Signal sharing between Microsoft and Google has taken down RedVDS, a criminal marketplace linked to more than $66 million in reported US fraud losses. The exchange ran through the Global Signal Exchange (GSE), a non-profit platform that lets trusted organisations share threat data securely. In a second case run through the same platform, Google’s intelligence helped Microsoft shut down a scam campaign impersonating its own brand.

Fraud and scam networks are inherently fragmented. Criminals spread their operations across domains, cloud infrastructure, communication platforms and payment systems, so no single organisation ever sees the complete picture. GSE was built to close that gap, giving trusted organisations a secure, fast way to share what they know.

In January 2026, Microsoft’s Digital Crimes Unit, the team that investigates and takes legal action against cybercrime, disrupted RedVDS. The service sold cybercriminals access to virtual machines running unlicensed software, for as little as $24 a month. Attacks linked to it compromised more than 191,000 Microsoft email accounts across over 130,000 organisations between September and December 2025. Microsoft went to court in the US and UK to seize the marketplace’s web domains, then shared its threat data with Google through GSE. Google used that data to identify and suspend related accounts on its own platforms. German law enforcement seized RedVDS’s main server, and Europol acted against servers used by its customers across Europe. By February, active RedVDS servers had fallen by more than 95 per cent.

Emily Taylor, CEO at Oxford Information Labs and Co-Founder of the Global Signal Exchange, said: “Fraud does not respect company boundaries, and no single organisation ever sees the whole picture. That is exactly why we built GSE: to give trusted partners a secure way to share what they know, quickly. These two cases are a good example of GSE doing exactly what it was designed to do.”

In a separate case, Google identified a tech support scam impersonating Microsoft, targeting victims in English, Japanese and French and referred the matter to US law enforcement. It shared around 300 indicators of compromise, the digital fingerprints of an attack, including malicious domains and URLs, with Microsoft through GSE. Microsoft confirmed the scale of the abuse of its own brand, shut down the infrastructure behind the campaign, and referred the case to law enforcement in the United States.

Both companies say they intend to keep sharing intelligence through GSE as new fraud campaigns emerge.

By admin

Leave a Reply

Your email address will not be published. Required fields are marked *