← All cases

[2026] NSWSC 195

Fairfield City Council v Persons Unknown

Default judgment entered and orders made in terms of Annexure A

Catchwords

EQUITY – Equitable remedies – injunctions – where the plaintiffs seek leave to proceed pursuant to UCPR r 11.8AA – where plaintiffs seek injunctions by way of default judgment against persons whose identities are unknown, but who are defined in the statement of claim by reference to specified past conduct and/or communications with sufficient clarity that the injunctions do not operate against the world at large

Cases cited

  • Agar v Hyde (2000) 201 CLR 552;[2000] HCA 41
  • Ansell Limited v Persons Unknown[2026] NSWSC 65
  • Australian Medical Association (WA) Incorporated v Persons Unknown[2026] NSWSC 111
  • Brady v Brady[2025] NSWSC 217
  • Commonwealth of Australia v John Fairfax & Sons Ltd (1980) 147 CLR 39;[1980] HCA 44
  • DRJ v Commissioner of Victims Rights[2020] NSWCA 136
  • Del Casale v Artedomus (Aust) Pty Ltd (2007) 73 IPR 326;[2007] NSWCA 172
  • HWL Ebsworth Lawyers v Persons Unknown (2024) 113 NSWLR 418;[2024] NSWSC 71
  • Mid-City Skin & Laser Centre Pty Ltd v Zahedi-Anarak (2006) 67 NSWLR 569;[2006] NSWSC 844
  • Nationwide News Pty Ltd v Quami (2016) 93 NSWLR 384;[2016] NSWCCA 97
  • Qantas Airways Ltd v Persons Unknown[2025] NSWSC 776
  • Qantas Airways Ltd v Persons Unknown (No 2)[2025] NSWSC 1328
  • ReadyTech Holdings Ltd v Persons Unknown[2026] NSWSC 66
  • Rinehart v Welker (2011) 93 NSWLR 311;[2011] NSWCA 403
  • Streetscape Projects Australia Pty Ltd v City of Sydney (2013) 85 NSWLR 196;[2013] NSWCA 2
  • University of Notre Dame Australia v Persons Unknown[2025] NSWSC 550
  • Wentworth Partners Estate Agents Pty Ltd t/as Re Max Gold v Gordony[2007] NSWSC 1135
  • X v Twitter Inc (2017) 95 NSWLR 301;[2017] NSWSC 1300
  • X v Y & Z[2017] NSWSC 1214

Legislation cited

  • Court Suppression and Non-publication Orders Act 2010 (NSW), § 6, 7, 8
  • Uniform Civil Procedure Rules 2005 (NSW), § 11.8, 11.8AA, 14.26, 16.2, 16.3, 16.10

Judgment

Introduction

  1. [1]

    These reasons concern the plaintiff’s notice of motion filed on 10 February 2026 seeking leave to proceed pursuant to r 11.8AA of the Uniform Civil Procedure Rules 2005 (NSW) (UCPR), injunctive relief on a final basis by way of default judgment, non-publication orders pursuant to the Court Suppression and Non-Publication Orders Act 2010 (NSW), and an order restricting access by news media organisations to parts of the court file.

  2. [2]

    Following a hearing on 6 March 2026 and after considering a supplementary written submission received from counsel for the plaintiff later that day, I made orders on 9 March 2026 in the terms sought by the plaintiffs and reproduced in Annexure A hereto on the basis that my reasons for doing so would be published as soon as practicable. These are those reasons.

Salient facts

  1. [3]

    The following account of the factual matters relevant to the application are drawn from the plaintiffs’ evidence, which has not been challenged as the defendants have not appeared.

  2. [4]

    The plaintiff is a body politic of the State pursuant to s 220 of the Local Government Act 1993 (NSW) with responsibility for managing the local government area of Fairfield in Western Sydney, New South Wales.

