LAW.coLAW.co

Microsoft Corporation v. John Does 1-2

2026-08-05

Authorities cited

Opinion

majority opinion

UNITED STATES DISTRICT COURT

FOR THE DISTRICT OF COLUMBIA

Microsoft Corporation, a Washington State

Corporation, NGO-ISAC, a New York State

Non-Profit Organization, :

:

Plaintiffs, : Civil Action No.: 24-2719 (RC)

:

v. : Re Document No.: 45

:

John Does 1-2, Controlling A Computer

Network and Thereby Injuring Plaintiff and Its

Customers. :

:

Defendants. :

MEMORANDUM OPINION

GRANTING MICROSOFT & NGO-ISAC’S MOTION FOR DEFAULT JUDGMENT AND PERMANENT

INJUNCTION

I. INTRODUCTION

This matter comes before the Court on Plaintiffs’ motion for a default judgment and

permanent injunction. Plaintiffs, Microsoft Corporation (“Microsoft”) and NGO Information

Sharing and Analysis Center (“NGO-ISAC”), bring claims under the Computer Fraud and Abuse

Act (“CFAA”), Electronic Communications Privacy Act (“ECPA”), the Lanham Act, and the

common law doctrines of trespass to chattels, conversion, and unjust enrichment. Plaintiffs

allege that Defendants, whom they characterize as “Russia-based cybercriminals,” operate “an

ongoing internet-based spear phishing operation known as ‘Star Blizzard.’” Compl. ¶¶ 1, 17.

“Spear phishing is a type of personalized attack in which the cybercriminal attempts to acquire

sensitive information or access a computer by sending a fake email message that appears to be

legitimate,” which tricks the target into clicking on a malicious link, attachment, or providing confidential information or credentials. Id. ¶ 19. The scheme is allegedly directed at Microsoft

and its customers, NGO-ISAC’s member organizations, and the general public. Id. During the

pendency of this litigation, Defendants have not appeared or responded in any manner, and

“[d]efendants’ true identities remain unknown despite extensive discovery efforts.” Decl. of

Anna Z. Saber ¶ 26. Upon review of the record and all relevant documents, this Court grants

Plaintiffs’ motion.

II. FACTUAL BACKGROUND

A. Relevant Facts

Plaintiffs allege that Defendants are the masterminds of “an ongoing internet-based spear

phishing operation known as ‘Star Blizzard.’” Compl. at 1. According to Plaintiffs, Defendants

begin their attacks by scouring “public facing sources of intelligence,” including social media, to

identify targets. See id. ¶ 22. Next, Defendants will “open a new email account,” which they

design “to match or look similar to legitimate addresses and account names.” See id. ¶ 24. For

example, Defendants have “impersonate[d] NGO-ISAC member Carnegie Corporation of New

York . . . in [their] spear phishing emails.” The Defendants then use the email account to contact

their target. See id. ¶ 25. Their communications “begin[] with rapport building and then

escalate[] to the sending of a fictitious attachment.” Id. ¶ 26. At this point, “Defendants attach a

file or include[] a link to a file share platform like OneDrive.” Id. To effectuate their attacks,

Defendants control hundreds of internet domains. See id. ¶ 20. When targets click on links sent

to them by the Defendants, they are directed to one of those domains. See id. ¶ 35. The domains

appear as though they were the login page for a Microsoft service. See id. ¶ 36. As an example,

the spoofed login pages will often include the “language ‘©Microsoft 2016’” to convince the

target that “the link is to a legitimate Microsoft webpage.” See id. ¶ 45. More generally,

2

Defendants use “Microsoft brands and trademarks . . . to confuse Microsoft’s customers into

clicking on malicious links that they believe are associated with and owned by Microsoft.” See

id. ¶ 46. “Once a victim inputs their login credentials, Star Blizzard is able to capture the

credential.” Id. ¶ 39. The Defendants then use the captured credentials to gain access to the

target’s email account. See id. Once in possession of the target’s login credentials, “[t]he final

step of Star Blizzard’s attack sequence is data exfiltration.” Id. ¶ 41. Defendants have used their

newfound access to target’s emails to set up rules “that would automatically forward an email

received by the victim to another email address,” and have extracted “mailing lists and other

contact information,” which aid Defendants in other attacks. See id. In response to these attacks,

Microsoft has “expended more than $1,000,000” to investigate the harms resulting from these

attacks, and Carnegie Corporation of New York, a member of NGO-ISAC, has similarly

expended “approximately $200,000.” Id. ¶ 48.

