Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • PATENT—Fed. Cir.: PTAB’s obviousness finding reversed; Board applied erroneous standard to analysis of secondary considerations
    • COPYRIGHT—E.D.N.Y.: Court lacks power to alter Copyright Office records
    • PATENT—D.N.J.: LG’s request for new trial denied in patent dispute with Mondis
    • TECHNOLOGY/INTERNET—9th Cir.: Security software firm’s use of ‘malicious’ and ‘threat’ to describe competitor’s products actionable under Lanham Act
    • TRADE SECRETS—N.D. Ohio: Court tosses DTSA claims against medical group co-founder
    • TRADEMARK—4th Cir.: Injunction lifted over mark for video game chairs
    • TRADEMARK—TTAB: EL BURRO marks were not likely to be confused in Mexican restaurant context
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    IP Law Daily, TECHNOLOGY/INTERNET—9th Cir.: Security software firm’s use of ‘malicious’ and ‘threat’ to describe competitor’s products actionable under Lanham Act, (Jun 6, 2023)

    Law Firms Mentioned:Budd Law PLLC
    Organizations Mentioned:Enigma Software Group USA, LLC | Enigma Software Group, Inc. | Hueston Hennigan, LLP | Malwarebytes, Inc.

    By Justin Marcus Smith, J.D.

    A dissenting judge warned that the majority opinion will have a chilling effect on cybersecurity companies if they perceive civil liability may attach if a court disagrees with a classification of a program as “malware.”

    On Enigma Softwa ...

    By Justin Marcus Smith, J.D.

    A dissenting judge warned that the majority opinion will have a chilling effect on cybersecurity companies if they perceive civil liability may attach if a court disagrees with a classification of a program as “malware.”

    On Enigma Software Group USA, LLC’s (Enigma’s) appeal of a district court’s dismissal of its unfair competition claims against competitor Malwarebytes, Inc. (Malwarebytes), a divided panel of the United States Court of Appeals for the Ninth Circuit has concluded that when a computer security business describes a competitor’s software as “malicious” and a “threat” to a customer’s computer, the statement is not protected opinion, but an assertion of objective fact, actionable as false advertising under the Lanham Act. The district court’s dismissal of Enigma’s false advertising claim was reversed. The Ninth Circuit also found that Malwarebytes was subject to personal jurisdiction in New York, making New York choice of law applicable. Claims for tortious interference with business relations and violation of New York General Business Law (NYGBL) § 349 were revived, while dismissal of Enigma’s tortious interference with contractual relations claim was affirmed for failure to identify a specific contract. Circuit Judge Bumatay filed a dissenting opinion to express his view that Malwarebyte’s statements constituted subjective opinion not subject to a claim for false advertising (Enigma Software Group USA, LLC v. Malwarebytes, Inc., June 2, 2023, Clifton, R.).

    Background. Both plaintiff Enigma, a Florida limited liability company, and defendant Malwarebytes, headquartered in California, are competing providers of software that assists Internet users to filter unwanted content from their computers. While both companies are competitors in the development of computer security products, Enigma markets anti-malware software known as "SpyHunter," and Malwarebytes markets "Malwarebytes Anti-Malware" (MBAM).

    In its complaint filed in 2016, Enigma alleged that Malwarebytes revised MBAM’s threat detection criteria to identify SpyHunter and other Enigma products as threats to consumers. According to Enigma, Malwarebytes’ actions disrupted or disabled Enigma’s products on consumers’ computers, so as to give Malwarebytes an unfair competitive advantage. Enigma alleged that it suffered immediate harm in the form of lost sales and revenue and irreparable harm to its business reputation.

    The district court initially granted Enigma’s motion to dismiss on the basis that Malwarebytes was immune from suit under the safe harbor provided by Section 230 of the Communications Decency Act (CDA). Among other things, Section 230 of the CDA immunizes computer-software providers from liability from claims arising from actions the provider takes to help users block certain types of unwanted, online material. Enigma appealed, and the Ninth Circuit reversed and remanded, holding that the "Good Samaritan" immunity provided to computer service providers in Section 230(c)(2) of the CDA does not bar claims based on allegations of removal of "objectionable" content for competitive purposes.

