[2026] NSWSC 65
Ansell Limited v Persons Unknown
Default judgment entered and orders made in terms of Annexure A
Catchwords
EQUITY – Equitable remedies – injunctions – where the plaintiffs seek leave to proceed pursuant to UCPR r 11.8AA – where plaintiffs seek injunctions by way of default judgment against persons whose identities are unknown, but who are defined in the statement of claim by reference to specified past conduct and/or communications with sufficient clarity that the injunctions do not operate against the world at large
Cases cited
- Agar v Hyde(2000) 201 CLR 552
- Brady v Brady[2025] NSWSC 217
- DRJ v Commissioner of Victims Rights[2020] NSWCA 136
- HWL Ebsworth Lawyers v Persons Unknown (2024) 113 NSWLR 418;[2024] NSWSC 71
- Nationwide News Pty Ltd v Quami (2016) 93 NSWLR 384;[2016] NSWCCA 97
- Qantas Airways Ltd v Persons Unknown[2025] NSWSC 776
- Qantas Airways Ltd v Persons Unknown (No 2)[2025] NSWSC 1328
- Rinehart v Welker (2011) 93 NSWLR 311;[2011] NSWCA 403
- Streetscape Projects Australia Pty Ltd v City of Sydney (2013) 85 NSWLR 196;[2013] NSWCA 2
- University of Notre Dame Australia v Persons Unknown[2025] NSWSC 550
- X v Twitter Inc (2017) 95 NSWLR 301;[2017] NSWSC 1300
- X v Y & Z[2017] NSWSC 1214
Legislation cited
- Court Suppression and Non-publication Orders Act 2010 (NSW), § 6, 7, 8
- Uniform Civil Procedure Rules 2005 (NSW), § 11.8, 11.8AA, 14.26, 16.2, 16.3, 16.10
Judgment
Introduction
- [1]
These reasons concern the plaintiffs’ notice of motion filed on 11 December 2025 seeking leave to proceed pursuant to r 11.8AA of the Uniform Civil Procedure Rules 2005 (NSW) (UCPR), injunctive relief on a final basis by way of default judgment, non-publication orders pursuant to the Court Suppression and Non-Publication Orders Act 2010 (NSW), and an order restricting access by news media organisations to parts of the court file.
- [2]
Following a hearing on 6 February 2026, and a short further hearing on 10 February 2026, I made orders in the terms sought by the plaintiffs and reproduced in Annexure A on the basis that my reasons for doing so would be published as soon as practicable. These are those reasons.
- [3]
It is appropriate to record at the outset that I was greatly assisted by the detailed written submissions prepared by counsel for the plaintiffs and provided prior to the hearing of the application, and by counsel’s supplementary oral submissions made during the hearing. I am most grateful for that assistance.
Salient facts
- [4]
The following account of the factual matters relevant to the application are drawn from the plaintiffs’ evidence, which has not been challenged as the defendants have not appeared.
- [5]
The first plaintiff, Ansell Limited, is a publicly listed Australian company. It owns a group of companies, including the second to eighteenth plaintiffs. Ansell is headquartered in Melbourne, Victoria, but operates in all Australian States and Territories and internationally. Each of the second to eighteenth plaintiffs is a foreign corporation. In these reasons, I will refer to the plaintiffs collectively as Ansell.
- [6]
Ansell manufactures safety and personal protection equipment for healthcare and industrial workers. It uses software supplied by a third party to support management of its business processes, including its human resources processes and its dealings with customers.
- [7]
That software is hosted within a private cloud on virtual servers that are hosted on physical servers located in two datacentres in New Jersey and Arizona in the United States of America (the Servers). The software stores high volumes of Ansell’s commercial and client data and information relating to Ansell’s current and former employees and their dependents.
- [8]
On 30 September 2025, unnamed persons claiming to be part of a named group began sending waves of emails to members of Ansell’s executive team claiming to have gained access to the software, and to have successfully infiltrated a large number of Ansell’s files, including confidential files. The senders of those emails communicated that the files would be published unless Ansell made a payment, and sought to open negotiations for that payment by instructing Ansell to make contact with them through two specified email addresses. In these reasons, the unnamed persons are referred to collectively as the Threat Actor.
- [9]
In further communications shortly thereafter, the Threat Actor demanded payment of a specified sum in return for the Threat Actor agreeing not to publish the files and to delete the data.
- [10]
Ansell has not paid that ransom. Nor has it paid any other sum to the Threat Actor.
