Hold Security LLC v. Microsoft Inc

District Court, W.D. Washington·Decided December 5, 2023·No. 2:23-cv-00899·Unknown

Opinion

UNITED STATES DISTRICT COURT WESTERN DISTRICT OF WASHINGTON AT SEATTLE HOLD SECURITY LLC., a Wisconsin CASE NO. 23-899 Limited Liability Corporation, ORDER GRANTING MOTION TO Plaintiff, DISMISS v. MICROSOFT CORPORATION, a Washington Corporation, This matter comes before the Court on Defendant’s Motion to Dismiss. (Dkt. No. 21.) Having reviewed the Motion, Plaintiff’s Response (Dkt. No. 25), the Reply (Dkt. No. 28), and all other relevant material, the Court GRANTS the Motion. This case arises out of a contract between Plaintiff Hold Security (“Hold”) and Defendant Microsoft for services provided to Microsoft by Hold. Hold brings breach of contract claims and extra-contractual claims based on Microsoft’s alleged misuse of Hold’s services outside the intended use of the contract. Hold is an internet security company that assists corporations in protecting the security of their users’ online accounts against cyberattacks. (AC ¶ 3.2 (Dkt. No. 17); Response at 1.) One of the services Hold provides is the “Credential Integrity Service.” (AC ¶ 3.2.) This involves recovering stolen data, such as account log in information, and then providing the data to the

corporate client who can alert users that their account has been compromised. (Id.) Hold’s pricing model for its services is based on the expected benefit to the clients. (Id. at ¶ 3.3.) Hold factors in how many potential user victims there might be, the type of client, the type of customer the client has, and the type of data being recovered. (Id.) In 2014, Microsoft contacted Hold to obtain services related to recovering stolen account credentials. (AC ¶ 3.5.) Microsoft, through an employee, represented to Hold that it would limit the use of the recovered stolen data “to activities that are designed to prevent or mitigate harm to our customers.” (Id. at ¶ 3.13.) Microsoft assured Hold the data would not be used for any other purpose, and that it would destroy all copies of the data. (Id.) Based on Microsoft’s representations, Microsoft and Hold entered into negotiations “with the explicit and sole

objective of protecting certain Microsoft services, brands, and customers.” (Id. at ¶ 3.20.) Hold understood the protected Microsoft domains, services, and brands would be exclusively business-to-consumer – meaning the data supplied by Hold would only be used for Microsoft customers, not other businesses. (Id. at ¶ 3.2.) Hold specifically excluded business-to-business domains, services, and brands so as not to reduce Hold’s potential customer base. (Id.) Hold and Microsoft signed a contract in 2015, which incorporated a 2014 Non-Disclosure Agreement (“NDA”), a Master Supplier Services Agreement (“MSSA”), and a Statement of Work (“SOW”). Microsoft drafted the MSSA using one of its standard form agreements. (AC ¶ 3.23.) Hold contends that this means the MSSA contains terms and provisions that are not

applicable to its agreement with Microsoft. (Id.) Though Hold is silent as to who drafted the SOW, the language indicates both parties had a hand in drafting it. (See AC ¶ 3.24 (“Microsoft and Hold executed a Statement of Work . . . The parties agreed . . .”) The following are the relevant contract provisions that the Court required for its analysis:

The NDA The NDA provides in the pertinent part: [The parties] will not disclose the other’s confidential information to third parties; and [the parties] will use and disclose the other’s confidential information only for purposes of our business relationship with each other.

NDA Section 3(a). (Declaration of Jacob Thornburg ISO MTD, Exhibit A, NDA at 2 (Dkt. No. 22).) The MSSA The MSSA provides: Section 1 - Definitions (c): “Deliverables means all IP or other work product developed by Supplier (or a Subcontractor of Supplier for Microsoft under a SOW or as part of the Services; Section 3 – Ownership and use of the parties’ respective IP (e)(1): Ownership of IP Rights in Deliverables. All Deliverables are “work made for hire” for Microsoft under applicable copyright law . . . To the extent any Deliverables do not qualify as work made for hire, Supplier assigns all right, title, and interest in and to the Deliverables, including all IP rights, to Microsoft. Supplier waives, and agrees not to assert, any moral rights that may exist in the Deliverables. (Thornburg Decl. Ex. B.) The SOW The SOW provides: Section 3 – Description of Services and Delivery Schedule (b): Services. Microsoft has asked Supplier to deliver compromised “Account Credential Data” that have been recovered by the Supplier from sites on the Internet in order to reveal and protect against threats to services, brands and domains owned by Microsoft. “Account Credential

Data” are defined as lists of pairs of user id and password where user id is in form of a valid e- mail address [RFC 2822] only and password is non-blank. Supplier will conduct an extensive search of its data sources to provide Microsoft all currently held Account Credential Data as a one-time deliverable as a ‘catch-up’ . . . Per the line item details below, Supplier will provide compromised Account Credential Data on a daily basis: 1) Supplier will be collecting compromised accounts from sites on the Internet; the methods of which are proprietary to the Supplier. Supplier’s proprietary methods for gathering Account Credential Data from sites on the Internet shall not be considered Supplier IP incorporated into the Deliverables.