B. Procedural History

On September 24, 2024, Plaintiffs filed their complaint. See generally Compl. At the

same time, Plaintiffs moved for a temporary restraining order (“TRO”) and a preliminary

injunction transferring ownership of Star Blizzard-controlled domains to Plaintiffs, which this

Court granted on September 25, 2024.1 Subsequently, this Court granted requests for several

supplemental preliminary injunctions. See Dkt. No. 22; Dkt. No. 28; Dkt. No. 41.

1

The purpose of transferring domains controlled by Defendants to Microsoft is so that “any time a user clicks on a link in a spear phishing email and provides their username and password, that information will be prevented from going to the Defendants at the Star Blizzardcontrolled domains, because those domains will be hosted on a Microsoft-controlled, secure server, beyond the control of the Star Blizzard Defendants.” Decl. of Sean Ensz ¶ 55, ECF No. 4-2.

3

Defendants have not responded to the litigation in any capacity since Plaintiffs first

served Defendants on October 3, 2024. See Pls.’ Br. Supp. Default J. and Permanent Inj. (“Pls.’

Br.”) at 3, ECF No. 45-2. Accordingly, on February 25, 2026, Plaintiffs moved for an entry of

default under Rule 55. See Dkt. No. 43. The Clerk entered default on February 27, 2026. See

Dkt. No. 44. Plaintiffs then moved for default judgment and a permanent injunction on March

27, 2026. See Dkt. No. 45.

III. LEGAL STANDARD

Federal Rule of Civil Procedure 55 governs the default judgment procedure. Fed. R. Civ.

P. 55. Rule 55(a) permits the entry of default by the clerk when “a party against whom a

judgment for affirmative relief is sought has failed to plead or otherwise defend, and that failure

is shown by affidavit or otherwise.” Id. Once the clerk enters the default under Rule 55(a), the

Plaintiff must “apply to the court for a default judgment” under Rule 55(b)(2).2 Id.

After an entry of default, the “defaulting defendant is deemed to admit every wellpleaded allegation in the complaint.” AARP v. Sycle, 991 F. Supp. 2d 234, 238 (D.D.C. 2014)

(quoting Int’l Painters & Allied Trades Indus. Pension Fund v. R.W. Amrine Drywall Co., Inc.,

239 F. Supp. 2d 26, 30 (D.D.C. 2002)). That being said, “the determination of whether default

judgment is proper is committed to the discretion of the trial court.” Portillo v. Smith Commons

DC, LLC, No. CV 20-49-RC, 2021 WL 3287741, at *2 (D.D.C. Aug. 2, 2021). But “a court

should satisfy itself that is has personal jurisdiction before entering judgment against an absent

defendant.” Mwani v. bin Laden, 417 F.3d 1, 6 (D.C. Cir. 2005). And “a district court may deny

an application for default judgment where the allegations of the complaint, even if true, are

2

Rule 55(b)(1) provides for the entry of a default judgment by the clerk on the Plaintiffs’ request, but only “[if] the plaintiff’s claim is for a sum certain.” Id. Here, Plaintiffs have requested injunctive relief and, therefore, needed to apply to the Court for a default judgment.

4

legally insufficient to make out a claim.” Gutierrez v. Berg Contracting Inc., No. CIV. A. 99-3044 (TAF), 2000 WL 331721, at *2 (D.D.C. Mar. 20, 2000).