    On remand, Enigma filed a second amended complaint (SAC) asserting four causes of action: (1) false advertising in violation of the Lanham Act, 15 U.S.C. § 1125(a)(1)(B); (2) a violation of NYGBL § 349, prohibiting deceptive and unlawful business practices; (3) tortious interference with contractual relations; and (4) tortious interference with business relations. The district court then granted Malwarebytes’ Fed. R. Civ. P. 12(b)(6) motion to dismiss the SAC on the basis that all of Enigma’s claims were insufficient as a matter of law, but primarily on the basis that Malwarebytes’ designations of Enigma products were “non-actionable statements of opinion.” Enigma again appealed.

    Lanham Act false advertising claim. The Ninth Circuit held that Enigma’s allegations, taken as true on a motion to dismiss, were sufficient to state a Lanham Act false advertising claim. Malwarebytes used terminology “substantively meaningful and verifiable in the cybersecurity context.” Statements that Enigma products contained “malicious” files or were a “threat” to the security of users’ computers were not mere puffery or protected opinion, according to the court. Context was paramount. The court found the users would have interpreted Malwarebytes’ statements as identification of malware, factual assertions, because Malwarebytes was in the business of identifying malware. The court concluded that Malwarebytes' statements that Enigma's products were a "threat" and "malicious" were actionable because they constituted statements of objective fact, subject to being found false. On the other hand, the majority determined that Malwarebytes’ use of the phrase “potentially unwanted program” or “PUPs,” to describe Enigma’s products was too vague to be a factual assertion.

    Personal jurisdiction. The Southern District of New York did not decide Malwarebytes’ challenge to personal jurisdiction before it transferred the matter to the Northern District of California. The Ninth Circuit found that the Malwarebytes website easily qualified as interactive, under Weiss, to confer personal jurisdiction in New York. The Ninth Circuit also found that Malwarebytes transacted business in New York through its website because the website allowed New York users to buy and download products. Malwarebytes did not have to be physically present in New York to transact business there. Enigma’s claims also partially arose out of Malwarebytes’ transaction of business in New York. The Ninth Circuit also found conformity with the Due Process Clause under New York’s long-arm statute. The court accordingly reversed the district court’s holding that New York lacked personal jurisdiction over Malwarebytes. New York law would therefore apply, not California law, at least to Malwarebytes’ transactions with customers in New York. The choice of law question as to customers elsewhere was not before the court.

    State law claims. The court reversed and remanded dismissal of the NYGBL § 349 claim because the Lanham Act claim was actionable and New York law otherwise applied.

    As to the tortious interference claims, the district court’s application of California law was no longer pertinent. New York law applied. The court held that Enigma plausibly demonstrated each element of a New York claim for tortious interference with business relations. The district court’s dismissal for Enigma’s inability to identify an independent wrongful act was erroneous. The reinstated Lanham Act and NYGBL § 349 claims certainly qualified under California law, but more importantly, New York law did not require an independent wrongful act. New York law only required a showing of malice.

    However, as to tortious interference with contractual relations, Enigma failed to identify any contractual breach that Malwarebytes induced. The mere cancellation of subscriptions did not show any contractual breach by those customers. Although the district court improperly applied California law, the dismissal result with respect to contractual relations was still correct under New York law.

    Concurrence. International Trade Judge M. Miller Baker, sitting by designation, concurred but sought to elaborate on the choice of law analysis. The parties did not address choice of law beyond the personal jurisdiction question. The majority opinion therefore assumed that New York choice of law rules required application of that state’s substantive law to Enigma’s state law claims save for claims based on Malwarebytes’ transactions with customers elsewhere.

    Dissent. Circuit Judge Patrick Bumatay did not agree that the Lanham Act was applicable to Malwarebytes’ statements. Judge Bumatay reasoned that flagging a competitor’s products as “potentially unwanted,” a “threat,” or “malicious,” were not expressions of fact. Malwarebytes’ statements were subjective because they were not readily verifiable, and without “objective meaning,” they were opinions. Treating Malwarebytes statements as fact sent a “chilling message” to cybersecurity companies that civil liability may now attach if a court later disagrees with classification of a program as “malware.” The court did not have the cybersecurity competence to “arrogate” to itself “regulatory oversight over cybersecurity.”

    The Case is No. 21-16466.

    Attorneys: Terry Budd (Budd Law PLLC) for Enigma Software Group USA, LLC. John Charles Hueston (Hueston Hennigan, LLP) for Malwarebytes, Inc.

    Companies: Enigma Software Group USA, LLC; Malwarebytes, Inc.

    Cases: TechnologyInternet AlaskaNews ArizonaNews CaliforniaNews HawaiiNews IdahoNews MontanaNews NevadaNews OregonNews WashingtonNews

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use