Court, Explained
U.S. Federal District Courts
←Back to docket
S.D.N.Y.Procedural orderFiled Sept. 18, 2025

Google LLC v. Does 1-25

Judge
James Oetken
Docket
1:25-cv-04503
Court
U.S. District Court · Southern District of New York
Pages
11
Civil ProcedureCriminal
In one sentence

In Google v. Does 1-25, Judge Oetken entered default judgment and a permanent injunction after finding violations of federal computer-fraud and racketeering laws.

Who this affects

Google LLC; Does 1-25 and people acting with them; Google customers and users of affected devices; and hosting companies, data centers, internet service providers, and others connected to the identified domains or infrastructure.

What happened

Google LLC sued Does 1-25 under the Computer Fraud and Abuse Act and the Racketeer Influenced and Corrupt Organizations Act, alleging that they operated the BadBox 2.0 botnet, spread malware, committed advertising fraud, and sold access to infected devices. The court said the botnet had infected more than ten million devices worldwide and tens of thousands in the Southern District of New York.

The defendants were served by email and publication but did not answer or otherwise defend the case. Because of their default, the court treated the complaint’s factual allegations as admitted and found that Google had established violations of both federal statutes. The court also found that Google faced continuing harm that money alone could not adequately repair.

Judge J. Paul Oetken granted Google’s motion for default judgment and a permanent injunction and entered judgment for Google against the defendants. The order permanently barred the defendants and people acting with them from spreading malware, operating or supporting the botnet, selling proxy access, committing advertising fraud, and engaging in related activities. It also allowed Google to serve the order on hosting companies and service providers, which were directed to take steps to block or disable related domains and preserve information and evidence.

The detailed version

For law students, journalists, and other readers who want the full reasoning

Case
Google LLC v. Does 1-25 · No. 1:25-cv-04503
Judge
James Oetken
Date
Sept. 18, 2025

Background

Google moved for default judgment and entry of a permanent injunction against Does 1-25. The opinion describes the defendants as participants in the BadBox 2.0 botnet, which allegedly involved malware, command-and-control servers, advertising fraud, and the sale of access to infected devices. The court found that the botnet had infected more than ten million devices worldwide, including tens of thousands of devices in the Southern District of New York.

The court found that the defendants had been served with the summons, complaint, and other pleadings by email and publication on a publicly available website. It also found that they had actual notice based on media coverage and their responses to Google’s disruption of the botnet. They did not appear, answer, or otherwise defend the action. The Clerk entered default under Rule 55(a) on August 27, 2025.

Jurisdiction and Liability

The court found federal-question jurisdiction under 28 U.S.C. § 1331. It found personal jurisdiction because the defendants allegedly distributed malware, infected devices, sent commands to infected computers, and sold access to infected devices in the district and New York State. It found venue proper under federal venue provisions and the Racketeer Influenced and Corrupt Organizations Act.

Because the defendants defaulted, the complaint’s factual allegations were deemed admitted, and the court also considered evidence in Google’s supporting papers. The court found that Google established its claims under two statutes:

- Computer Fraud and Abuse Act: The court found that the defendants intentionally transmitted malware and commands to protected computers without authorization, intentionally caused damage, and accessed protected computers to further fraud and obtain something of value. The court found that the defendants infected devices without users’ knowledge or consent and caused Google more than $5,000 in loss during a one-year period. - Racketeer Influenced and Corrupt Organizations Act: The court found that the defendants operated an enterprise with a shared purpose of spreading malware, building a botnet, and carrying out criminal schemes for profit. It found a pattern of racketeering activity based on alleged Computer Fraud and Abuse Act violations and wire fraud. The court also found that Google suffered injury to its business or property through advertising fraud, refunds for fraudulent traffic, the sale of residential proxy access, and the costs of investigating and combating the schemes.

Permanent Injunction

The court applied the factors for a permanent injunction: irreparable harm, inadequate legal remedies, the balance of hardships, and the public interest. It found that Google had shown each factor. The court cited threats to internet and device security, continuing harm to Google’s goodwill and reputation, economic losses, and the risk of further attacks or other criminal schemes. It also found that the defendants had continued conduct covered by earlier court orders, including attempts to establish new command-and-control servers and infect additional devices.

Order

The court granted Google’s motion for default judgment and entry of a permanent injunction, declared the defendants in default, and awarded judgment in Google’s favor against them. The injunction applies worldwide to the defendants and other restrained parties who receive actual notice. It prohibits them from accessing Google customers’ protected computers without authorization, sending malicious code, operating or facilitating the BadBox 2.0 botnet, compromising devices or networks, stealing information, selling proxy services, committing advertising fraud, using specified domains, and undertaking similar activities that harm Google, its customers, or the public.

The court also authorized Google to serve the order on hosting companies, data centers, and other service providers connected to domains identified in the complaint. Those providers were directed to take reasonable steps to identify and block related traffic, disable or suspend services, prevent circumvention, preserve evidence, provide identifying information about the operators, and assist in implementing the order. Violations of the injunction may be treated and prosecuted as contempt of court.

The authoritative version

Read the full 11-page opinion on CourtListener, the free public archive maintained by the Free Law Project.

Open opinion PDF →
Summary written with AI assistance. See how summaries are made. Spot something wrong? Tell us.