- [11]
Ansell’s investigations have ascertained that the Threat Actor did exfiltrate data that includes personal information relating to Ansell’s current and former employees and their dependents (including persons in Australia) and commercial and client data and information (including customer lists) (the Exfiltrated Dataset).
- [12]
The Exfiltrated Dataset is a subset of the data stored on the Servers which the Threat Actor accessed without authority (the Impacted Dataset).
- [13]
On 14 October 2025, Ansell made an announcement to the Australian Securities Exchange that it had identified unauthorised access to certain sets of its data, including confidential information. It has notified the Office of the Australian Information Commissioner and relevant regulatory authorities overseas.
- [14]
Ansell takes precautions to prevent unauthorised access to and use of its data and information on the Servers and has never published the Exfiltrated Dataset itself.
- [15]
Ansell wishes to take all reasonable steps within its power to protect its own commercial and reputational interests, and to protect the interests of its current and former employees, customers, suppliers, and other persons, which would be likely to be adversely affected by any widespread dissemination of the Exfiltrated Dataset.
- [16]
The identity of the Threat Actor is not known and its precise location cannot be ascertained. Ansell’s application proceeded on the assumption that the Threat Actor is located outside Australia. Ansell’s evidence supports that inference.
- [17]
The plaintiffs commenced these proceedings on an urgent basis on 29 October 2025 against the defendant “Persons Unknown”, described as any person or entity which:
- (1)
carried out, participated in or assisted in the exfiltration of some or all of the plaintiffs’ Impacted Dataset; or
- (2)
in respect of the Exfiltrated Dataset, communicated payment demands or threats to the plaintiffs (directly or indirectly), or posted some or all of the Exfiltrated Dataset online (whether for sale or otherwise).
- (1)
- [18]
The Court made interim orders on an ex parte basis on that date restraining the defendants (by themselves, their agents, or by any third party in possession of some or all of the Exfiltrated Dataset) from publishing, disclosing, or using any information or material from the Impacted Dataset (including the Exfiltrated Dataset) without the written consent of the plaintiffs, and requiring the defendants to take all steps to immediately remove any of the Impacted Dataset (including the Exfiltrated Dataset) from all accessible internet locations, including “dark web” locations).
- [19]
The Court also made orders for substituted service on the defendants by sending to the email addresses specified by the Threat Actor in communications with Ansell a Dropbox link through which copies of the statement of claim and other documents can be downloaded. The plaintiffs were permitted to redact from the copies of the documents served all references to the names, identifying details, and contact details of the plaintiffs’ legal representatives, information technology and cyber-security experts, and certain other material. Interim non-publication orders were made pursuant to s 7(b) of the Court Suppression and Non-Publication Orders Act 2010 (NSW). Time for service was abridged to 10:00am on 30 October 2025.
- [20]
The interim injunctions and non-publication orders were subsequently extended until further order.
- [21]
At the time of the commencement of the proceedings, the Threat Actor had not yet acted on its threat to publish the Exfiltrated Dataset.
- [22]
On 1 November 2025, the Threat Actor uploaded and published the Exfiltrated Dataset on the “dark web” – a portion of the internet that that is intentionally hidden and requires special software to access. The plaintiffs have adduced expert evidence from a cyber security consultant with tertiary qualifications in computer science and cybersecurity who specialises in cybercriminal infrastructure and tracking the activity of threat actors and is experienced in that field. The expert’s report establishes that the Exfiltrated Dataset has only been published on the dark web, and that ordinary persons are unlikely to come across the Exfiltrated Dataset during routine internet browsing and are unlikely to be able to access it any event. The expert’s evidence supports the plaintiffs’ submission that there has probably been only a very limited degree of dissemination of the Exfiltrated Dataset to date, and I so find.
Application for leave to proceed
- [23]
The plaintiffs have adduced evidence that, on 30 October 2025, the Threat Actor was served in accordance with the substituted service orders made on 29 October 2025 with: a Form 161 notice; the plaintiffs’ statement of claim and notice of motion filed on 29 October 2025; the affidavits relied on by the plaintiffs in support of the interim relief claimed in notice of motion and the exhibits to those affidavits; and the written submissions made by counsel for the plaintiffs at the hearing on 29 October 2025 together with the orders made by the Court on that date, redacted as permitted by the orders made on 29 October 2025.