  3. [5]

    The plaintiff operates computerised servers located at several premises of the plaintiff, and at a third-party data centre, in New South Wales (the Servers). The Servers are used to host applications used by the plaintiff in its day-to-day operations, and to store data and information that includes:

    1. (1)

      personal information relating to councillors;

    2. (2)

      personal, financial and property information relating to customers, ratepayers and residents of the plaintiff;

    3. (3)

      personal, financial and employment information relating to the plaintiff’s employees;

    4. (4)

      operational materials, including information relating to development and other compliance matters;

    5. (5)

      financial information relating to the plaintiff; and

    6. (6)

      legal advice and associated documents.

  4. [6]

    On or about 8 October 2025, unnamed persons claiming to be part of a named group gained unauthorised access to the Servers and encrypted them with ransomware. In the course of investigating this activity, the plaintiff discovered a ransom note which claimed that the plaintiff’s network/system had been encrypted, that the unnamed persons had downloaded compromising and sensitive data from the network/system (including some of the kinds of information referred to at [5] above), and that the data would be published if the plaintiff refused to communicate or failed to come to an agreement with the unnamed persons. The ransom note included instructions for the plaintiff to communicate with the unnamed persons only through a specified chat room. In these reasons, the unnamed persons are referred to collectively as the Threat Actor.

  5. [7]

    The Threat Actor posted a message in the chatroom repeating its claim to have encrypted the plaintiff’s data and to have exfiltrated compromising and sensitive data from the plaintiff’s systems and network, and demanding payment of a specified sum in return for the Threat Actor providing decryption tools and a complete list of all files they had taken from the plaintiff’s network, promising that it would not attack the plaintiff again in the future, and guaranteeing that “we will forget about this incident”.

  6. [8]

    The plaintiff has not paid the ransom demanded by the Threat Actor. Nor has it paid any other sum to the Threat Actor.

  7. [9]

    The plaintiff’s investigations have ascertained that the Threat Actor did exfiltrate large amounts of data from the Servers. The full extent of the exfiltration is the subject of ongoing investigation. For this reason, and due to the large number of files that are presently known to have been encrypted and exfiltrated and the plaintiffs’ ongoing restoration efforts, it is not possible to enumerate all of the specific files comprising the Exfiltrated Dataset. However, having regard to the nature and volume of the data stored on the Servers (as referred to at [5] above) and the nature of the data that the Threat Actor claimed to have exfiltrated in the ransom note referred to at [6] above, and the file names of the files presently known to have been exfiltrated, it is probable that the Exfiltrated Dataset includes a significant quantity of information of the kind referred to at [5] above.

  8. [10]

    I refer to all of the data stored on the Servers which the Threat Actor accessed without authorisation as the Impacted Dataset. I refer to the data that was exfiltrated from the Servers by the Threat Actor as the Exfiltrated Dataset.

  9. [11]

    The plaintiff has notified various government agencies and regulators of the incident, including Cyber Security New South Wales, the Australian Cyber Security Centre, the Information and Privacy Commission New South Wales, and the Office of the Australian Information Commissioner.

  10. [12]

    The plaintiff takes precautions to prevent unauthorised access to and use of its data and information on the Servers by employing physical barriers to the Servers and technical security barriers to the data stored on them. The plaintiff has never published the Exfiltrated Dataset itself.

  11. [13]

    The plaintiff wishes to take all reasonable steps within its power to protect its reputation and relationships with customers, ratepayers, residents, councillors, employees and other stakeholders whose personal and financial information is stored on the Servers and who may be exposed to the risk of identity theft or fraud as a result of the Threat Actor’s exfiltration of and threat to publish that information. The plaintiff wishes to protect the interests of those affected persons, and also to prevent harm to the plaintiff’s operations that would result from any publication of the Exfiltrated Dataset.

  12. [14]

    The identity of the Threat Actor is not known and its precise location cannot be ascertained. The application for default judgment proceeded on the assumption that the Threat Actor is located outside Australia. The evidence adduced by the plaintiff supports that inference.