IV. ANALYSIS

A. Jurisdiction and Venue

Plaintiffs have asserted claims under various federal laws including: the Lanham Act, the

Computer Fraud and Abuse Act, and the Electronic Communications Privacy Act. See Compl.

¶¶ 54–90. As this Court found when it issued the TRO, there is subject matter jurisdiction over

those claims. See 28 U.S.C. § 1331 (“The district courts shall have original jurisdiction of all

civil actions arising under the Constitution, laws, or treaties of the United States.”); Ex Parte

TRO and O.S.C. Re Prelim. Inj. ¶ 1, ECF No. 12. Additionally, this Court has supplemental

jurisdiction over Plaintiff’s common law trespass to chattels, conversion, and unjust enrichment

claims. See 28 U.S.C. § 1367 (“[I]n any civil action of which the district courts have original

jurisdiction, the district courts shall have supplemental jurisdiction over all other claims that are

so related to claims in the action within such original jurisdiction that they form part of the same

case or controversy.”).

Venue is also proper in this judicial district as a substantial part of the events or

omissions giving rise to Plaintiff’s claims have occurred within this district. Plaintiffs have

identified that individuals targeted by Defendants’ attacks “predominately reside in the U.S., in

and around the Washington D.C. area.” See Compl. ¶ 14.

B. Service of Process

“Before a federal court may exercise personal jurisdiction over a defendant, the

procedural requirement of service of summons must be satisfied.” Mwani v. bin Laden, 417 F.3d

1, 8 (D.C. Cir. 2005) (quoting Omni Cap. Int’l, Ltd. v. Rudolf Wolff & Co., 484 U.S. 97, 104

5

(1987)). Additionally, to satisfy due process, the method of service must be “reasonably

calculated, under all the circumstances, to apprise interested parties of the pendency of the action

and afford them an opportunity to present their objections.” Mullane v. Central Hanover Bank &

Trust Co., 339 U.S. 306, 314 (1950). Plaintiffs alleged that Defendants are “Russia-based

cybercriminals,” and thus, Defendants can be served according to Rule 4(f), which governs

service to individuals in foreign countries. See Fed. R. Civ. P. 4. Rule 4(f)(3) permits service

“by other means not prohibited by international agreement, as the court orders.” Id. And “[t]o

validly effectuate service under Rule 4(f)(3), a plaintiff must affirmatively seek and obtain the

district court's authorization for a particular means of service.” Zavadovsky v. Rabl, No. CV 24-1997 (RC), 2025 WL 2466024, at *10 (D.D.C. Aug. 27, 2025). Courts in this district have relied

on Rule 4(f) to permit both service by email and service by publication. See, e.g., Juniper

Networks, Inc. v. Bahattab, No. CIV.A. 07-1771 (PLF), 2008 WL 250584, at *2 (D.D.C. Jan. 30,

2008) (authorizing service by electronic mail under Rule 4(f)(3)); Kaplan v. Hezbollah, 715 F.

Supp. 2d 165, 167 (D.D.C. 2010) (authorizing service by publication under Rule 4(f)(3)).

Additionally, “in the case of persons missing or unknown, employment of an indirect and even a

probably futile means of notification is all that the situation permits and creates no constitutional

bar to a final decree foreclosing their rights.” Mwani, 417 F.3d at 8 (quoting Mullane, 339 U.S.

at 317).

Plaintiffs requested permission to serve Defendants by email and publication. Pls.’ Mem.

Supp. Appl. Emergency Ex Parte TRO and O.S.C. Re Prelim. Inj. at 34, ECF No. 4-1. This

Court subsequently granted that request and authorized service “by any means authorized by

law” including service by email and publication on “a publicly available Internet website.” Ex

Parte TRO and O.S.C. RE Prelim. Inj. at 10–11. Plaintiffs aver that they “served email addresses

6

associated with the Defendants’ Internet domains” on October 3, 2024. Pls.’ Br. at 3. And the

“emails were repeatedly opened and viewed by Defendants between October 3, 2024 and the

present.” Id. Additionally, Plaintiffs served Defendants by publication beginning on October 3,

2024.3 See id.

Despite online publication and emailed notice, Defendants ignored this lawsuit. The

combination of service by email and by publication does not violate any international agreement

and is reasonably calculated to achieve notice to the Defendants.4 Accordingly, the Court

concludes that service by email and publication was sufficient.