Compromised Account Credential Data will be used to check against Microsoft’s own services, brands and domains in order to protect Microsoft customers. The reason for including third-party account credential data is that Microsoft customers are able to use third-party user credentials (e.g., john@contoso.com) on Microsoft brands and services. All services shall be treated as Microsoft Confidential Information unless otherwise designated by Microsoft. Details - Supplier will on a daily basis collect and deliver to Microsoft compromised Account Credential Data for the following domains (The asterisk ‘*’ indicates matching of any

and all characters; e.g., hotmail.* would match for hotmail.com, hotmail.co.uk, hotmail.fr and many others): • microsoft.* • bing.* • hotmail.* • office365.* • live.* • office.* • outlook.* • legallery.* • msn.* • microsoftstore.com • passport.* • onmicrosoft.com • windowslive.* • microsoftonline.com • msncs.com • onmschina.cn • skype.* • *.TLD (third-party login • nokia.* credentials, e.g., ‘contoso.com’) • xbox.* The SOW also provides a payment and delivery schedule, which outlines the dates by which Hold must deliver all services to Microsoft and what Microsoft will pay in return. (SOW Sections 4, 5.) (Thornburg Decl. Ex. C.) The Lawsuit The parties performed pursuant to the contract from 2015 until 2020. (AC ¶ 3.31.) In 2020, Hold discovered Microsoft was using the data in a matter it believed to be outside the scope of the contract in the following three ways: First, Microsoft allegedly employed an updated version of its Active Directory Federation Service (“AD FS”) “enabling federated identity and access management.” (AC ¶ 3.32.) Hold alleges Microsoft used the data provided by Hold in order to create the AD FS. (Id.) Though Hold provides no information on what the AD FS is or how it works, it claims the AD FS does not protect Microsoft customers per se, but instead, is a business to business authentication service that directly competes with Hold. (Id.) Hold claims Microsoft breached the contract when it developed the AD FS because it uses the data outside the scope of the contract. (Response at 6.) Second, Microsoft allowed third parties to use the data through Microsoft’s web browser Edge. (AC ¶ 3.40.) The intent behind Edge is to protect the internet as a whole, therefore when

Free access — add to your briefcase to read the full text and ask questions with AI

Hold Security LLC v. Microsoft Inc, (W.D. Wash. 2023).

Hold Security LLC v. Microsoft Inc (Hold Security LLC v. Microsoft Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Jones Associates, Inc. v. Eastside Properties, Inc.
704 P.2d 681 (Court of Appeals of Washington, 1985)
Mendoza v. Rivera-Chavez
945 P.2d 232 (Court of Appeals of Washington, 1997)
Bailie Communications, Ltd. v. Trend Business Systems, Inc.
810 P.2d 12 (Court of Appeals of Washington, 1991)
Byrne v. Ackerlund
739 P.2d 1138 (Washington Supreme Court, 1987)
Hawk v. Mayer
220 P.2d 885 (Washington Supreme Court, 1950)
Berg v. Hudesman
801 P.2d 222 (Washington Supreme Court, 1990)
Badgett v. Security State Bank
807 P.2d 356 (Washington Supreme Court, 1991)
Swartz v. KPMG, LLC
401 F. Supp. 2d 1146 (W.D. Washington, 2004)
Keystone Land & Development Co. v. Xerox Corp.
94 P.3d 945 (Washington Supreme Court, 2004)
Hearst Communications, Inc. v. Seattle Times Co.
154 Wash. 2d 493 (Washington Supreme Court, 2005)
Young v. Young
164 Wash. 2d 477 (Washington Supreme Court, 2008)
Matson v. Kennecott Mines Co.
171 P. 1040 (Washington Supreme Court, 1918)
Spectrum Glass Co. v. Public Utility District No. 1
119 P.3d 854 (Court of Appeals of Washington, 2005)
Dragt v. Dragt/DeTray, LLC
139 Wash. App. 560 (Court of Appeals of Washington, 2007)