Microsoft Corporation v. John Does 1-2
CourtDistrict Court, District of Columbia
Date FiledAugust 5, 2026
DocketCivil Action No. 2024-2719
JudgeJudge Rudolph Contreras
StatusPublished
📰 News Coverage: Read the LAWS.com news report on this case
Full Opinion
UNITED STATES DISTRICT COURT
FOR THE DISTRICT OF COLUMBIA
Microsoft Corporation, a Washington State
Corporation, NGO-ISAC, a New York State
Non-Profit Organization, :
:
Plaintiffs, : Civil Action No.: 24-2719 (RC)
:
v. : Re Document No.: 45
:
John Does 1-2, Controlling A Computer
Network and Thereby Injuring Plaintiff and Its
Customers. :
:
Defendants. :
MEMORANDUM OPINION
GRANTING MICROSOFT & NGO-ISAC’S MOTION FOR DEFAULT JUDGMENT AND PERMANENT
INJUNCTION
I. INTRODUCTION
This matter comes before the Court on Plaintiffs’ motion for a default judgment and
permanent injunction. Plaintiffs, Microsoft Corporation (“Microsoft”) and NGO Information
Sharing and Analysis Center (“NGO-ISAC”), bring claims under the Computer Fraud and Abuse
Act (“CFAA”), Electronic Communications Privacy Act (“ECPA”), the Lanham Act, and the
common law doctrines of trespass to chattels, conversion, and unjust enrichment. Plaintiffs
allege that Defendants, whom they characterize as “Russia-based cybercriminals,” operate “an
ongoing internet-based spear phishing operation known as ‘Star Blizzard.’” Compl. ¶¶ 1, 17.
“Spear phishing is a type of personalized attack in which the cybercriminal attempts to acquire
sensitive information or access a computer by sending a fake email message that appears to be
legitimate,” which tricks the target into clicking on a malicious link, attachment, or providing
confidential information or credentials. Id. ¶ 19. The scheme is allegedly directed at Microsoft
and its customers, NGO-ISAC’s member organizations, and the general public. Id. During the
pendency of this litigation, Defendants have not appeared or responded in any manner, and
“[d]efendants’ true identities remain unknown despite extensive discovery efforts.” Decl. of
Anna Z. Saber ¶ 26. Upon review of the record and all relevant documents, this Court grants
Plaintiffs’ motion.
II. FACTUAL BACKGROUND
A. Relevant Facts
Plaintiffs allege that Defendants are the masterminds of “an ongoing internet-based spear
phishing operation known as ‘Star Blizzard.’” Compl. at 1. According to Plaintiffs, Defendants
begin their attacks by scouring “public facing sources of intelligence,” including social media, to
identify targets. See id. ¶ 22. Next, Defendants will “open a new email account,” which they
design “to match or look similar to legitimate addresses and account names.” See id. ¶ 24. For
example, Defendants have “impersonate[d] NGO-ISAC member Carnegie Corporation of New
York . . . in [their] spear phishing emails.” The Defendants then use the email account to contact
their target. See id. ¶ 25. Their communications “begin[] with rapport building and then
escalate[] to the sending of a fictitious attachment.” Id. ¶ 26. At this point, “Defendants attach a
file or include[] a link to a file share platform like OneDrive.” Id. To effectuate their attacks,
Defendants control hundreds of internet domains. See id. ¶ 20. When targets click on links sent
to them by the Defendants, they are directed to one of those domains. See id. ¶ 35. The domains
appear as though they were the login page for a Microsoft service. See id. ¶ 36. As an example,
the spoofed login pages will often include the “language ‘©Microsoft 2016’” to convince the
target that “the link is to a legitimate Microsoft webpage.” See id. ¶ 45. More generally,
2
Defendants use “Microsoft brands and trademarks . . . to confuse Microsoft’s customers into
clicking on malicious links that they believe are associated with and owned by Microsoft.” See
id. ¶ 46. “Once a victim inputs their login credentials, Star Blizzard is able to capture the
credential.” Id. ¶ 39. The Defendants then use the captured credentials to gain access to the
target’s email account. See id. Once in possession of the target’s login credentials, “[t]he final
step of Star Blizzard’s attack sequence is data exfiltration.” Id. ¶ 41. Defendants have used their
newfound access to target’s emails to set up rules “that would automatically forward an email
received by the victim to another email address,” and have extracted “mailing lists and other
contact information,” which aid Defendants in other attacks. See id. In response to these attacks,
Microsoft has “expended more than $1,000,000” to investigate the harms resulting from these
attacks, and Carnegie Corporation of New York, a member of NGO-ISAC, has similarly
expended “approximately $200,000.” Id. ¶ 48.
