DCT

7:26-cv-00274

Zapfraud Inc v. Google LLC

Key Events
Complaint
complaint Intelligence

I. Executive Summary and Procedural Information

  • Parties & Counsel:
  • Case Identification: 7:26-cv-00274, W.D. Tex., Midland-Odessa Division, 07/20/2026
  • Jurisdiction: The complaint alleges subject-matter jurisdiction under 28 U.S.C. §§ 1331 and 1338(a) and personal jurisdiction over Defendants under the Texas Long Arm Statute Compl. p. 4
  • Standing: ZapFraud alleges it owns the entire right, title, and interest in and to each of the Asserted Patents, including the right to sue for and recover damages for past, present, and future infringement Compl. ¶2
  • Venue Allegations: Venue is alleged based on Defendants maintaining regular and established places of business within the Western District of Texas, including a Google office and Wursta's corporate headquarters in Austin.
  • Core Dispute: Plaintiff alleges that Defendant Google’s Workspace and Gmail for business products, along with related implementation and support services from Defendant Wursta, infringe two patents related to detecting Business Email Compromise (BEC) scams.
  • Technical Context: The technology addresses the detection of sophisticated, low-volume fraudulent emails that are designed to evade traditional spam filters by analyzing trust relationships and looking for signs of impersonation.
  • Key Procedural History: The complaint notes that U.S. Patent No. 11,595,336 is a continuation of the application that issued as U.S. Patent No. 10,721,195, and that the two patents share the same specification. This relationship suggests that arguments made during the prosecution of one patent, and definitions within the shared specification, may be relevant to construing the claims of both.

Case Timeline

Date Event
2016-01-26 Priority Date for '195 and '336 Patents
2020-07-21 '195 Patent Issued
2023-02-28 '336 Patent Issued
2026-07-20 Complaint Filed

II. Technology and Patent(s)-in-Suit Analysis

U.S. Patent No. 10,721,195

  • Patent Identification: U.S. Patent No. 10,721,195 (Detection of Business Email Compromise), issued July 21, 2020 (the “'195 Patent”) Compl. ¶20

The Invention Explained

  • Problem Addressed: The patent’s background section states that traditional spam filters, which often rely on high-volume detection and simple blacklists, are ill-suited to defend against targeted Business Email Compromise (BEC) scams (Compl. ¶¶23-25; ’195 Patent, col. 3:17-26). These targeted scams appear more realistic and can evade conventional filtering techniques Compl. ¶24
  • The Patented Solution: The invention describes a system that determines trust relationships between parties (e.g., whether they belong to the same organization or have a history of communication) and then performs a risk determination on incoming messages from untrusted or suspicious parties Compl. ¶38 ’195 Patent, abstract This risk analysis is based on factors like display-name or domain-name similarity, and if a risk is found, the system automatically performs a security action like quarantining the message or marking it up with a warning ’195 Patent, abstract ’195 Patent, col. 1:35-44
  • Technical Importance: This approach represented a shift from purely content-based or volume-based filtering to a more contextual analysis based on identity, trust, and relationship history to combat targeted fraud Compl. ¶25

Key Claims at a Glance

  • The complaint asserts at least independent Claim 1 Compl. ¶41
  • The essential elements of Claim 1 include:
    • A processor configured to automatically determine that a first party is trusted by a second party, based on at least one of: (a) the first and second party belonging to the same organization, and (b) a threshold number of messages having been transmitted between them.
    • Receive a message addressed to the second party from a distinct third party.
    • Perform a risk determination on the message based on similarity between the display or domain name of the trusted first party and the third party.
    • Responsive to the trust determination and risk determination, automatically perform a security action (e.g., warning or quarantine) and a report generation action without user input from the second party.
    • A memory coupled to the processor.
  • The complaint reserves the right to assert additional claims Compl. ¶30

U.S. Patent No. 11,595,336

  • Patent Identification: U.S. Patent No. 11,595,336 (Detecting of Business Email Compromise), issued February 28, 2023 (the “'336 Patent”) Compl. ¶21

The Invention Explained

  • Problem Addressed: As a continuation of the '195 Patent, the '336 Patent addresses the same problem of targeted BEC scams evading traditional email filters Compl. ¶¶22-24
  • The Patented Solution: The '336 Patent also describes a system for determining trust and assessing risk, but the exemplary embodiment in its abstract details different criteria. Trust is based on the first party being on a whitelist or in an address book, and risk determination includes checking if the message contains a hyperlink ’336 Patent, abstract If a risk is identified, the security action includes replacing the hyperlink with a "proxy hyperlink" in addition to other actions like warning or quarantining Compl. ¶52 ’336 Patent, abstract
  • Technical Importance: This invention adds specific analytical vectors, such as hyperlink analysis and different trust heuristics (whitelist/address book), to the BEC detection framework Compl. ¶57

