Microsoft disrupts RedVDS, a subscription service tied to AI-powered phishing and BEC attacks

March 21, 20262 min read2 sources
Share:
Microsoft disrupts RedVDS, a subscription service tied to AI-powered phishing and BEC attacks

Microsoft says it has taken down RedVDS, a cybercrime subscription service accused of enabling phishing, business email compromise (BEC), account takeover and other fraud campaigns that have cost victims millions.

According to reporting by Infosecurity Magazine, RedVDS operated as a criminal service platform sold to other threat actors. Microsoft linked the operation to AI-assisted attack workflows that helped customers create more convincing phishing lures and scale fraud activity. The company said the service was used in schemes targeting both individuals and organizations.

While the available reporting does not name specific victims or list technical indicators, the case fits a wider pattern: cybercrime groups are packaging infrastructure, templates and automation into rentable services that lower the skill needed to run effective scams. In RedVDS’s case, the use of AI appears to have improved the quality and speed of phishing and BEC operations rather than introducing a new attack method.

The impact is significant because BEC remains one of the costliest forms of cybercrime. Once attackers steal credentials or gain access to a business email account, they can redirect invoices, change payment details or impersonate executives and suppliers. AI tools make those messages easier to tailor, harder to spot and faster to produce at scale.

For defenders, the takedown is useful but unlikely to end the threat. Criminal infrastructure often reappears under new domains or providers after disruption. Organizations should treat polished phishing emails and payment-change requests as high risk, especially when they create urgency. Basic controls still matter: phishing-resistant MFA, DMARC, out-of-band payment verification and tighter monitoring for suspicious inbox activity. Employees using public networks should also secure traffic with a VPN, though that will not stop email fraud on its own.

Microsoft’s move shows how major vendors are increasingly targeting the service layer of cybercrime, not just individual malware strains. As AI becomes a standard feature in fraud operations, takedowns like this may raise costs for attackers, but they will also need to be repeated often to have lasting effect.

Share:

// SOURCES

// RELATED

Meta settles bellwether lawsuit alleging addictive design harmed student mental health

Meta's confidential settlement with a Washington school district marks a pivotal moment in the massive litigation against social media's psychological

6 min readMay 24

Huawei zero-day attack behind last year’s crash of Luxembourg's entire telecoms network

A sophisticated zero-day attack on Huawei routers allegedly caused Luxembourg's 2023 national telecom outage, raising severe global security concerns.

6 min readMay 23

MiniPlasma Windows 0-day enables SYSTEM privilege escalation on fully patched systems

A newly disclosed 0-day flaw, MiniPlasma, allows attackers to gain full SYSTEM control on patched Windows systems, with a public PoC accelerating risk

6 min readMay 18

The ransomware dilemma: why more than half of security chiefs would pay the price

A new survey reveals 56% of CISOs would consider paying a ransom, highlighting the intense pressure to restore operations despite official guidance.

6 min readMay 16