  13. [15]

    The plaintiff commenced these proceedings on an urgent basis on 6 November 2025 against the defendant “Persons Unknown”, described as any person or entity which:

    1. (1)

      carried out, participated in or assisted in the exfiltration of some or all of the plaintiff’s Impacted Dataset; or

    2. (2)

      in respect of the Exfiltrated Dataset, communicated payment demands or threats to the plaintiff (directly or indirectly), or posted some or all of the Exfiltrated Dataset online (whether for sale or otherwise).

  14. [16]

    The Court made interim orders on an ex parte basis on that date:

    1. (1)

      restraining the defendants (by themselves, their agents, or by any third party in possession of some or all of the Exfiltrated Dataset) until 5:00pm on 10 November 2025 from doing any of the following without the plaintiffs’ written consent:

    2. (2)

      requiring the defendants to take all steps to immediately remove any of the Impacted Dataset (including the Exfiltrated Dataset) from all accessible internet locations (including “dark web” locations).

  15. [17]

    On 10 November 2025, those orders were extended until further order.

  16. [18]

    The orders made on 6 November 2025 also included orders for substituted service on the defendants by sending a message to the chatroom specified by the Threat Actor containing a Dropbox link through which copies of the statement of claim and other documents can be downloaded. [1] The plaintiff was granted leave to redact from the copies of the documents served all references to the names, identifying details, and contact details of the plaintiffs’ legal representatives, information technology and cyber-security experts, and certain other material. Interim non-publication orders were made pursuant to s 7(b) of the Court Suppression and Non-Publication Orders Act 2010 (NSW). Time for service was abridged to 2:00pm on 7 November 2025.

  17. [19]

    At the time of the hearing of the application for default judgment, the Threat Actor has not published the Exfiltrated Dataset online insofar as the searches and investigations made by the plaintiff’s expert had been able to ascertain. However, having regard to the ransom note, there remains a material risk that the Threat Actor will publish or otherwise disseminate the Exfiltrated Dataset.

Consideration and determination

  1. [20]

    The applicable legal principles are well established. Much of what follows draws heavily on recent judgments in which I have summarised those principles by reference to earlier judgments of this Court. [2] I have been greatly assisted by the detailed submissions made by counsel for the plaintiffs in relation to the application of those principles in the circumstances of this case.

  2. [21]

    The plaintiff has adduced evidence that, on 7 November 2025, the Threat Actor was served in accordance with the substituted service orders made on 6 November 2025 [3] with: a Form 161 notice; the plaintiffs’ statement of claim and notice of motion filed on 6 November 2025; the affidavit relied on by the plaintiffs in support of the interim relief claimed in the notice of motion and the exhibit to that affidavit; and the written submissions made by counsel for the plaintiffs at the hearing on 6 November 2025, together with the orders made by the Court on that date, redacted as permitted by the Court’s orders.

  3. [22]

    Rule 11.8AA of the UCPR is engaged because the defendants, or at least some of them, are most likely located outside Australia and so have been served outside Australia. No appearance has been entered on behalf of any person or persons identifying themselves as a defendant in these proceedings. The time for doing so expired 42 days after service on 7 November 2025, being 19 December 2025. [4]

  4. [23]

    I respectfully agree with Brereton J’s conclusion in University of Notre Dame Australia v Persons Unknown (Notre Dame) [5] that, when considering an unopposed application under r 11.8AA, leave should be granted if:

    1. (1)

      there is proof of service;

    2. (2)

      the Court is satisfied that the originating process, on its face, reveals that the claim engages r 11.4 of the UCPR; and

    3. (3)

      there are no apparent countervailing considerations that would cause the Court to exercise its discretion to decline to grant leave.

  5. [24]

    I respectfully agree with and adopt his Honour’s reasons for that conclusion and his analysis of Agar v Hyde. [6]

  6. [25]

    In the present case, I am satisfied by the plaintiff’s evidence referred to at [21] above that the Threat Actor has been served with the documents there referred to. As the plaintiff submitted, neither the application for leave under r 11.8AA nor the application for default judgment was required to be served. [7]

  7. [26]

    I accept the plaintiff’s submission that the relief claimed in the statement of claim includes an injunction to restrain the dissemination of the Exfiltrated Dataset at any location on the internet, which must necessarily encompass dissemination in Australia. That engages r 11.4 of the UCPR, which permits service of the statement of claim outside Australia without prior leave of the Court, because the case is of the kind referred to in paragraph (d)(i) of Schedule 6 to the UCPR. [8]

  8. [27]

    Neither the statement of claim nor the evidence that I have summarised at [4]-[19] above reveal any countervailing considerations that would cause the Court to decline to grant leave in this case.