C. Default Judgment

As noted above, before entering a default judgment, the Court must evaluate Plaintiffs’

complaint to be sure that it sufficiently states a claim for which relief can be granted. See

Gutierrez, 2000 WL 331721, at *2.

D. Lanham Act Claims

Plaintiffs bring claims under the Lanham Act for trademark infringement and false

designation of origin. See Compl. ¶ 71–90. “To prevail on a claim for federal trademark

infringement . . . and false designation of origin, ‘the plaintiff must show (1) that it owns a valid

trademark, (2) that its trademark is distinctive or has acquired secondary meaning, and (3) that

3

Plaintiffs made use of the following public domain:

https://noticeofpleadings.com/starblizzard/. See Pls.’ Br. at 8.

4

Russia and the United States are both parties to the Hague Convention on the Service Abroad of Judicial and Extrajudicial Documents in Civil or Commercial Matters, however, the convention is inapplicable where, as here, the address of the persons to be served is unknown. See Convention Done at the Hague Nov. 15, 1965;, T.I.A.S. No. 6638 (Feb. 10, 1969) (“This Convention shall not apply where the address of the person to be served with the document is not known.”); BP Prods. N. Am., Inc. v. Dagra, 236 F.R.D. 270, 271 (E.D. Va. 2006) (“[T]he Hague Convention does not apply when a defendant’s address is unknown and the attempts at service have been futile.”); see also Pls.’ Br. at 8 (“Plaintiffs were unable to specifically and definitively determine the ‘real’ names and physical addresses of Defendants.”).

7

there is a substantial likelihood of confusion between the plaintiff’s mark and the alleged

infringer’s mark.’” AARP v. Sycle, 991 F. Supp. 2d 224, 229 (D.D.C. 2013) (quoting Globalw

Ltd. V. Carmon & Carmon Law Office, 452 F. Supp 2d 1, 26–27 (D.D.C. 2006)).

At the default judgment stage, Defendants have conceded that Microsoft and NGO-ISAC

member organization Carnegie Corporation of New York’s trademarks are valid and that they

have distinctive or secondary meaning. Microsoft and NGO-ISAC have also provided their

federal trademark registrations in their complaint. See Compl. Apps. B & C. Plaintiffs have

alleged that, as part of their scheme, Defendants present targets with “a webpage that appears to

be a Microsoft login page,” and that they use “Microsoft brands and trademarks . . . to confuse

Microsoft’s customers into clicking on Malicious links that they believe are associated with and

owned by Microsoft.” Compl. ¶ 45. As an example, Plaintiffs provide an image, see id. fig. 10,

of a “cloned phishing portal used by the . . . Defendants to directly impersonate [Microsoft].” Id.

¶ 37. The clear purpose and effect, when successful, in using Plaintiffs’ trademarks is to confuse

targets into thinking that Defendants’ domains are actually controlled by the owners of the

trademarks to induce targets to provide the sought after credentials or information. Additionally,

Plaintiffs allege that Defendants have impersonated Carnegie Corporation of New York, an

NGO-ISAC member, “in its spear phishing emails to its target victims.” Id. ¶ 50. Thus, the

allegation in the complaint sufficiently makes out claims of trademark infringement and false

designation of origin under the Lanham Act.