- [24]
Rule 11.8AA of the UCPR is engaged because the defendants, or at least some of them, are most likely located outside Australia and so have been served outside Australia. No appearance has been entered on behalf of any person or persons identifying themselves as a defendant in these proceedings. The time for doing so expired 42 days after service on 30 October 2025, being 11 December 2025. [1]
- [25]
I respectfully agree with Brereton J’s conclusion in University of Notre Dame Australia v Persons Unknown (Notre Dame) [2] that, when considering an unopposed application under r 11.8AA, leave should be granted if:
- (1)
there is proof of service;
- (2)
the Court is satisfied that the originating process, on its face, reveals that the claim engages r 11.4 of the UCPR; and
- (3)
there are no apparent countervailing considerations that would cause the Court to exercise its discretion to decline to grant leave.
- (1)
- [26]
I respectfully agree with and adopt his Honour’s reasons for that conclusion and his analysis of Agar v Hyde. [3]
- [27]
In the present case, I am satisfied by the plaintiffs’ evidence referred to at [26] above that the Threat Actor has been served with the documents there referred to. As the plaintiffs submitted, neither the application for leave under r 11.8AA nor the application for default judgment was required to be served. [4]
- [28]
I accept the plaintiffs’ submission that the relief claimed in the statement of claim includes an injunction to restrain the dissemination of the Exfiltrated Dataset at any location on the internet, which must necessarily encompass dissemination in Australia. That engages r 11.4 of the UCPR, which permits service of the statement of claim outside Australia without prior leave of the Court, because the case is of the kind referred to in paragraph (d)(i) of Schedule 6 to the UCPR. [5]
- [29]
Neither the statement of claim nor the evidence that I have summarised at [5]-[25] above reveal any countervailing considerations that would cause the Court to decline to grant leave in this case.
- [30]
Although I do not consider that I am required to have regard to the strength of the plaintiffs’ case, or whether this Court is a clearly inappropriate forum, for the purpose of deciding whether to grant leave under r 11.8AA, [6] it is appropriate to record, in case a different view may be taken on the hearing of any subsequent application, that I consider that the evidence summarised at [5]-[25] above discloses that the plaintiffs have a strong case for the reasons explained at [37]-[42] below, and that I do not consider that this Court is a clearly inappropriate forum. The holding company of the Ansell group of companies who are the plaintiffs in these proceedings is the publicly listed Australian company Ansell Limited, which has engaged solicitors and counsel in New South Wales. I infer that it is likely that at least some of the current and former employees of that Australian company who are potentially affected by the risks that would arise from widespread dissemination of the Exfiltrated Dataset reside in New South Wales. Additionally, as the plaintiffs submitted, the foreign jurisdiction or jurisdictions within which the defendants are located is unknown. [7]
Application for default judgment
- [31]
No defence has been filed on behalf of any person or persons identifying themselves as a defendant in these proceedings. Irrespective of whether the defendants are permitted 28 days under r 14.3(1) or 42 days under r 11.8 of the UCPR to file a defence, the time for doing so has expired. [8] The defendants are therefore in default for the purpose of Part 16 of the UCPR. [9] The Court therefore has power to enter default judgment, including by granting injunctive relief. [10] Service having been established, the likelihood that the defendants are outside Australia is no obstacle to this Court granting such relief. [11]
- [32]
The Court may give such judgment against the defendants in default as the plaintiffs appear to be entitled to on their statement of claim. [12]
- [33]
As the plaintiffs submitted, an equitable duty of confidence arises when confidential information comes to the knowledge of a person in circumstances where they have notice that the information is confidential, so that it would be just in all the circumstances that they should be precluded from disclosing the information to others. In order to obtain an equitable remedy for a breach or apprehended breach of the duty, a plaintiff will typically need to identify the information specifically, and establish that it is of a confidential nature and that there has been actual or threatened unauthorised use of the information by the defendant to the detriment of the plaintiff. The requirement to identify the information specifically does not require a plaintiff to individually itemise documents in a case where the defendant has gained unauthorised access to a very large volume of the plaintiff’s confidential information. Such a requirement would be oppressive. The confidential quality of the information is generally demonstrated by the information not being public property and public knowledge, and by steps taken by the plaintiff to protect the information and keep it largely to itself. In cases such as the present where a defendant has gained unauthorised access to, and taken, the plaintiff’s information to extort money from the plaintiff under threat that the information will otherwise be published, it can readily be concluded that the defendants obtained the information with knowledge that it was confidential. [13]
- [34]
The plaintiffs’ pleaded case, which is supported by the affidavit evidence, is compelling, in my opinion.