B. Procedural History
On September 24, 2024, Plaintiffs filed their complaint. See generally Compl. At the
same time, Plaintiffs moved for a temporary restraining order (“TRO”) and a preliminary
injunction transferring ownership of Star Blizzard-controlled domains to Plaintiffs, which this
Court granted on September 25, 2024.1 Subsequently, this Court granted requests for several
supplemental preliminary injunctions. See Dkt. No. 22; Dkt. No. 28; Dkt. No. 41.
1
The purpose of transferring domains controlled by Defendants to Microsoft is so that
“any time a user clicks on a link in a spear phishing email and provides their username and
password, that information will be prevented from going to the Defendants at the Star Blizzard-
controlled domains, because those domains will be hosted on a Microsoft-controlled, secure
server, beyond the control of the Star Blizzard Defendants.” Decl. of Sean Ensz ¶ 55, ECF No.
4-2.
3
Defendants have not responded to the litigation in any capacity since Plaintiffs first
served Defendants on October 3, 2024. See Pls.’ Br. Supp. Default J. and Permanent Inj. (“Pls.’
Br.”) at 3, ECF No. 45-2. Accordingly, on February 25, 2026, Plaintiffs moved for an entry of
default under Rule 55. See Dkt. No. 43. The Clerk entered default on February 27, 2026. See
Dkt. No. 44. Plaintiffs then moved for default judgment and a permanent injunction on March
27, 2026. See Dkt. No. 45.
III. LEGAL STANDARD
Federal Rule of Civil Procedure 55 governs the default judgment procedure. Fed. R. Civ.
P. 55. Rule 55(a) permits the entry of default by the clerk when “a party against whom a
judgment for affirmative relief is sought has failed to plead or otherwise defend, and that failure
is shown by affidavit or otherwise.” Id. Once the clerk enters the default under Rule 55(a), the
Plaintiff must “apply to the court for a default judgment” under Rule 55(b)(2).2 Id.
After an entry of default, the “defaulting defendant is deemed to admit every well-
pleaded allegation in the complaint.” AARP v. Sycle, 991 F. Supp. 2d 234, 238 (D.D.C. 2014)
(quoting Int’l Painters & Allied Trades Indus. Pension Fund v. R.W. Amrine Drywall Co., Inc.,
239 F. Supp. 2d 26, 30 (D.D.C. 2002)). That being said, “the determination of whether default
judgment is proper is committed to the discretion of the trial court.” Portillo v. Smith Commons
DC, LLC, No. CV 20-49-RC, 2021 WL 3287741, at *2 (D.D.C. Aug. 2, 2021). But “a court
should satisfy itself that is has personal jurisdiction before entering judgment against an absent
defendant.” Mwani v. bin Laden, 417 F.3d 1, 6 (D.C. Cir. 2005). And “a district court may deny
an application for default judgment where the allegations of the complaint, even if true, are
2
Rule 55(b)(1) provides for the entry of a default judgment by the clerk on the Plaintiffs’
request, but only “[if] the plaintiff’s claim is for a sum certain.” Id. Here, Plaintiffs have
requested injunctive relief and, therefore, needed to apply to the Court for a default judgment.
4
legally insufficient to make out a claim.” Gutierrez v. Berg Contracting Inc., No. CIV. A. 99-
3044 (TAF), 2000 WL 331721, at *2 (D.D.C. Mar. 20, 2000).
