How Signal Sharing Between Microsoft and Google Took Down a $66M Fraud Marketplace

How Signal Sharing Between Microsoft and Google Took Down a $66M Fraud Marketplace

Fraud and scam ecosystems are inherently fragmented. Threat actors leverage a complex mix of domains, cloud infrastructure, email services, communication platforms, payment mechanisms, advertising networks, and identity providers to identify victims, facilitate engagement, and monetize fraud schemes. As a result, no individual organization has a complete view of an actor's activity or the full scope of an emerging threat campaign. This fragmentation creates a significant challenge for defenders. Effective fraud disruption increasingly depends on the ability of platform providers to share indicators of compromise (IOCs), correlate activity observed across different ecosystems, and rapidly act on complementary intelligence.

The Global Signal Exchange (GSE) was designed to address this challenge by providing a secure, compliant, and scalable mechanism for sharing actionable threat signals among trusted participants. By reducing operational and legal friction associated with bilateral information sharing, GSE enables organizations to quickly combine their unique visibility, build a more complete picture of malicious activity, accelerate disruption actions, and provide stronger evidence packages to support law enforcement investigations. The following case studies demonstrate how cross-platform IOC sharing through GSE has enabled Microsoft and Google to disrupt fraud infrastructure, protect consumers, and strengthen collective defense against evolving scam and fraud campaigns.

Case Study 1: Tech Support Fraud — Corroborating Evidence Through IOC Sharing via GSE

Google identified an active tech support fraud (TSF) campaign, which utilized malicious websites to impersonate Microsoft for the purpose of defrauding consumers under the guise of legitimate technical support services. The campaign targeted victims across multiple languages, including English, Japanese and French. Google shared approximately 300 Indicators of Compromise (IOCs) associated with the TSF campaign through the GSE to Microsoft, including malicious domains, and URLs linked to threat actors. Google also referred the matter to law enforcement in the United States.

Upon ingesting these signals, Microsoft was able to ascertain the significant misuse of Microsoft’s brands and trademarks by this large-scale TSF campaign. As a response, Microsoft conducted further investigations, suspended malicious technical infrastructure leveraged for this campaign and provided supplemental findings to law enforcement enabling a more complete and credible multi-source evidence package to support potential legal action against the actors involved.

GSE was the critical enabler throughout, providing both parties with a secure, compliant mechanism, which can be set up and configured within a few clicks on the platform, to exchange threat signals quickly, removing the friction that typically accompanies inter-organizational data sharing and allowing Microsoft to act on Google's contribution without delay. Looking ahead, both parties will continue bidirectional signal sharing through GSE to sustain intelligence flow as the campaign evolves, while supporting law enforcement efforts with additional signals and context as the investigation develops.

Case Study 2: Infrastructure RedVDS Disruption — Cross-Platform Signal Sharing via GSE

In January 2026, Microsoft's Digital Crimes Unit (DCU) announced a coordinated disruption of RedVDS, a criminal marketplace that had become a key enabler of AI-enhanced fraud, business email compromise (BEC), mass phishing, account takeover, and payment diversion scams. For as little as $24 per month, RedVDS provided cybercriminals with virtual machines running unlicensed Windows software, enabling them to launch attacks at scale against victims worldwide. The service was also increasingly leveraged alongside generative AI tools, including voice cloning, video manipulation, and face-swapping technologies, to enhance fraud and impersonation schemes. Microsoft's investigation revealed the global scale of the operation. In just three months between September and December 2025, RedVDS-enabled attacks resulted in the compromise or fraudulent access of more than 191,000 Microsoft email accounts across over 130,000 organizations worldwide. Since March 2025 alone, activity linked to RedVDS contributed to more than $66 million in reported fraud losses in the United States.

To disrupt the criminal ecosystem, the DCU pursued a comprehensive legal and operational strategy. In January 2026, Microsoft filed coordinated civil actions in both the United States and the United Kingdom. Through these legal actions, Microsoft obtained authority to seize the primary RedVDS marketplace domains, and secured additional information regarding the operators and customers of the service. Microsoft also shared extensive actionable intelligence with law enforcement partners in the United States and Europe, supporting coordinated criminal enforcement activity. These efforts contributed to the seizure of critical infrastructure, including RedVDS's primary server by German Law Enforcement, while Europol coordinated additional actions against servers used by RedVDS customers across Europe.

As part of the disruption operation, Microsoft shared IOCs with Google through the GSE. Upon ingesting Microsoft's indicators, Google was able to cross-reference them against activity observed across its own platforms, enabling significant internal disruptions, including the suspension of numerous Google accounts associated with business email compromise schemes. Google's ability to rapidly operationalize Microsoft's signals helped limit the reach of the campaign across the broader ecosystem and demonstrated the value of coordinated cross-platform action against shared criminal infrastructure.

Following the disruption, DCU continued to actively monitor for RedVDS infrastructure and systematically removed it through the Statutory Automated Disruption (SAD) program. By February - less than two months after the action – there was a reduction of more than 95% in active RedVDS servers, effectively rendering RedVDS non-operational.

The RedVDS operation demonstrates that effectively disrupting modern cybercrime infrastructure requires a holistic, multi-pronged strategy. Fraud and cybercrime ecosystems are resilient by design, with operators often relying on distributed infrastructure, multiple service providers, and complex criminal partnerships that allow them to quickly adapt when a single component is disrupted. By combining legal authorities, technical takedowns, law enforcement action, and cross-platform intelligence sharing, Microsoft and its partners were able to degrade not only the visible marketplace itself, but also the broader criminal infrastructure and services that enabled RedVDS customers to conduct fraud and cybercrime at scale.

Looking ahead, Microsoft and Google intend to continue using GSE as a standing channel for signal exchange on related and emerging campaigns, building on these collaborations as a model for coordinated, cross-platform enforcement against fraud infrastructure and cybercriminal ecosystems.


Our Authors