- [35]
The weight of authority favours the view that, in circumstances where the defendant has failed to file a defence to the statement of claim, the factual allegations pleaded in the statement of claim are taken to have been admitted. [14]
- [36]
In the present case, the statement of claim pleads facts the deemed admission of which provides ample support for findings that the plaintiffs’ information to which the Threat Actor gained unauthorised access was protected by the plaintiffs and included significant volumes of confidential information, that the Threat Actor was on notice that the information was confidential, and that its conduct in surreptitiously exfiltrating the information before making extortionate threats to publish the information make it just that the Threat Actor should be restrained from disclosing the information to others and should be required to destroy the information in its possession. The evidence summarised at [5]-[19] above provides further support for such findings. This is a case in which it would be oppressive to require the plaintiffs to individually itemise the confidential information, which has been described in sufficient detail in my opinion in the statement of claim and in the affidavits read by the plaintiffs. Although there has been some limited degree of dissemination of the information to date, [15] I accept the plaintiffs’ submission that this has not caused the information to lose its quality of confidence such that it would no longer warrant protection. [16]
- [37]
Injunctions in terms similar to those sought by the plaintiffs have been granted by way of default judgment in previous cases arising out of unauthorised access to and exfiltration of a plaintiff’s data, including confidential information, by persons who cannot be identified. [17] In the present case, the defendants have been defined in the statement of claim as persons unknown who have engaged in, or participated in or assisted with, specified past conduct, or who directly or indirectly made certain communications to the plaintiffs, the injunction sought will not operate against the world at large. In my view, the defendants are described with sufficient clarity to identify those included and excluded. [18]
- [38]
Although the terms of the injunction sought mentions third parties, it is in the form discussed by Brereton J in Notre Dame, which I consider is appropriate for the same reasons as his Honour gave in that case. [19]
- [39]
I accept the plaintiffs’ submission that the injunctions sought have utility, notwithstanding that there is a possibility that the Threat Actor may not obey the injunction. As Slattery J said in HWL Ebsworth, a reputation for wilful disobedience to the law does not confer immunity from injunctions. Moreover, as the plaintiffs submitted, it will be open to them to notify third parties of the injunction. [20] Such third parties, properly advised, would be aware that they should not take any step that would frustrate the effectiveness of this Court’s orders. [21]
Application for non-publication orders
- [40]
Under s 7 of the Court Suppression and Non-Publication Orders Act (the Act), the Court has power to make non-publication orders on one or more of the grounds set out in s 8 of the Act.
- [41]
Ansell ultimately sought non-publication orders under the Court Suppression and Non-Publication Orders Act in the terms set out in paragraph 4 of Annexure A hereto. That formulation of the orders incorporates amendments made by Ansell to the form of orders initially sought by reducing the scope of the information to which the orders apply in each of paragraphs 4(c)(i) to (vii). Those amendments were made after I raised some concerns with counsel at the hearing on 6 February 2026 that the orders would otherwise effectively require reasons for judgment published by the Court in relation to Ansell’s default judgment application to either heavily redacted or expressed in such general terms as to preclude meaningful public scrutiny of those reasons.
- [42]
The information to which the non-publication orders apply fall into three broad categories:
- (1)
certain information about Ansell’s information technology systems and data arrangements, its means of detecting unauthorised access to data, its response to the incident, and its concerns about the effects of public disclosure of the Exfiltrated Data: paragraphs 4(c)(ii) and (vi) of Annexure A;
- (2)
Ansell’s knowledge about the Threat Actor and its intentions, its communications with the Threat Actor, and the specific communication channels provided by the Threat Actor to Ansell for the purpose of communicating with the Threat Actor: paragraphs 4(c)(iii), (iv) and (vii) of Annexure A; and
- (3)
the names and identifying details and contact details of any person or firm included in documents filed in these proceedings (including witnesses, experts, lawyers and law firms): paragraphs 4(c)(i) and (v) of Annexure A.
