Hold Security LLC v. Microsoft Inc

District Court, W.D. Washington·Decided April 2, 2024·No. 2:23-cv-00899·Unknown

Opinion

UNITED STATES DISTRICT COURT WESTERN DISTRICT OF WASHINGTON AT SEATTLE HOLD SECURITY, CASE NO. C23-899 Plaintiff, ORDER GRANTING MOTION TO DISMISS v. Defendant. This matter comes before the Court on Defendant’s Motion to Dismiss. (Dkt. No. 39.) Having reviewed the Motion, the Response (Dkt. No. 44), the Reply (Dkt No. 46), and all other supporting material, the Court GRANTS the Motion. This case arises out of a contract between Microsoft Corporation (“Microsoft”) and Hold Security (“Hold”). Hold alleges Microsoft breached the contract by using Hold’s services outside the intended scope of the contract. (Response at 1.) This is Hold’s second attempt to bring claims against Microsoft, following the Court’s dismissal of its First Amended Complaint for failure to state a claim for relief. (Dkt. No. 37.) Hold then brought its Second Amended Complaint (“SAC” (Dkt. No. 38)) within the allotted time frame, and Microsoft now moves to dismiss the SAC with prejudice. Hold is an internet security company that provides a “Credential Integrity Service.” Hold

conducts searches of the “Dark Web” to recover stolen and/or compromised login credentials and then shares that information with its company customers so they can identify and alert users’ who have had their login credentials stolen or otherwise compromised. (SAC ¶¶ 3.1, 3.3-3.4.) In 2014, Microsoft contacted Hold about utilizing Hold’s services. (Id. at ¶ 3.8.) Microsoft represented to Hold that its sole objective in using the Compromised Account Credential Data retrieved by Hold was to check against the login credentials of Microsoft customers for Microsoft’s own services, products, and domains. (Id. at ¶ 3.12.) Microsoft also allegedly told Hold that it would delete and discard all compromised Account Credential Data once it had been checked against the login credentials of Microsoft customers. (Id. at ¶ 3.13.) Based on these representations Hold discussed pricing and service options, and the parties began

negotiating a contract. (Id. at ¶¶ 3.8-3.16.) The Contract In 2015, Microsoft and Hold executed a Master Supplier Services Agreement (“MSSA”), which provides in the pertinent part: Section 1 - Definitions (c): “Deliverables means all IP or other work product developed by Supplier (or a Subcontractor of Supplier for Microsoft under a Statement of Work (“SOW”) or as part of the Services; Section 3 – Ownership and use of the parties’ respective IP

(e)(1): Ownership of IP Rights in Deliverables. All Deliverables are “work made for hire” for Microsoft under applicable copyright law . . . To the extent any Deliverables do not qualify as work made for hire, Supplier assigns all right, title, and interest in and to the Deliverables, including all IP rights, to Microsoft. Supplier waives, and agrees not to assert, any

moral rights that may exist in the Deliverables. (Declaration of Jacob Thornburgh ISO MTD, Exhibit B, MSSA (Dkt. No. 22).) Microsoft and Hold also executed a Statement of Work (“SOW”) at the same time as the MSSA, which is incorporated into the MSSA. The SOW provides: Section 3 – Description of Services and Delivery Schedule (b): Services. Microsoft has asked Supplier to deliver compromised “Account Credential Data” that have been recovered by the Supplier from sites on the Internet in order to reveal and protect against threats to services, brands and domains owned by Microsoft. “Account Credential Data” are defined as lists of pairs of user id and password where user id is in form of a valid email address [RFC 2822] only and password is non-blank.

Supplier will conduct an extensive search of its data sources to provide Microsoft all currently held Account Credential Data as a one-time deliverable as a ‘catch-up’ . . . Per the line item details below, Supplier will provide compromised Account Credential Data on a daily basis: 1) Supplier will be collecting compromised accounts from sites on the Internet; the methods of which are proprietary to the Supplier. Supplier’s proprietary methods for gathering Account Credential Data from sites on the Internet shall not be considered Supplier IP incorporated into the Deliverables. Compromised Account Credential Data will be used to check against Microsoft’s own services, brands and domains in order to protect Microsoft customers. The reason for including

third-party account credential data is that Microsoft customers are able to use third-party user credentials (e.g., john@contoso.com) on Microsoft brands and services. All services shall be treated as Microsoft Confidential Information unless otherwise designated by Microsoft.

