{"id":3553,"date":"2026-06-24T05:30:00","date_gmt":"2026-06-24T12:30:00","guid":{"rendered":"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/?p=3553"},"modified":"2026-06-24T08:26:42","modified_gmt":"2026-06-24T15:26:42","slug":"five-disruptions-one-infrastructrure","status":"publish","type":"post","link":"https:\/\/www.microsoft.com\/en-us\/corporate-responsibility\/topics\/cybersecurity\/stories\/five-disruptions-one-infrastructrure\/","title":{"rendered":"Five takedowns, one infrastructure: How Microsoft is tackling the cybercrime economy"},"content":{"rendered":"

To comprehend the challenges of fighting cybercrime today, you need to first understand that, in the digital world, crime is a business, and cybercriminal operations often look a lot like legitimate companies. <\/p>

In any industry, businesses rely on a distributed supply chain to operate efficiently at scale, and the same is true for cybercrime. The lone hacker is a thing of the past. Now, any type of cyberattack relies on a network of specialized providers that make up the cybercrime-as-a-service (CaaS) economy. <\/p>

The CaaS ecosystem functions as a supply chain for cybercrime, with different vendors offering interconnected tools and services. Upstream providers sell access—different ways to break into a system, including stolen login credentials, malware, and phishing kits. Midstream providers sell infrastructure like servers, hosting, and proxy networks. Downstream providers support specific attacks with ransom negotiations, payment systems, and cryptocurrency laundering. This distributed network makes cybercrime efficient, coordinated, and scalable. No single actor needs to be able to do everything; they can simply tap into the network.  <\/p>

“These are business models run by criminals to enable other criminals,” says Jason Lyons, Director of Investigations at Microsoft’s Digital Crimes Unit (DCU). The DCU has been disrupting cybercrime for more than a decade and has learned that fighting this industrialized criminal system is not about taking out individual cyberattackers. It’s about dismantling the infrastructure that facilitates attacks.  <\/p>

“Recently, we have started going after enablers, people who aren’t necessarily carrying out the attacks but are providing a service to those who are,” says Maurice Mason, Principal Cybercrime Investigator with the DCU. By taking out the upstream providers in the supply chain, the team aims to prevent the damage a criminal can do once they gain access to a system—attacks like ransomware, extortion, and social engineering.  <\/p>

In the last nine months alone, the DCU has taken down five large-scale global cybercrime operations, each part of the scaffolding that supports the CaaS economy. <\/p>

\"A
The DCU’s recent series of disruptions took down cyberthreats affecting hundreds of thousands of victims worldwide. Source: Microsoft Defender <\/em><\/figcaption><\/figure>