E. Computer Fraud and Abuse Act Claim

The CFAA provides a private cause of action for any person “suffering damage or loss”

from a violation of the act. 18 U.S.C. § 1030(g). Additionally, a civil action under § 1030(g)

can only be brought “if the conduct involves 1 of the factors set forth” in one of the five

8

subclauses of subsection (c)(4)(A)(i). Id. The only subclause relevant to Plaintiffs’ claims

requires “loss to 1 or more persons during any 1-year period . . . aggregating at least $5,000 in

value.” § 1030(4)(A)(i)(I). Defendants can violate CAFA in numerous ways: “intentionally

access[ing] a protected computer without authorization and as a result of such conduct, caus[ing]

damage and loss,” § 1030(a)(5)(C); “intentionally access[ing] a computer without authorization

or exceed[ing] authorized access, and thereby obtain[ing] information from any protected

computer,” § 1030(a)(2); and “knowingly caus[ing] the transmission of a program, information,

code or command, and as a result of such conduct, intentionally caus[ing] damage without

authorization to a protected computer. § 1030(a)(5)(A). The statute also defines a “protected

computer” as a computer “which is used in or affecting interstate or foreign commerce,”

§ 1030(e)(2), and it defines “exceeds authorized access” as “to access a computer with

authorization and to use such access to obtain or alter information in the computer that the

accesser is not entitled so to obtain or alter.” § 1030(e)(6).

Plaintiffs alleged that Defendants engineer their spear phishing emails to “deceive their

victims into thinking that they are responding to a legitimate email and to trick them into opening

a malicious link or attachment.” Compl. ¶ 19 (emphasis added). When successful, Defendants

“gain unfettered access and control of the victim’s inbox.” Id. In some cases, the Defendants

then use their access to “exfiltrate mailing lists and other contact information” as well as

“exfiltrate[] emails and attachments from the inbox of victims.” Id. ¶ 41. The core goal of

Defendants’ scheme is to gain access to target’s email accounts without their knowledge or

consent. Microsoft and NGO-ISAC have also alleged that they have expended more than

$1,000,000 and $200,000 respectively responding to these attacks, which is far greater than the

9

$5,000 loss required by the statute. See id. ¶ 48. Thus, Plaintiffs have successfully demonstrated

a claim against Defendants under the CFAA.

F. Electronic Communications Privacy Act Claim

ECPA prohibits “intentionally access[ing] without authorization a facility through which

an electronic communication service is provided.” 18 U.S.C. § 2701(a). ECPA provides a civil

cause of action for “any provider of electronic communication service, subscriber, or other

person aggrieved by any violation of this chapter.” § 2707(a).

Plaintiffs have alleged that “the Star Blizzard Defendants use stolen credentials and

replayed authentication tokens to directly sign in to victim email accounts.” Decl. of Sean Ensz

¶ 34, ECF No. 4-2. As an example, Plaintiffs allege that the Defendants, in a successful phishing

operation, were able to “obtain unique grant numbers associated with a[n] [NGO-ISAC] member

organization’s grant issuing process.” Pls.’ Br. at 17. This is precisely the conduct that ECPA

was designed to prevent. In re DoubleClick Inc. Priv. Litig., 154 F. Supp. 2d 497, 507 (S.D.N.Y.

2001) (“[Section 2701] aims to prevent hackers from obtaining, altering or destroying certain

stored electronic communications.”). Thus, Plaintiffs have successfully demonstrated a claim

against Defendants under ECPA.

G. Remaining Claims

Plaintiffs have brought four additional causes of action: trademark dilution under the

Lanham Act, trespass to chattels, conversion, and unjust enrichment. See Compl. ¶¶ 86–90, 91–

100, 107–114. However, “[b]ecause the Court has found that [Plaintiffs] [are] entitled to default

judgment on some [their] claims, the Court need not reach remaining claims as the scope of the

appropriate injunctive relief would not vary based on the merits of the remaining claims.”

Microsoft Corp. v. Does 1-2, No. 20-CV-1217 (LDH) (RER), 2021 WL 4755518, at *8

10

(E.D.N.Y. May 28, 2021), report and recommendation adopted, No. 20CV1217LDHRER, 2021

WL 4260665 (E.D.N.Y. Sept. 20, 2021).

