MITCHELL Publisher

Microsoft and Google have used the Global Signal Exchange to disrupt RedVDS, a criminal marketplace linked to more than USD $66 million in reported US fraud losses. The action marks two separate enforcement cases carried out through the non-profit threat-sharing platform.

In one case, Microsoft's Digital Crimes Unit moved against RedVDS, which sold cybercriminals access to virtual machines running unlicensed software from as little as USD $24 a month. Microsoft shared threat data with Google through the Global Signal Exchange, enabling Google to identify and suspend related accounts on its platforms.

German law enforcement seized RedVDS's main server, while Europol acted against servers used by its customers across Europe. By February, active RedVDS servers had fallen by more than 95 per cent.

According to the companies, attacks linked to RedVDS compromised more than 191,000 Microsoft email accounts across more than 130,000 organisations between September and December 2025. The reported USD $66 million figure refers to US fraud losses linked to RedVDS activity since March 2025.

Two cases

A second investigation shared through the same platform involved a tech support scam impersonating Microsoft. Google identified the campaign, which targeted victims in English, Japanese and French, and referred the matter to US law enforcement.

It passed about 300 indicators of compromise to Microsoft through the Global Signal Exchange, including malicious domains and URLs. Microsoft confirmed the scale of the abuse of its brand, shut down the infrastructure behind the campaign and supplied additional evidence to support the law enforcement case.

The cases show how fraud operations often rely on multiple providers and services, making it difficult for any one company to map the full network behind an attack. Threat actors commonly spread activity across domains, cloud services, communications tools and payment systems, leaving each organisation with only part of the picture.

The Global Signal Exchange was created to address that problem by allowing accredited organisations to share abuse and threat data through a common system. Oxford Information Labs, the UK-based group behind the exchange, said the platform now tracks more than 350 million threat signals in real time, with Google, Meta, Microsoft and 30 other international organisations among its members.

In the RedVDS investigation, Microsoft also went to court in the US and UK to seize the marketplace's web domains. It continued to monitor RedVDS infrastructure after the disruption and removed it through its Statutory Automated Disruption programme.

Shared intelligence

The wider significance of the RedVDS case lies in how the operation was dismantled through a mix of legal orders, technical action, law enforcement intervention and cross-platform intelligence sharing. Rather than focusing only on the marketplace itself, the effort also targeted the infrastructure used by RedVDS customers.

That approach reflects the structure of modern fraud and cybercrime networks, which are built to absorb isolated takedowns. Operators often rely on distributed hosting, multiple intermediaries and shifting criminal partnerships, allowing activity to reappear quickly when one part of the chain is removed.

The use of generative AI tools has added another layer to that environment. The companies said scam services are increasingly using voice cloning, video manipulation and face-swapping tools to improve fraud and impersonation schemes.

Emily Taylor, Chief Executive Officer at Oxford Information Labs and Co-Founder of the Global Signal Exchange, said: "Fraud does not respect company boundaries, and no single organisation ever sees the whole picture. That is exactly why we built GSE: to give trusted partners a secure way to share what they know, quickly. These two cases are a good example of GSE doing exactly what it was designed to do."

Microsoft and Google presented the exchange as a standing channel for sharing signals on related and emerging campaigns. In the RedVDS case, Google could act on intelligence gathered during Microsoft's investigation without waiting for a separate bilateral process. In the Microsoft impersonation scam, Google's findings gave Microsoft evidence to shut down associated infrastructure.

The two cases also show how large technology groups are relying more heavily on shared intelligence to tackle abuse that crosses platforms and jurisdictions. With law enforcement, cloud providers, domain operators and communications services each holding only part of the record, centralised exchanges such as GSE are being used to turn those fragments into an actionable picture.