  9. [28]

    No defence has been filed on behalf of any person or persons identifying themselves as a defendant in these proceedings. Irrespective of whether the defendants are permitted 28 days under r 14.3(1) or 42 days under r 11.8 of the UCPR to file a defence, the time for doing so has expired. [9] The defendants are therefore in default for the purpose of Part 16 of the UCPR. [10] The Court therefore has power to enter default judgment, including by granting injunctive relief. [11] Service having been established, the likelihood that the defendants are outside Australia is no obstacle to this Court granting such relief. [12]

  10. [29]

    The Court may give such judgment against the defendants in default as the plaintiff appears to be entitled to on its statement of claim. [13]

  11. [30]

    As the plaintiff submitted, an equitable duty of confidence arises when confidential information comes to the knowledge of a person in circumstances where they have notice that the information is confidential, so that it would be just in all the circumstances that they should be precluded from disclosing the information to others. In order to obtain an equitable remedy for a breach or apprehended breach of the duty, a plaintiff will typically need to identify the information specifically, and establish that it is of a confidential nature and that there has been actual or threatened unauthorised use of the information by the defendant to the detriment of the plaintiff. The requirement to identify the information specifically does not require a plaintiff to individually itemise documents in a case where the defendant has gained unauthorised access to a very large volume of the plaintiff’s confidential information. Such a requirement would be oppressive. The confidential quality of the information is generally demonstrated by the information not being public property and public knowledge, by the plaintiff having expended effort in the creation or collection of the information, and by the plaintiff having taken steps to protect the information and keep it largely to itself. In cases such as the present where a defendant has gained unauthorised access to, encrypted, and taken the plaintiff’s information to extort money from the plaintiff under threat that the information will otherwise be published, it can readily be concluded that the defendants obtained the information with knowledge that it was confidential. [14]

  12. [31]

    The plaintiff’s pleaded case, which is supported by the affidavit evidence, is compelling, in my opinion.

  13. [32]

    The weight of authority favours the view that, in circumstances where the defendant has failed to file a defence to the statement of claim, the factual allegations pleaded in the statement of claim are taken to have been admitted. [15]

  14. [33]

    The plaintiff’s statement of claim pleads facts, the deemed admission of which provides ample support for findings that the plaintiff’s information to which the Threat Actor gained unauthorised access was protected by the plaintiff and included significant volumes of information of the kind referred to at [5] above which is confidential (including because the plaintiff has developed effort in creating or collecting it, its secrecy is guarded by the plaintiff, and it includes information of a private and personal nature concerning the plaintiff’s customers, ratepayers, residents, councillors and employees), [16] that the Threat Actor was on notice that the information was confidential, and that its conduct in surreptitiously exfiltrating the information before making extortionate threats to publish the information make it just that the Threat Actor should be restrained from transmitting, publishing, or disclosing the information to others and should be restrained from using the information. The evidence summarised at [4]-[14] above provides further support for such findings. This is a case in which it would be oppressive to require the plaintiff to individually itemise the confidential information, which has been described in sufficient detail in my opinion in the statement of claim and in the affidavits read by the plaintiff. As there has been no transmission, publication or dissemination of the information to date, I accept the plaintiff’s submission that the information retains its quality of confidence and warrants protection.