H. Injunctive Relief

Plaintiffs seek a permanent injunction:

(1) prohibiting Defendants from operating or propagating the Star Blizzard

infrastructure; (2) permanently transferring ownership to Microsoft of known

malicious Star Blizzard domains identified in the Court’s prior injunction orders . .

. ; and (3) adopting an expedited process for overseeing issues with Defendants’

compliance with the permanent injunction including streamlined briefing and

regular telephonic hearings to immediately resolve these issues either by appointing

a Court Monitor or through another process under this Court’s supervision.

Pls.’ Br. at 2. “In determining whether to enter a permanent injunction, the Court considers a

modified iteration of the factors it utilizes in assessing preliminary injunctions: (1) success on the

merits, (2) whether the plaintiffs will suffer irreparable injury absent an injunction, (3) whether,

balancing the hardships, there is harm to defendants or other interested parties, and (4) whether

the public interest favors granting the injunction.” Am. C.L. Union v. Mineta, 319 F. Supp. 2d

69, 87 (D.D.C. 2004), dismissed, No. 04-5285, 2005 WL 263924 (D.C. Cir. Feb. 2, 2005).

As discussed above, Plaintiffs have succeeded by default on the merits of the action.

Plaintiffs further argue that they have suffered irreparable injury owing to the “[c]onsumer

confusion and injury to business goodwill” that is likely to occur if “Defendants are able to

continue to use domains bearing Plaintiffs’ trademarks and brands in furtherance of their

activities.” Pls.’ Br. at 22. This Court has previously found that, absent an injunction,

“irreparable harm will occur to Microsoft, Microsoft’s customer, NGO-ISAC, NGO-ISAC’s

customers, and the public.” Order Granting Mot. for Prelim. Inj. ¶ 8, ECF No. 12. Additionally,

with respect to Plaintiffs’ Lanham Act claims, “trademark infringement, by its very nature,

carries a presumption of harm.” See Hanley-Wood LLC v. Hanley Wood LLC, 783 F. Supp. 2d

11

147, 151 (D.D.C. 2011). Thus, there is ample reason to believe that Plaintiffs will suffer

irreparable injury absent a permanent injunction. Lastly, the Court finds that an injunction would

not harm Defendants or other interested parties, and that the public interest favors both

“protecting against further violation of federal copyright and trademark laws,” Hanley-Wood

LLC, 783 F. Supp. 2d at 151, and preventing the use of domains by Defendants to “conduct their

cybercriminal activity.” Pls.’s Br. at 2. Accordingly, the Court concludes that the Plaintiffs are

entitled to a permanent injunction as requested in their motion.

I. Plaintiffs’ Request for a Court Monitor

Plaintiffs have requested that the Court “adopt an expedited process of overseeing issues

with Defendants’ compliance with the permanent injunction.” Pls.’ Br. at 27. Plaintiffs have

also requested that this process “be overseen by a Court Monitor.” Id. Rule 53(a)(1)(C)

authorizes the appointment of a court monitor to “address pretrial and posttrial matters that

cannot be effectively and timely addressed by an available district judge or magistrate judge of

the district.” Fed. R. Civ. P. 53. There is precedent in cases similar to this one, in this district

and elsewhere, for the appointment of a court monitor to oversee a permanent injunction. See,

e.g., Microsoft Corporation v. John Does 1-2, Civil Action No. 19-cv-00716-ABJ; Microsoft

Corp. v. John Does 1-2, Civil Action No. 1:16-cv-993 (E.D. Va. Dec. 6, 2016). This Court

agrees with Plaintiffs that the appointment of a special master is warranted given Defendants’

ongoing establishment of new domains to effectuate their scheme, which has already required

Plaintiffs to move for a supplemental preliminary injunction on three separate occasions.

12

V. CONCLUSION

For the foregoing reasons, Plaintiffs’ Motion for Default Judgment and Permanent

Injunction is GRANTED. An order consistent with this Memorandum Opinion is separately and

contemporaneously issued.

Dated: August 5, 2026 RUDOLPH CONTRERAS

United States District Judge

13