IV. ANALYSIS
A. Jurisdiction and Venue
Plaintiffs have asserted claims under various federal laws including: the Lanham Act, the
Computer Fraud and Abuse Act, and the Electronic Communications Privacy Act. See Compl.
¶¶ 54–90. As this Court found when it issued the TRO, there is subject matter jurisdiction over
those claims. See 28 U.S.C. § 1331 (“The district courts shall have original jurisdiction of all
civil actions arising under the Constitution, laws, or treaties of the United States.”); Ex Parte
TRO and O.S.C. Re Prelim. Inj. ¶ 1, ECF No. 12. Additionally, this Court has supplemental
jurisdiction over Plaintiff’s common law trespass to chattels, conversion, and unjust enrichment
claims. See 28 U.S.C. § 1367 (“[I]n any civil action of which the district courts have original
jurisdiction, the district courts shall have supplemental jurisdiction over all other claims that are
so related to claims in the action within such original jurisdiction that they form part of the same
case or controversy.”).
Venue is also proper in this judicial district as a substantial part of the events or
omissions giving rise to Plaintiff’s claims have occurred within this district. Plaintiffs have
identified that individuals targeted by Defendants’ attacks “predominately reside in the U.S., in
and around the Washington D.C. area.” See Compl. ¶ 14.
B. Service of Process
“Before a federal court may exercise personal jurisdiction over a defendant, the
procedural requirement of service of summons must be satisfied.” Mwani v. bin Laden, 417 F.3d
1, 8 (D.C. Cir. 2005) (quoting Omni Cap. Int’l, Ltd. v. Rudolf Wolff & Co., 484 U.S. 97, 104
5
(1987)). Additionally, to satisfy due process, the method of service must be “reasonably
calculated, under all the circumstances, to apprise interested parties of the pendency of the action
and afford them an opportunity to present their objections.” Mullane v. Central Hanover Bank &
Trust Co., 339 U.S. 306, 314 (1950). Plaintiffs alleged that Defendants are “Russia-based
cybercriminals,” and thus, Defendants can be served according to Rule 4(f), which governs
service to individuals in foreign countries. See Fed. R. Civ. P. 4. Rule 4(f)(3) permits service
“by other means not prohibited by international agreement, as the court orders.” Id. And “[t]o
validly effectuate service under Rule 4(f)(3), a plaintiff must affirmatively seek and obtain the
district court's authorization for a particular means of service.” Zavadovsky v. Rabl, No. CV 24-
1997 (RC), 2025 WL 2466024, at *10 (D.D.C. Aug. 27, 2025). Courts in this district have relied
on Rule 4(f) to permit both service by email and service by publication. See, e.g., Juniper
Networks, Inc. v. Bahattab, No. CIV.A. 07-1771 (PLF), 2008 WL 250584, at *2 (D.D.C. Jan. 30,
2008) (authorizing service by electronic mail under Rule 4(f)(3)); Kaplan v. Hezbollah, 715 F.
Supp. 2d 165, 167 (D.D.C. 2010) (authorizing service by publication under Rule 4(f)(3)).
Additionally, “in the case of persons missing or unknown, employment of an indirect and even a
probably futile means of notification is all that the situation permits and creates no constitutional
bar to a final decree foreclosing their rights.” Mwani, 417 F.3d at 8 (quoting Mullane, 339 U.S.
at 317).
Plaintiffs requested permission to serve Defendants by email and publication. Pls.’ Mem.
Supp. Appl. Emergency Ex Parte TRO and O.S.C. Re Prelim. Inj. at 34, ECF No. 4-1. This
Court subsequently granted that request and authorized service “by any means authorized by
law” including service by email and publication on “a publicly available Internet website.” Ex
Parte TRO and O.S.C. RE Prelim. Inj. at 10–11. Plaintiffs aver that they “served email addresses
6
associated with the Defendants’ Internet domains” on October 3, 2024. Pls.’ Br. at 3. And the
“emails were repeatedly opened and viewed by Defendants between October 3, 2024 and the
present.” Id. Additionally, Plaintiffs served Defendants by publication beginning on October 3,
2024.3 See id.
Despite online publication and emailed notice, Defendants ignored this lawsuit. The
combination of service by email and by publication does not violate any international agreement
and is reasonably calculated to achieve notice to the Defendants.4 Accordingly, the Court
concludes that service by email and publication was sufficient.
