The Court granted final injunctive relief by way of default judgment against unidentified ransomware threat actors who exfiltrated approximately 3.3 terabytes of confidential data, restraining them from publishing, transmitting, or using the exfiltrated data. The Court held that an equitable duty of confidence arises where a threat actor surreptitiously obtains data with knowledge of its confidential nature, and that it would be oppressive to require plaintiffs to individually itemise confidential information in cases involving very large volumes of exfiltrated data. Non-publication orders of varying duration (six months to five years) were made under the Court Suppression and Non-Publication Orders Act 2010 (NSW) to protect the identities of legal practitioners, cyber-security experts, and details of IT systems and communications with the threat actor, on the basis that publication would risk assisting threat actors, exposing named individuals to retaliation, and deterring future victims from commencing similar proceedings.
The full text is available to signed-in members, including the 1 later case that cites this judgment.