On January 14, 2026, Microsoft announced coordinated legal action against RedVDS, a marketplace that rented virtual servers used for phishing, business email compromise and payment fraud. The operation involved legal action in the United States and United Kingdom, the seizure of two domains, a server seizure by German authorities and cooperation with Europol.

The operation targeted RedVDS infrastructure

Microsoft said the two seized domains hosted the RedVDS marketplace and its customer portal. German authorities seized a critical server used to power the central marketplace. Europol worked with Microsoft to disrupt Europe-based servers and payment networks that supported RedVDS customers.

The action focused on the service’s infrastructure. Microsoft did not say that every server, domain or customer was removed.

RedVDS rented servers, not malware

RedVDS was a cybercrime marketplace and virtual dedicated server provider. It rented Windows-based remote desktop servers with administrator access and no usage limits. Customers installed their own tools, which included mass-mailing software, email harvesters, phishing kits and privacy tools. RedVDS itself supplied the hosting infrastructure; the customers operated their campaigns.

Microsoft said RedVDS launched publicly in 2019 and identified its operator as Storm-2470. The service used cloned Windows Server 2022 images and automated provisioning with QEMU virtualization and VirtIO drivers to create virtual machines.

How criminals used the servers for payment fraud

Business email compromise, or BEC, is a form of fraud in which criminals misuse or impersonate business email accounts to deceive organizations into sending money. RedVDS servers supported several steps in that process: attackers researched targets, sent phishing messages, stole credentials or session tokens, and monitored compromised mailboxes.

Access to a mailbox could reveal pending payments, suppliers and ongoing email threads. Criminals could then impersonate a trusted contact, request a change to payment instructions and divert the funds. Phishing and account takeover were also among the reported uses of the servers.

Microsoft’s reported reach

Microsoft said that, during one observed month, more than 2,600 RedVDS virtual machines sent an average of one million phishing messages per day to Microsoft customers. The company also attributed roughly $40 million in reported U.S. fraud losses to RedVDS-enabled activity since March 2025.

Microsoft identified activity affecting more than 9,000 real-estate customers, with particularly severe impact in Canada and Australia.