An international law enforcement operation has disrupted the global cybercrime service known as “RedVDS,” with authorities in Germany, the United States, and the United Kingdom collaborating alongside Microsoft to dismantle the infrastructure.
The coordinated action was confirmed by the Central Office for Cybercrime (ZIT) at the Public Prosecutor General’s Office in Frankfurt, and the State Criminal Police Office of Brandenburg in a joint statement released on Wednesday. Investigators estimate hundreds of victims have been impacted.
Authorities and Businesses Among the Victims
German investigators played a key role in the investigation of the platforms. The digital service allowed cybercriminals to commit crimes anonymously, according to the statement from German law enforcement.
Numerous companies and government agencies in Germany, including those in Hesse and Brandenburg, were among those targeted.
Technical Hub of the Criminals Located in Limburg
Suspects have not been apprehended, and are believed to be located in a Middle Eastern country. Experts estimate the financial damage to be in the hundreds of millions of euros.
The technical center of the cybercriminals was a data center located in Germany. According to the German Press Agency (dpa), it was located in Limburg, where RedVDS servers were seized on Tuesday afternoon. Authorities did not disclose the precise location.
Millions in Losses from “Boss” Fraud Scheme
The fraud schemes frequently followed a similar pattern: criminals first attempted to gain access to their victims’ computer systems, often through phishing emails.
Once inside, the attackers were able to steal money or sensitive data by impersonating a CEO, colleague, business partner, or supplier, potentially submitting fraudulent invoices or manipulating bank details.
Online Subscription for Criminals
RedVDS allegedly provided these fraudsters with an online subscription service, allowing them to rent the infrastructure needed for their crimes.
According to Microsoft, the service provided access to a virtual disposable computer – a server with pirated Windows software – for $24 a month. This server could be shut down after the crime to hinder prosecution.
Millions of Dangerous Phishing Emails
With the RedVDS subscription, criminals were able to operate quickly, anonymously, and across borders, Microsoft explained. In a single month, more than 2,600 different virtual RedVDS machines sent an average of one million phishing messages per day to Microsoft customers alone.
Although most of these were blocked or flagged, the sheer volume meant that a small percentage may have successfully reached their targets. Victims were not limited to Microsoft customers, but included users of all major platforms.
Frequently Asked Questions
What was RedVDS?
RedVDS was a cybercrime service that provided criminals with access to infrastructure, including virtual computers and software, for a monthly fee. This allowed them to conduct fraudulent activities anonymously and across borders.
Which countries were involved in dismantling RedVDS?
Germany, the United States, and the United Kingdom collaborated with Microsoft to dismantle the RedVDS infrastructure.
What type of fraud was facilitated by RedVDS?
RedVDS facilitated a “boss” fraud scheme, where criminals impersonated authority figures to steal money or sensitive data from victims, often through phishing emails and fraudulent invoices.
As authorities continue to investigate, it is possible that further details regarding the individuals behind RedVDS will emerge, and additional victims may be identified. It remains to be seen whether this operation will significantly disrupt cybercriminal activity in the long term, or if similar services will emerge to take its place.