  15. [34]

    Injunctions in terms similar to those sought by the plaintiff have been granted by way of default judgment in previous cases arising out of unauthorised access to and exfiltration of a plaintiff’s data, including confidential information, by persons who cannot be identified. [17] The plaintiff in this case - a government entity - is not seeking to restrain the publication of the Exfiltrated Dataset for the purpose of precluding public review of the data and scrutiny of government action. [18] Rather, the plaintiff is seeking to protect the interests of those who would be most directly affected persons affected by, and to prevent harm to the plaintiff’s operations that would result from, any publication of the Exfiltrated Dataset. [19]

  16. [35]

    The defendants have been defined in the statement of claim as persons unknown who have engaged in, or participated in or assisted with, specified conduct, or who directly or indirectly made certain communications to the plaintiff. The injunction sought will not operate against the world at large. In my view, the defendants are described with sufficient clarity to identify those included and excluded. [20]

  17. [36]

    Although the terms of the injunction sought mention third parties, it is in the form discussed by Brereton J in Notre Dame, which I consider is appropriate for the same reasons as his Honour gave in that case. [21]

  18. [37]

    I accept the plaintiff’s submission that the injunctions sought have utility, notwithstanding that there is a possibility that the Threat Actor may not obey the injunction. As Slattery J said in HWL Ebsworth, a reputation for wilful disobedience to the law does not confer immunity from injunctions. Moreover, as the plaintiff submitted, it will be open to it to notify third parties of the injunction. [22] Such third parties, properly advised, would be aware that they should not take any step that would frustrate the effectiveness of this Court’s orders. [23]

  19. [38]

    Under s 7 of the Court Suppression and Non-Publication Orders Act (the Act), the Court has power to make non-publication orders on one or more of the grounds set out in s 8 of the Act.

  20. [39]

    The plaintiff sought non-publication orders under the Act in the terms set out in paragraph 3 of Annexure A hereto. The information to which those non-publication orders apply falls into three broad categories:

    1. (1)

      certain information about the plaintiff’s information technology systems and data arrangements, its security response to the incident and remediation measures, and its concerns about the effects of public disclosure of the Exfiltrated Data: paragraphs 3(c)(2) and (6) of Annexure A;

    2. (2)

      the plaintiff’s knowledge about the Threat Actor and its intentions, its communications with the Threat Actor, and the specific communication channels provided by the Threat Actor to the plaintiff for the purpose of communicating with the Threat Actor: paragraphs 3(c)(3), (4) and (7) of Annexure A; and

    3. (3)

      the names and identifying details and contact details of any person or firm included in documents filed in these proceedings (including witnesses, experts, lawyers and law firms): paragraphs 3(c)(1) and (5) of Annexure A.

  21. [40]

    Taking into account that a primary objective of the administration of justice is to safeguard the public interest in open justice, [24] I am satisfied that the evidence adduced by the plaintiff demonstrates that the non-publication orders in the terms of paragraph 3 of Annexure A are necessary, in the strong sense in which that word is used in this context, [25] to prevent prejudice to the proper administration of justice [26] and/or to protect the safety of any person [27] and/or to serve the public interest in resisting the growing scourge of digital extortion crimes which significantly outweighs the public interest in open justice to the extent that open justice would otherwise inadvertently assist the Threat Actor or other potential threat actors. [28]

  22. [41]

    The evidence adduced by the plaintiff establishes that there is a risk of the Threat Actor, or other potential threat actors, being inadvertently assisted by publication of the first and second categories of information referred to above, including by disclosing contact details for the Threat Actor to third parties who have no entitlement to the Exfiltrated Data but who may wish to acquire or access that data for their own benefit or gain. Indeed, those risks are rather obvious as a matter of common sense, having regard to the increasing incidence of digital extortion which is a matter of common knowledge and is illustrated by the judgments of this Court in previous proceedings arising out of such incidents. [29] It would be contrary to the public interest for the Threat Actor, other potential threat actors or third parties, to be inadvertently assisted in this way by the publication of the first and second categories of information. [30]

  23. [42]