Details - Supplier will on a daily basis collect and deliver to Microsoft compromised Account Credential Data for the following domains (The asterisk ‘*’ indicates matching of any and all characters; e.g., hotmail.* would match for hotmail.com, hotmail.co.uk, hotmail.fr and many others): • microsoft* • bing.* • hotmail* • office365.* • live.* • office.* • outlook.* • legallery.* • msn.* • microsoftstore.com • passport.* • onmicrosoft.com • windowslive.* • microsoftonline.com • msncs.com • onmschina.cn • skype* • *.TLD (third party login • nokia.* credentials, e.g., • xbox.* ‘contoso.com’) The SOW also provides a payment and delivery schedule, which outlines the dates by which Hold must deliver all services to Microsoft and what Microsoft will pay in return. (SOW Sections 4, 5.) (Thornburgh Decl. Ex. C.) Microsoft’s Use of the Data Hold alleges that after it executed the contract with Microsoft, Microsoft employed an updated version of its Active Directory Federation Service (AD FS). (SAC ¶ 3.25.) Microsoft’s AD FS service provides security services for third parties’ products by using the Compromised Account Credential Data to check against the login credentials of the third-party’s users. (Id.) Hold claims Microsoft breached their contract by employing this service because it directly competes with Hold’s services. (Id.) Microsoft also launched an updated version of its Microsoft Edge web browser that uses the Compromised Account Credential Data to check against any login credentials entered into

any website, not just Microsoft’s services, brands, and domains. (SAC ¶ 3.26.) Hold alleges the use of the compromised login data for this use is outside the scope of the contract. (Id. at ¶ 3.27.) Lawsuit Hold then brought this lawsuit against Microsoft alleging several breach of contract claims. The Court dismissed Hold’s First Amended Complaint for failure to state a claim for relief. Hold amended its complaint and filed its SAC alleging breach of contract as well as a Washington Consumer Protection Act (“CPA”) claim. Microsoft now moves to dismiss Hold’s SAC for failing to state a claim for relief under Federal Rule of Civil Procedure 12(b)(6). A. Legal Standard

Free access — add to your briefcase to read the full text and ask questions with AI

Hold Security LLC v. Microsoft Inc, (W.D. Wash. 2024).

Hold Security LLC v. Microsoft Inc (Hold Security LLC v. Microsoft Inc) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Early v. Packer
537 U.S. 3 (Supreme Court, 2002)
Bell Atlantic Corp. v. Twombly
550 U.S. 544 (Supreme Court, 2007)
Ashcroft v. Iqbal
556 U.S. 662 (Supreme Court, 2009)
Hangman Ridge Training Stables, Inc. v. Safeco Title Insurance
719 P.2d 531 (Washington Supreme Court, 1986)
Jones Associates, Inc. v. Eastside Properties, Inc.
704 P.2d 681 (Court of Appeals of Washington, 1985)
Mendoza v. Rivera-Chavez
945 P.2d 232 (Court of Appeals of Washington, 1997)
Berg v. Hudesman
801 P.2d 222 (Washington Supreme Court, 1990)
Badgett v. Security State Bank
807 P.2d 356 (Washington Supreme Court, 1991)
Wagner v. Wagner
621 P.2d 1279 (Washington Supreme Court, 1980)
Vance v. Ingram
133 P.2d 938 (Washington Supreme Court, 1943)
Sing v. John L. Scott, Inc.
134 Wash. 2d 24 (Washington Supreme Court, 1997)
Keystone Land & Development Co. v. Xerox Corp.
94 P.3d 945 (Washington Supreme Court, 2004)
Hearst Communications, Inc. v. Seattle Times Co.
154 Wash. 2d 493 (Washington Supreme Court, 2005)
Matson v. Kennecott Mines Co.
171 P. 1040 (Washington Supreme Court, 1918)