C. Default Judgment
As noted above, before entering a default judgment, the Court must evaluate Plaintiffs’
complaint to be sure that it sufficiently states a claim for which relief can be granted. See
Gutierrez, 2000 WL 331721, at *2.
D. Lanham Act Claims
Plaintiffs bring claims under the Lanham Act for trademark infringement and false
designation of origin. See Compl. ¶ 71–90. “To prevail on a claim for federal trademark
infringement . . . and false designation of origin, ‘the plaintiff must show (1) that it owns a valid
trademark, (2) that its trademark is distinctive or has acquired secondary meaning, and (3) that
3
Plaintiffs made use of the following public domain:
https://noticeofpleadings.com/starblizzard/. See Pls.’ Br. at 8.
4
Russia and the United States are both parties to the Hague Convention on the Service
Abroad of Judicial and Extrajudicial Documents in Civil or Commercial Matters, however, the
convention is inapplicable where, as here, the address of the persons to be served is unknown.
See Convention Done at the Hague Nov. 15, 1965;, T.I.A.S. No. 6638 (Feb. 10, 1969) (“This
Convention shall not apply where the address of the person to be served with the document is not
known.”); BP Prods. N. Am., Inc. v. Dagra, 236 F.R.D. 270, 271 (E.D. Va. 2006) (“[T]he Hague
Convention does not apply when a defendant’s address is unknown and the attempts at service
have been futile.”); see also Pls.’ Br. at 8 (“Plaintiffs were unable to specifically and definitively
determine the ‘real’ names and physical addresses of Defendants.”).
7
there is a substantial likelihood of confusion between the plaintiff’s mark and the alleged
infringer’s mark.’” AARP v. Sycle, 991 F. Supp. 2d 224, 229 (D.D.C. 2013) (quoting Globalw
Ltd. V. Carmon & Carmon Law Office, 452 F. Supp 2d 1, 26–27 (D.D.C. 2006)).
At the default judgment stage, Defendants have conceded that Microsoft and NGO-ISAC
member organization Carnegie Corporation of New York’s trademarks are valid and that they
have distinctive or secondary meaning. Microsoft and NGO-ISAC have also provided their
federal trademark registrations in their complaint. See Compl. Apps. B & C. Plaintiffs have
alleged that, as part of their scheme, Defendants present targets with “a webpage that appears to
be a Microsoft login page,” and that they use “Microsoft brands and trademarks . . . to confuse
Microsoft’s customers into clicking on Malicious links that they believe are associated with and
owned by Microsoft.” Compl. ¶ 45. As an example, Plaintiffs provide an image, see id. fig. 10,
of a “cloned phishing portal used by the . . . Defendants to directly impersonate [Microsoft].” Id.
¶ 37. The clear purpose and effect, when successful, in using Plaintiffs’ trademarks is to confuse
targets into thinking that Defendants’ domains are actually controlled by the owners of the
trademarks to induce targets to provide the sought after credentials or information. Additionally,
Plaintiffs allege that Defendants have impersonated Carnegie Corporation of New York, an
NGO-ISAC member, “in its spear phishing emails to its target victims.” Id. ¶ 50. Thus, the
allegation in the complaint sufficiently makes out claims of trademark infringement and false
designation of origin under the Lanham Act.
