What stops them from forcing Chrome to block the website, or LetsEncrypt to not issue any more certificates for the domain, or Microsoft and Apple to add them to their firewalls? Hell, can they go after the infrastructure software developers and say, force nginx to add a check and refuse to serve the domain?
Then what happens when a fake report is sent to an open source project without budget for lawyers?