A federal court has ruled in favor of Microsoft Corporation and the NGO Information Sharing and Analysis Center (NGO-ISAC) in a case against unidentified cybercriminals operating a phishing scheme. The court's decision grants Microsoft a permanent injunction to protect its customers and brand from ongoing cyber threats. This ruling is significant as it highlights the legal measures available to combat cybercrime and the responsibilities of tech companies in safeguarding their users.
The case, titled Microsoft Corporation v. John Does 1-2, was filed in the District Court for the District of Columbia (Civil Action No. 2024-2719) on August 5, 2026. The court's ruling affects Microsoft, its customers, and the broader public, emphasizing the need for vigilance against cyber threats.
Microsoft and NGO-ISAC accused the defendants, described as “Russia-based cybercriminals,” of running a phishing operation known as “Star Blizzard.” This operation involved sending fake emails that appeared legitimate to trick users into providing sensitive information. The court noted that the defendants had not responded to the lawsuit, leading to a default judgment in favor of the plaintiffs.
The plaintiffs claimed that the defendants used sophisticated tactics to deceive their targets. They would create fake email accounts that closely resembled legitimate addresses and impersonate trusted organizations, such as the Carnegie Corporation of New York, to gain the trust of their victims. Once a target clicked on a malicious link, the defendants could steal login credentials and access sensitive information.
Microsoft reported spending over $1 million to combat the effects of these cyberattacks, while NGO-ISAC's member organization incurred costs of approximately $200,000. The plaintiffs argued that the defendants' actions caused significant harm, not only to their organizations but also to their customers.
The court's ruling included several key components. Judge Rudolph Contreras granted Microsoft and NGO-ISAC's motion for a default judgment and a permanent injunction against the defendants. The court stated, "Plaintiffs have succeeded by default on the merits of the action," and emphasized the need for an injunction to prevent further harm. The ruling prohibits the defendants from operating the Star Blizzard infrastructure and mandates the transfer of ownership of malicious domains to Microsoft.
Additionally, the court agreed to establish an expedited process for overseeing compliance with the permanent injunction. This includes regular hearings to address any issues that may arise, ensuring that the defendants cannot easily evade the court's order.
The impact of this ruling extends beyond this specific case. It underscores the importance of legal actions in combating cybercrime and protecting consumers. The court's decision serves as a warning to potential cybercriminals that they may face serious legal consequences for their actions.
Going forward, this ruling may set a precedent for similar cases involving cybercrime and phishing schemes. It highlights the legal avenues available to tech companies and organizations in their efforts to protect their users and brands from malicious actors.
While the defendants in this case remain unidentified, the court's ruling emphasizes the need for vigilance and proactive measures against cyber threats. Microsoft and NGO-ISAC are likely to continue their efforts to secure their networks and protect their customers from future attacks.
The court's decision can potentially be appealed, but details regarding any related cases or appeals were not available in the court filing. The ruling represents a significant step in the ongoing battle against cybercrime and the protection of digital security.