E. Computer Fraud and Abuse Act Claim
The CFAA provides a private cause of action for any person “suffering damage or loss”
from a violation of the act. 18 U.S.C. § 1030(g). Additionally, a civil action under § 1030(g)
can only be brought “if the conduct involves 1 of the factors set forth” in one of the five
8
subclauses of subsection (c)(4)(A)(i). Id. The only subclause relevant to Plaintiffs’ claims
requires “loss to 1 or more persons during any 1-year period . . . aggregating at least $5,000 in
value.” § 1030(4)(A)(i)(I). Defendants can violate CAFA in numerous ways: “intentionally
access[ing] a protected computer without authorization and as a result of such conduct, caus[ing]
damage and loss,” § 1030(a)(5)(C); “intentionally access[ing] a computer without authorization
or exceed[ing] authorized access, and thereby obtain[ing] information from any protected
computer,” § 1030(a)(2); and “knowingly caus[ing] the transmission of a program, information,
code or command, and as a result of such conduct, intentionally caus[ing] damage without
authorization to a protected computer. § 1030(a)(5)(A). The statute also defines a “protected
computer” as a computer “which is used in or affecting interstate or foreign commerce,”
§ 1030(e)(2), and it defines “exceeds authorized access” as “to access a computer with
authorization and to use such access to obtain or alter information in the computer that the
accesser is not entitled so to obtain or alter.” § 1030(e)(6).
Plaintiffs alleged that Defendants engineer their spear phishing emails to “deceive their
victims into thinking that they are responding to a legitimate email and to trick them into opening
a malicious link or attachment.” Compl. ¶ 19 (emphasis added). When successful, Defendants
“gain unfettered access and control of the victim’s inbox.” Id. In some cases, the Defendants
then use their access to “exfiltrate mailing lists and other contact information” as well as
“exfiltrate[] emails and attachments from the inbox of victims.” Id. ¶ 41. The core goal of
Defendants’ scheme is to gain access to target’s email accounts without their knowledge or
consent. Microsoft and NGO-ISAC have also alleged that they have expended more than
$1,000,000 and $200,000 respectively responding to these attacks, which is far greater than the
9
$5,000 loss required by the statute. See id. ¶ 48. Thus, Plaintiffs have successfully demonstrated
a claim against Defendants under the CFAA.
F. Electronic Communications Privacy Act Claim
ECPA prohibits “intentionally access[ing] without authorization a facility through which
an electronic communication service is provided.” 18 U.S.C. § 2701(a). ECPA provides a civil
cause of action for “any provider of electronic communication service, subscriber, or other
person aggrieved by any violation of this chapter.” § 2707(a).
Plaintiffs have alleged that “the Star Blizzard Defendants use stolen credentials and
replayed authentication tokens to directly sign in to victim email accounts.” Decl. of Sean Ensz
¶ 34, ECF No. 4-2. As an example, Plaintiffs allege that the Defendants, in a successful phishing
operation, were able to “obtain unique grant numbers associated with a[n] [NGO-ISAC] member
organization’s grant issuing process.” Pls.’ Br. at 17. This is precisely the conduct that ECPA
was designed to prevent. In re DoubleClick Inc. Priv. Litig., 154 F. Supp. 2d 497, 507 (S.D.N.Y.
2001) (“[Section 2701] aims to prevent hackers from obtaining, altering or destroying certain
stored electronic communications.”). Thus, Plaintiffs have successfully demonstrated a claim
against Defendants under ECPA.
G. Remaining Claims
Plaintiffs have brought four additional causes of action: trademark dilution under the
Lanham Act, trespass to chattels, conversion, and unjust enrichment. See Compl. ¶¶ 86–90, 91–
100, 107–114. However, “[b]ecause the Court has found that [Plaintiffs] [are] entitled to default
judgment on some [their] claims, the Court need not reach remaining claims as the scope of the
appropriate injunctive relief would not vary based on the merits of the remaining claims.”
Microsoft Corp. v. Does 1-2, No. 20-CV-1217 (LDH) (RER), 2021 WL 4755518, at *8
10
(E.D.N.Y. May 28, 2021), report and recommendation adopted, No. 20CV1217LDHRER, 2021
WL 4260665 (E.D.N.Y. Sept. 20, 2021).
