Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs

January 14, 2026

Criminal Subscription Service Behind AI-Powered Cyber-Attacks Taken Out By Microsoft

January 14, 2026

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

January 14, 2026
Facebook X (Twitter) Instagram
Wednesday, January 14
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»News»Criminal Subscription Service Behind AI-Powered Cyber-Attacks Taken Out By Microsoft
News

Criminal Subscription Service Behind AI-Powered Cyber-Attacks Taken Out By Microsoft

Team-CWDBy Team-CWDJanuary 14, 2026No Comments3 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


A cybercriminal subscription services responsible for fraud campaigns causing millions of dollars in losses has been disrupted in coordinated action by Microsoft alongside legal partners in the US and, for the first time, the UK.

On Wednesday January 14, Microsoft announced it had seized the website and infrastructure of RedVDS, a platform which hosted cybercrime-as-a-service tools for phishing and fraud campaigns, which cost users as little as $24 a month.

Despite the low cost of entry, the cybercriminal subscription service is known to have cost victims in the US alone over $40 million since March 2025. These include a cyber-attack against Alabama‑based pharmaceutical company H2-Pharma that caused more than $7.3m in losses and Gatehouse Dock Condominium Association, home association in Florida which  lost over $500,000 to RedVDS hosted campaigns.

In total, Microsoft has identified nearly 190,000 organizations worldwide which fell victim to RedVDS supported campaigns. The US, Canada and the UK were the most impacted countries.

RedVDS provided cybercriminals with access to cheap, effective and disposable virtual computers running unlicensed software, including Windows, allowing criminals to operate quickly and anonymously against victims around the world.

RedVDS Uses AI to Tailor Phishing and BEC Scams 

These servers allowed RedVDS to be used for a range of cybercriminal activity, including sending campaigns ranging from high-volume phishing attacks and highly targeted business email compromise (BEC) scams.

As part of the BEC attacks, cybercriminals are known to have quietly observed ongoing communications between victims and their legitimate business partners, before waiting for the right moment to strike, impersonating that contact to request significant wire transfers.

According to Microsoft, RedVDS services were commonly paired with generative AI tools to help criminals quickly identify potentially high-value targets and generate realistic looking phishing emails and associated attachments to mimic legitimate messages the victim would expect to see.

Microsoft also noted that there were hundreds of examples of attackers exploiting AI deepfake videos and voice cloning to impersonate specific individuals and create even more realistic means of deception.

Victims Urged to Report Cybercrime to Prevent Future Attacks

The coordinated action to take down and disrupt RedVDS saw legal action in US and UK combined with support from international law enforcement, including Europol.

Microsoft also praised RedVDS victims, like H2-Pharma and the Gatehouse Dock Condominium Association, for help in aiding the disruptive action.

“Their cooperation made this action possible and will help protect future victims. Falling victim to a scam should never carry stigma. These attacks are executed by organized, professional criminal groups that intercept and manipulate legitimate communications between trusted parties,” said Microsoft.

Phishing and BEC scams are often sophisticated, but there are actions which can be taken to reduce the chance of falling victim. These include slowing down and questioning the urgency of opening links and requests for payment and verifying payment requests with colleagues.

It’s also recommended that users apply multi-factor authentication to help prevent account takeover and that software is kept up to date with security patches to counter known vulnerabilities.

Finally, Microsoft recommended that in the event of finding out they’ve fallen victim to a cyber-attack or scam, companies should report it: because as has been the case with RedVDS, it can help stop cybercriminals from damaging others.

“Every report helps dismantle networks like RedVDS and brings us closer to stopping cybercrime at scale,” the company said.



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleTrend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions
Next Article Hackers Use Fake PayPal Notices to Steal Credentials, Deploy RMMs
Team-CWD
  • Website

Related Posts

News

Trend Micro Apex Central RCE Flaw Scores 9.8 CVSS in On-Prem Windows Versions

January 14, 2026
News

G7 Sets 2034 Deadline for Finance to Adopt Quantum-Safe Systems

January 14, 2026
News

CISA Retires 10 Emergency Cybersecurity Directives Issued Between 2019 and 2024

January 14, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202521 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views

U.S. Treasury Sanctions DPRK IT-Worker Scheme, Exposing $600K Crypto Transfers and $1M+ Profits

September 5, 20256 Views

Ukrainian Ransomware Fugitive Added to Europe’s Most Wanted

September 11, 20255 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202521 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Exploit Threat Intel Platforms For Phishing

September 7, 20256 Views
Our Picks

How the always-on generation can level up their cybersecurity game

September 11, 2025

AI-powered financial scams swamp social media

September 11, 2025

Your information is on the dark web. What happens next?

January 13, 2026

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.