Key Claims at a Glance

  • The complaint asserts at least independent Claim 1 Compl. ¶55
  • The essential elements of Claim 1 include:
    • A processor configured to automatically determine that a first party is trusted by a second party, based on the first party being on a whitelist or in an address book.
    • Receive a message addressed to the second party from a distinct third party.
    • Perform a risk determination by: (a) determining if the message comprises a hyperlink, and (b) determining similarity between the display or domain names of the first and third parties.
    • Responsive to the trust and risk determinations, automatically perform a security action (including replacing the hyperlink with a proxy hyperlink) and a report generation action without user input from the second party.
    • A memory coupled to the processor.
  • The complaint reserves the right to assert additional claims Compl. ¶30

III. The Accused Instrumentality

Product Identification

The accused instrumentalities are Google's Workspace and Gmail for business products, which include features for "anti-phishing, anti-spoofing, suspicious-link, business-email-compromise, warning, quarantine, reporting, and administrative functionality" (the "Google Accused Products") Compl. ¶3 Also accused are the services provided by The Wursta Corporation for implementing, configuring, and supporting these Google products (the "Wursta Accused Services") Compl. ¶3

Functionality and Market Context

  • The complaint alleges that the Google Accused Products provide "advanced security settings" for detecting and responding to email risks, including BEC scams Compl. ¶31 These settings allegedly include protections against spoofing, unauthenticated emails, and potential BEC messages, and allow administrators to configure responsive actions like displaying warning banners or quarantining emails Compl. ¶31 Compl. p. 10
  • The complaint provides a screenshot of a warning banner from the accused products, which states "Be careful with this message" and explains that an email appears to be from someone in the user's organization but could not be verified Compl. p. 11 This visual is presented as evidence of the accused warning functionality Compl. ¶32
  • Wursta is identified as a Google partner that sells, implements, and provides training and support for Google Workspace, including its security features Compl. ¶15 Compl. ¶27 An exhibit screenshot from Wursta's website offers to help customers with questions like, "Why am I getting phishing emails?" Exhibit 4, p. 8

IV. Analysis of Infringement Allegations

'195 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
automatically determine that a first party is trusted by a second party, based on at least one of determining that the first party and second party belong to the same organization and that at least a threshold number of messages have been transmitted... Google Workspace allegedly determines trust by identifying if a sender's name is in the organization's directory but the email is from an outside domain. It also allegedly uses message history (e.g., for calendar invites) to identify "known senders." ¶32 col. 47:41-47
receive a message addressed to the second party from a third party, the third party distinct from the first party; Google Workspace is an email system that receives messages from external third parties addressed to users within an organization. ¶33 col. 47:48-50
perform a risk determination of the message...by determining that a display name...or a domain name...are similar... The accused products allegedly perform risk determination by detecting "employee-name spoofing" and messages from domains that "look visually similar to trusted domains." ¶32; ¶33 col. 47:51-59
...automatically perform a security action and a report generation action without having received any user input...wherein the security action comprises marking the message up with a warning or quarantining the message... Google Workspace allegedly allows administrators to configure automatic actions for detected risks, including displaying "warning banners" and a "Quarantine action." The complaint provides a screenshot of such a banner. ¶31; ¶34 col. 47:60-67

'336 Patent Infringement Allegations

Claim Element (from Independent Claim 1) Alleged Infringing Functionality Complaint Citation Patent Citation
automatically determine that a first party is considered by the system to be trusted by a second party, based on at least one of determining that the first party is on a whitelist and that the first party is in an address book... Google Workspace allegedly provides for "allowlist settings" and uses a user's contact list to determine "known senders." ¶32; ¶52 col. 47:4-8
perform a risk determination of the message by determining whether the message comprises a hyperlink and by determining whether a display name...or a domain name...are similar... The accused products allegedly provide "Protection against suspicious...links" and scan for malicious content. It also allegedly detects display-name and domain-name spoofing. ¶31; ¶33 col. 47:12-21
...automatically perform a security action...wherein the security action comprises replacing the hyperlink in the message with a proxy hyperlink... Google’s link protection allegedly functions as a proxy by routing user clicks through Google's own analysis infrastructure before allowing access to the original destination. Third-party reports allegedly observe that URLs in emails are modified by the service. ¶33; ¶52 col. 47:22-30
...and a report generation action...comprises including information about the received message in a report accessible to an admin of the system; Google Workspace allegedly provides administrators with reports on spoofing and suspicious attachments in a "Security center" dashboard. ¶31; ¶34 col. 47:30-32
  • Identified Points of Contention:
    • Scope Questions: A central issue for the '195 Patent may be whether the accused system's method for determining a "trusted" party meets the claim's disjunctive trust limitation, which recites the bases in the alternative ("at least one of": same organization or a threshold number of messages). The complaint alleges features that may correspond to each basis, and its own infringement chart notes the message-threshold theory is "not a necessarily element because claim only requires 'one of.'" For the '336 Patent, a key question will be whether Google’s "link protection" feature can be construed as the claimed "proxy hyperlink," which the claim requires as part of the security action.
    • Technical Questions: A factual question for the court will be to compare the precise technical operation of Google's security features with the functions recited in the claims. For the '336 Patent, this includes examining whether the accused link scanning feature "replaces" the original hyperlink as claimed, or operates in a different manner that may fall outside the claim's scope.

