The Court granted default judgment entering final injunctions restraining unknown cyber-extortion threat actors from publishing, disseminating, or using data exfiltrated from the plaintiff's database, together with non-publication orders protecting details of the plaintiff's IT systems, communications with the threat actor, and the identities of lawyers and experts involved in the proceedings. The Court held that limited publication of a sample of exfiltrated data on the dark web, accessible only via specialised browsers and targeted searches, did not undermine the confidential character of the dataset so as to defeat injunctive relief. Non-publication orders protecting the identities of legal practitioners and expert witnesses were held necessary to mitigate risks of retaliatory action by threat actors, with the Court finding that such risks could deter experts and lawyers from acting in cyber-extortion cases, thereby prejudicing the broader administration of justice.
The full text is available to signed-in members.