- (1)
- [43]
Taking into account that a primary objective of the administration of justice is to safeguard the public interest in open justice, [22] I am satisfied that the evidence adduced by Ansell demonstrates that the non-publication orders in the terms of paragraph 4 of Annexure A are necessary, in the strong sense in which that word is used in this context, [23] to prevent prejudice to the proper administration of justice [24] and/or to protect the safety of any person [25] and/or are necessary to serve a public interest which significantly outweighs the public interest in open justice. [26]
- [44]
The evidence adduced by Ansell establishes that there is a risk of the Threat Actor, or other potential threat actors, being inadvertently assisted by publication of the first and second categories of information referred to above, including by disclosing contact details for the Threat Actor to third parties having no entitlement to the Exfiltrated Data but who may wish to acquire or access that data for their own benefit or gain. Indeed, those risks are rather obvious as a matter of common sense, having regard to the increasing incidence of digital extortion which is a matter of common knowledge and is illustrated by the judgments of this Court in previous proceedings arising out of such incidents. [27] It would be contrary to the public interest for the Threat Actor, other potential threat actors or third parties, to be inadvertently assisted in this way by the publication of the first and second categories of information. [28]
- [45]
It would also be prejudicial to the administration of justice in these proceedings if the price of Ansell adducing the evidence required to support its application for substantive relief was to directly or indirectly aid the Threat Actor, or other potential threat actors. The very harm that Ansell seeks to prevent by commencing and prosecuting these proceedings would be likely to be exacerbated, and it would be likely to be exposed to an increased risk of further incidents of unauthorised access to and exfiltration of its confidential information. Looking to the broader concept of the administration of justice, such a price would be inherently likely to deter prospective future plaintiffs who are the victims of similar incidents from commencing proceedings of this kind in this Court. [29]
- [46]
Non-publication of the first and second categories of information in this case does not preclude the Court giving reasons for judgment that are amenable to meaningful public scrutiny. Moreover, as counsel for Ansell submitted, any person permitted to access the court file will be able to view the information that is the subject of order 4. The order only prohibits the publication of that information by disseminating or providing access to the information to the public or a section of the public by any means.
- [47]
Insofar as they apply to the information in the first and second categories, the operation of the non-publication orders for a period of five years will impact on the open justice principle only to the extent that is, in my opinion, necessary to protect the public interest and to avoid prejudice to the administration of justice in this case and in the broader sense.
- [48]
In relation to the third category of information referred to above, the evidence adduced by Ansell establishes that its solicitors are a specialist legal and advisory firm that provides a range of services in relation to cyber, privacy and digital risk in Australia and New Zealand. In the relatively short period of time since the firm was established, it has frequently acted on multiple cyber incidents involving the same threat actor or group of threat actors. The firm receives instructions on a regular basis to make applications for injunctive relief of the kind sought in the present proceedings.
- [49]
The evidence adduced by Ansell also establishes that threat actors are prone to engaging in retaliation and pressure campaigns against individual lawyers, firms, and other individuals such as expert witnesses and expert consultants, who are named in documents filed in court proceedings of this kind as acting for or providing expert advice or assistance to or giving evidence for the plaintiff whose confidential data has been exfiltrated and who has been subjected to ransom demands. The evidence establishes that such campaigns may include sending threatening messages to named individuals, publishing or distributing information about named individuals in a way that may expose them to fraud attempts, phishing and other forms of cyber-attack, or attempting to track the movements and whereabouts of named individuals with a view to threatening their physical security.
- [50]
An order for the non-publication of the names and identifying details of those individuals, without going so far as to suppress their identity, is a means of mitigating those risks to their personal safety, and I am satisfied that such orders are necessary for that purpose in this case. The impact of the order on the public interest in open justice is very slight, as it will have no bearing on the substance of the Court’s reasons for judgment and will not preclude the public from scrutinising the work of the Court in this case. It prevents prejudice to the public interest and to the broader administration of justice by mitigating serious personal risks that might otherwise deter experts from providing professional services to plaintiffs who are the victims of cyber-crimes, and that might otherwise deter individual legal practitioners and firms from accepting instructions to appear from plaintiffs in matters of this kind. The ability of parties to proceedings to obtain legal representation should they wish to do so, and the assistance that legal practitioners provide to the Court, is of central importance to the administration of justice in any proceeding.
- [51]
I am satisfied that the three-year duration of the non-publication orders in relation to identifying details of solicitors and law firms and the six-month duration of the orders in relation to counsel is necessary to ameliorate the risks to their safety and to serve the public interest and prevent the prejudice to the administration of justice described above, having regard to the frequency with which the law firm acting for Ansell acts in matters of this kind. In seeking only a six month duration for the order insofar as it applies to identifying details of counsel, counsel accepted that they were in a slightly different position from the law firm. Amongst other things, the role of counsel does not extend to communicating directly with threat actors for the purpose of serving them with proceedings.
- [52]
I am satisfied that the five-year duration of the non-publication orders in relation to identifying details of other named persons is necessary to ameliorate the risks to their safety, and to serve the public interest in plaintiffs being able to obtain such expert assistance as they may require in response to incidents of the kind that gave rise to the present proceedings, without the personal safety of those experts being placed at risk.
Orders
- [53]
For all of the foregoing reasons, I made the orders set out in Annexure A to these reasons on 10 February 2026.