V. Key Claim Terms for Construction

For the '195 Patent

  • The Term: "automatically determine that a first party is trusted by a second party, based on at least one of determining that the first party and second party belong to the same organization and that at least a threshold number of messages have been transmitted..."
  • Context and Importance: This limitation defines the specific conditions for establishing "trust," which is the gateway to the subsequent risk analysis. The infringement case for this patent may depend on whether Google's system satisfies at least one of the alternative trust bases the claim recites ("at least one of"). Practitioners may focus on this term because the complaint maps these conditions to separate Google features, and the complaint's own infringement chart notes the message-threshold basis is "not a necessarily element because claim only requires 'one of.'"
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: The specification describes a variety of ways to establish trust, such as being a "friend" or being "internal" to an organization ’195 Patent, Fig. 4, which Plaintiff may argue supports a more flexible interpretation of how the claimed criteria are met.
    • Evidence for a Narrower Interpretation: The claim language explicitly recites a multi-part test. The defense may argue that the doctrine of claim differentiation and the specificity of the language limit the definition of "trusted" in this claim to entities that satisfy both the organizational and message-volume criteria.

For the '336 Patent

  • The Term: "proxy hyperlink"
  • Context and Importance: The "security action" of replacing a link with a "proxy hyperlink" is a critical distinguishing feature of asserted Claim 1 of the '336 Patent. The infringement allegation hinges on construing Google's link-scanning functionality as meeting this definition.
  • Intrinsic Evidence for Interpretation:
    • Evidence for a Broader Interpretation: Plaintiff may argue that any system that intercepts a user's click and routes it through a security-scanning infrastructure before redirection functions as a proxy. The shared specification describes replacing a hyperlink with a "safe" alternative to protect users, which could support a functional definition ’195 Patent, col. 24:1-15
    • Evidence for a Narrower Interpretation: The defense may argue that a "proxy hyperlink" has a specific technical meaning that requires more than just a pre-click scan, such as fully obscuring the original URL or maintaining a persistent intermediary session. The specification's description of a proxy hyperlink that "encodes the 'original' hyperlink" could be used to argue for a specific structural requirement not present in the accused system ’195 Patent, col. 24:1-2

VI. Other Allegations

  • Indirect Infringement: The complaint alleges that both Google and Wursta induce infringement by encouraging, instructing, and assisting customers in using the accused security features in an infringing manner Compl. ¶44 Compl. ¶59 The allegations against Wursta specifically highlight its role in selling, implementing, configuring, and training customers on the accused Google Workspace functionality Compl. ¶27
  • Contributory Infringement: The complaint also alleges contributory infringement under 35 U.S.C. § 271(c) as to both patents, pleading that particular components or functionality of the Google Accused Products are especially made or adapted for infringing use and are not staple articles suitable for substantial non-infringing use (Compl. ¶45 ('195 Patent); Compl. ¶60 ('336 Patent)).
  • Willful Infringement: The complaint alleges willful infringement based on Defendants' continued infringing conduct after having received notice of the Asserted Patents via the service of the complaint Compl. ¶48 Compl. ¶63
  • Prayer for Relief and Jury Demand: ZapFraud seeks a judgment of infringement; damages together with costs, expenses, and pre- and post-judgment interest; a declaration that the case is exceptional under 35 U.S.C. § 285 with an award of attorneys' fees; enhanced damages; and an injunction prohibiting further infringement, and demands a trial by jury on all issues so triable Compl. p. 20

VII. Analyst’s Conclusion: Key Questions for the Case

  1. A core issue will be one of claim construction and scope: Can the specific, multi-part logical tests for establishing "trust" and performing "risk determination" as recited in the patent claims be read to cover the allegedly more general-purpose security features of Google Workspace? The outcome may depend on whether the court finds a direct mapping or allows for a broader, functional interpretation.
  2. A central question of technical operation will be whether Google’s link-scanning functionality meets the '336 Patent’s "proxy hyperlink" limitation. The case may turn on evidence showing whether the accused feature merely scans a link's destination or operates by "replacing" the original link with an intermediary one that routes the user through Google's infrastructure, as the claim requires.
  3. A key question for liability will concern the role of the co-defendant, Wursta. The court will need to determine if Wursta’s actions in configuring, training, and supporting customers on the use of Google's security tools rise to the level of actively inducing infringement, should the Google Accused Products be found to infringe.
Loading Complaint