Microsoft Corporation v. John Does 1-2

District Court, District of Columbia·Decided August 5, 2026·No. Civil Action No. 2024-2719·Published

Opinion

UNITED STATES DISTRICT COURT FOR THE DISTRICT OF COLUMBIA

Microsoft Corporation, a Washington State Corporation, NGO-ISAC, a New York State Non-Profit Organization, :

:

Plaintiffs, : Civil Action No.: 24-2719 (RC)

:

v. : Re Document No.: 45 :

John Does 1-2, Controlling A Computer Network and Thereby Injuring Plaintiff and Its Customers. :

:

Defendants. :

MEMORANDUM OPINION

GRANTING MICROSOFT & NGO-ISAC’S MOTION FOR DEFAULT JUDGMENT AND PERMANENT INJUNCTION

I. INTRODUCTION

This matter comes before the Court on Plaintiffs’ motion for a default judgment and permanent injunction. Plaintiffs, Microsoft Corporation (“Microsoft”) and NGO Information Sharing and Analysis Center (“NGO-ISAC”), bring claims under the Computer Fraud and Abuse Act (“CFAA”), Electronic Communications Privacy Act (“ECPA”), the Lanham Act, and the common law doctrines of trespass to chattels, conversion, and unjust enrichment. Plaintiffs allege that Defendants, whom they characterize as “Russia-based cybercriminals,” operate “an ongoing internet-based spear phishing operation known as ‘Star Blizzard.’” Compl. ¶¶ 1, 17. “Spear phishing is a type of personalized attack in which the cybercriminal attempts to acquire sensitive information or access a computer by sending a fake email message that appears to be legitimate,” which tricks the target into clicking on a malicious link, attachment, or providing

confidential information or credentials. Id. ¶ 19. The scheme is allegedly directed at Microsoft and its customers, NGO-ISAC’s member organizations, and the general public. Id. During the pendency of this litigation, Defendants have not appeared or responded in any manner, and “[d]efendants’ true identities remain unknown despite extensive discovery efforts.” Decl. of Anna Z. Saber ¶ 26. Upon review of the record and all relevant documents, this Court grants Plaintiffs’ motion.

II. FACTUAL BACKGROUND

A. Relevant Facts

Plaintiffs allege that Defendants are the masterminds of “an ongoing internet-based spear phishing operation known as ‘Star Blizzard.’” Compl. at 1. According to Plaintiffs, Defendants begin their attacks by scouring “public facing sources of intelligence,” including social media, to identify targets. See id. ¶ 22. Next, Defendants will “open a new email account,” which they design “to match or look similar to legitimate addresses and account names.” See id. ¶ 24. For example, Defendants have “impersonate[d] NGO-ISAC member Carnegie Corporation of New York . . . in [their] spear phishing emails.” The Defendants then use the email account to contact their target. See id. ¶ 25. Their communications “begin[] with rapport building and then escalate[] to the sending of a fictitious attachment.” Id. ¶ 26. At this point, “Defendants attach a file or include[] a link to a file share platform like OneDrive.” Id. To effectuate their attacks, Defendants control hundreds of internet domains. See id. ¶ 20. When targets click on links sent to them by the Defendants, they are directed to one of those domains. See id. ¶ 35. The domains appear as though they were the login page for a Microsoft service. See id. ¶ 36. As an example, the spoofed login pages will often include the “language ‘©Microsoft 2016’” to convince the target that “the link is to a legitimate Microsoft webpage.” See id. ¶ 45. More generally,

Defendants use “Microsoft brands and trademarks . . . to confuse Microsoft’s customers into clicking on malicious links that they believe are associated with and owned by Microsoft.” See id. ¶ 46. “Once a victim inputs their login credentials, Star Blizzard is able to capture the credential.” Id. ¶ 39. The Defendants then use the captured credentials to gain access to the target’s email account. See id. Once in possession of the target’s login credentials, “[t]he final step of Star Blizzard’s attack sequence is data exfiltration.” Id. ¶ 41. Defendants have used their newfound access to target’s emails to set up rules “that would automatically forward an email received by the victim to another email address,” and have extracted “mailing lists and other contact information,” which aid Defendants in other attacks. See id. In response to these attacks, Microsoft has “expended more than $1,000,000” to investigate the harms resulting from these attacks, and Carnegie Corporation of New York, a member of NGO-ISAC, has similarly expended “approximately $200,000.” Id. ¶ 48.