H. Injunctive Relief
Plaintiffs seek a permanent injunction:
(1) prohibiting Defendants from operating or propagating the Star Blizzard
infrastructure; (2) permanently transferring ownership to Microsoft of known
malicious Star Blizzard domains identified in the Court’s prior injunction orders . .
. ; and (3) adopting an expedited process for overseeing issues with Defendants’
compliance with the permanent injunction including streamlined briefing and
regular telephonic hearings to immediately resolve these issues either by appointing
a Court Monitor or through another process under this Court’s supervision.
Pls.’ Br. at 2. “In determining whether to enter a permanent injunction, the Court considers a
modified iteration of the factors it utilizes in assessing preliminary injunctions: (1) success on the
merits, (2) whether the plaintiffs will suffer irreparable injury absent an injunction, (3) whether,
balancing the hardships, there is harm to defendants or other interested parties, and (4) whether
the public interest favors granting the injunction.” Am. C.L. Union v. Mineta, 319 F. Supp. 2d
69, 87 (D.D.C. 2004), dismissed, No. 04-5285, 2005 WL 263924 (D.C. Cir. Feb. 2, 2005).
As discussed above, Plaintiffs have succeeded by default on the merits of the action.
Plaintiffs further argue that they have suffered irreparable injury owing to the “[c]onsumer
confusion and injury to business goodwill” that is likely to occur if “Defendants are able to
continue to use domains bearing Plaintiffs’ trademarks and brands in furtherance of their
activities.” Pls.’ Br. at 22. This Court has previously found that, absent an injunction,
“irreparable harm will occur to Microsoft, Microsoft’s customer, NGO-ISAC, NGO-ISAC’s
customers, and the public.” Order Granting Mot. for Prelim. Inj. ¶ 8, ECF No. 12. Additionally,
with respect to Plaintiffs’ Lanham Act claims, “trademark infringement, by its very nature,
carries a presumption of harm.” See Hanley-Wood LLC v. Hanley Wood LLC, 783 F. Supp. 2d
11
147, 151 (D.D.C. 2011). Thus, there is ample reason to believe that Plaintiffs will suffer
irreparable injury absent a permanent injunction. Lastly, the Court finds that an injunction would
not harm Defendants or other interested parties, and that the public interest favors both
“protecting against further violation of federal copyright and trademark laws,” Hanley-Wood
LLC, 783 F. Supp. 2d at 151, and preventing the use of domains by Defendants to “conduct their
cybercriminal activity.” Pls.’s Br. at 2. Accordingly, the Court concludes that the Plaintiffs are
entitled to a permanent injunction as requested in their motion.
I. Plaintiffs’ Request for a Court Monitor
Plaintiffs have requested that the Court “adopt an expedited process of overseeing issues
with Defendants’ compliance with the permanent injunction.” Pls.’ Br. at 27. Plaintiffs have
also requested that this process “be overseen by a Court Monitor.” Id. Rule 53(a)(1)(C)
authorizes the appointment of a court monitor to “address pretrial and posttrial matters that
cannot be effectively and timely addressed by an available district judge or magistrate judge of
the district.” Fed. R. Civ. P. 53. There is precedent in cases similar to this one, in this district
and elsewhere, for the appointment of a court monitor to oversee a permanent injunction. See,
e.g., Microsoft Corporation v. John Does 1-2, Civil Action No. 19-cv-00716-ABJ; Microsoft
Corp. v. John Does 1-2, Civil Action No. 1:16-cv-993 (E.D. Va. Dec. 6, 2016). This Court
agrees with Plaintiffs that the appointment of a special master is warranted given Defendants’
ongoing establishment of new domains to effectuate their scheme, which has already required
Plaintiffs to move for a supplemental preliminary injunction on three separate occasions.
12
V. CONCLUSION
For the foregoing reasons, Plaintiffs’ Motion for Default Judgment and Permanent
Injunction is GRANTED. An order consistent with this Memorandum Opinion is separately and
contemporaneously issued.
Dated: August 5, 2026 RUDOLPH CONTRERAS
United States District Judge
13