The Court granted final injunctive relief by way of default judgment against unidentified cyber threat actors who exfiltrated confidential data from a local government council's servers and demanded ransom, restraining publication, transmission or use of the exfiltrated data. The Court confirmed that equitable breach of confidence principles apply to ransomware exfiltration cases even where the plaintiff cannot individually itemise the confidential information taken, and that injunctions retain utility notwithstanding the possibility of non-compliance by overseas defendants. Non-publication orders of varying duration (six months to five years) were granted to protect the identities of legal practitioners, experts and other named persons from threat actor retaliation, with the Court finding such orders necessary under ss 8(1)(a), (c) and (e) of the Court Suppression and Non-Publication Orders Act 2010 (NSW).
The full text is available to signed-in members, including the 3 later cases that cite this judgment.