B. Procedural History

On September 24, 2024, Plaintiffs filed their complaint. See generally Compl. At the same time, Plaintiffs moved for a temporary restraining order (“TRO”) and a preliminary injunction transferring ownership of Star Blizzard-controlled domains to Plaintiffs, which this Court granted on September 25, 2024.1 Subsequently, this Court granted requests for several supplemental preliminary injunctions. See Dkt. No. 22; Dkt. No. 28; Dkt. No. 41.

1 The purpose of transferring domains controlled by Defendants to Microsoft is so that “any time a user clicks on a link in a spear phishing email and provides their username and password, that information will be prevented from going to the Defendants at the Star Blizzard- controlled domains, because those domains will be hosted on a Microsoft-controlled, secure server, beyond the control of the Star Blizzard Defendants.” Decl. of Sean Ensz ¶ 55, ECF No. 4-2.

Defendants have not responded to the litigation in any capacity since Plaintiffs first served Defendants on October 3, 2024. See Pls.’ Br. Supp. Default J. and Permanent Inj. (“Pls.’ Br.”) at 3, ECF No. 45-2. Accordingly, on February 25, 2026, Plaintiffs moved for an entry of default under Rule 55. See Dkt. No. 43. The Clerk entered default on February 27, 2026. See Dkt. No. 44. Plaintiffs then moved for default judgment and a permanent injunction on March 27, 2026. See Dkt. No. 45.

III. LEGAL STANDARD

Federal Rule of Civil Procedure 55 governs the default judgment procedure. Fed. R. Civ.

P. 55. Rule 55(a) permits the entry of default by the clerk when “a party against whom a judgment for affirmative relief is sought has failed to plead or otherwise defend, and that failure is shown by affidavit or otherwise.” Id. Once the clerk enters the default under Rule 55(a), the Plaintiff must “apply to the court for a default judgment” under Rule 55(b)(2).2 Id.

After an entry of default, the “defaulting defendant is deemed to admit every well-

pleaded allegation in the complaint.” AARP v. Sycle, 991 F. Supp. 2d 234, 238 (D.D.C. 2014) (quoting Int’l Painters & Allied Trades Indus. Pension Fund v. R.W. Amrine Drywall Co., Inc., 239 F. Supp. 2d 26, 30 (D.D.C. 2002)). That being said, “the determination of whether default judgment is proper is committed to the discretion of the trial court.” Portillo v. Smith Commons DC, LLC, No. CV 20-49-RC, 2021 WL 3287741, at *2 (D.D.C. Aug. 2, 2021). But “a court should satisfy itself that is has personal jurisdiction before entering judgment against an absent defendant.” Mwani v. bin Laden, 417 F.3d 1, 6 (D.C. Cir. 2005). And “a district court may deny an application for default judgment where the allegations of the complaint, even if true, are

2 Rule 55(b)(1) provides for the entry of a default judgment by the clerk on the Plaintiffs’

request, but only “[if] the plaintiff’s claim is for a sum certain.” Id. Here, Plaintiffs have requested injunctive relief and, therefore, needed to apply to the Court for a default judgment.

legally insufficient to make out a claim.” Gutierrez v. Berg Contracting Inc., No. CIV. A. 99- 3044 (TAF), 2000 WL 331721, at *2 (D.D.C. Mar. 20, 2000).

IV. ANALYSIS

Free access — add to your briefcase to read the full text and ask questions with AI

Microsoft Corporation v. John Does 1-2, (D.D.C. 2026).

Microsoft Corporation v. John Does 1-2 (Microsoft Corporation v. John Does 1-2) — published by Counsel Stack Legal Research, free access to 12M+ legal documents.

Related

Mullane v. Central Hanover Bank & Trust Co.
339 U.S. 306 (Supreme Court, 1950)
Mwani, Odilla Mutaka v. Bin Ladin, Usama
417 F.3d 1 (D.C. Circuit, 2005)
Jackson v. District of Columbia
783 F. Supp. 2d 9 (District of Columbia, 2009)
American Civil Liberties Union v. Mineta
319 F. Supp. 2d 69 (District of Columbia, 2004)
In Re DoubleClick Inc. Privacy Litigation
154 F. Supp. 2d 497 (S.D. New York, 2001)
Kaplan v. Hezbollah
715 F. Supp. 2d 165 (District of Columbia, 2010)
Aarp v. Sycle
991 F. Supp. 2d 234 (District of Columbia, 2014)
Aarp v. Sycle
991 F. Supp. 2d 224 (District of Columbia, 2013)
BP Products North America, Inc. v. Dagra
236 F.R.D. 270 (E.D. Virginia, 2006)