    It would also be prejudicial to the administration of justice in these proceedings if the price of the plaintiff adducing the evidence required to support its application for substantive relief was to directly or indirectly aid the Threat Actor, or other potential threat actors. The very harm that the plaintiff seeks to prevent by commencing and prosecuting these proceedings would be likely to be exacerbated, and it would be likely to be exposed to an increased risk of further incidents of unauthorised access to and exfiltration of its confidential information. Looking to the broader concept of the administration of justice, such a price would be inherently likely to deter prospective future plaintiffs who are the victims of similar incidents from commencing proceedings of this kind in this Court. [31]

  24. [43]

    Non-publication of the first and second categories of information in this case does not preclude the Court from giving reasons for judgment that are amenable to meaningful public scrutiny. Moreover, as counsel for the plaintiff submitted, any person permitted to access the court file will be able to view the information that is the subject of order 3. The order only prohibits the publication of that information by disseminating or providing access to the information to the public or a section of the public by any means.

  25. [44]

    Insofar as they apply to the information in the first and second categories, the operation of the non-publication orders for a period of five years will impact on the open justice principle only to the extent that is, in my opinion, necessary to protect the public interest and to avoid prejudice to the administration of justice in this case and in the broader sense.

  26. [45]

    In relation to the third category of information referred to above, the evidence adduced by the plaintiff establishes that its solicitors are a specialist legal and advisory firm that provides a range of services in relation to cyber, privacy and digital risk in Australia and New Zealand. In the relatively short period of time since the firm was established, it has frequently acted on multiple cyber incidents involving the same threat actor or group of threat actors. The firm receives instructions on a regular basis to make applications for injunctive relief of the kind sought in the present proceedings.

  27. [46]

    The evidence adduced by the plaintiff also establishes that threat actors are prone to engaging in retaliation and pressure campaigns against individual lawyers, firms, and other individuals such as expert witnesses and expert consultants, who are named in documents filed in court proceedings of this kind as acting for or providing expert advice or assistance to or giving evidence for the plaintiff whose confidential data has been exfiltrated and who has been subjected to ransom demands. The evidence establishes that such campaigns may include sending threatening messages to named individuals, publishing or distributing information about named individuals in a way that may expose them to fraud attempts, phishing and other forms of cyber-attack, or attempting to track the movements and whereabouts of named individuals with a view to threatening their physical security.

  28. [47]

    An order for the non-publication of the names and identifying details of those individuals, without going so far as to suppress their identity, is a means of mitigating those risks to their personal safety, and I am satisfied that such orders are necessary for that purpose in this case. The impact of the order on the public interest in open justice is very slight, as it will have no bearing on the substance of the Court’s reasons for judgment and will not preclude the public from scrutinising the work of the Court in this case. It prevents prejudice to the public interest and to the broader administration of justice by mitigating serious personal risks that might otherwise deter experts from providing professional services to plaintiffs who are the victims of cyber-crimes, and that might otherwise deter individual legal practitioners and firms from accepting instructions to appear from plaintiffs in matters of this kind. The ability of parties to proceedings to obtain legal representation should they wish to do so and to engage legal practitioners of their choosing, and the assistance that legal practitioners provide to the Court, is of central importance to the administration of justice in any proceeding.

  29. [48]

    I am satisfied that the three-year duration of the non-publication orders in relation to identifying details of solicitors and law firms and the six-month duration of the orders in relation to counsel is necessary to ameliorate the risks to their safety and to serve the public interest and prevent the prejudice to the administration of justice described above, having regard to the frequency with which the law firm acting for the plaintiff acts in matters of this kind. In seeking only a six-month duration for the order insofar as it applies to identifying details of counsel, counsel accepted that they were in a slightly different position from the law firm. Amongst other things, the role of counsel does not extend to communicating directly with threat actors for the purpose of serving them with proceedings.

  30. [49]

    I am satisfied that the five-year duration of the non-publication orders in relation to identifying details of other named persons is necessary to ameliorate the risks to their safety, and to serve the public interest in plaintiffs being able to obtain such expert assistance as they may require in response to incidents of the kind that gave rise to the present proceedings, without the personal safety of those experts being placed at risk.

Orders

  1. [50]

    For all of the foregoing reasons, I made the orders set out in Annexure A to these reasons on 9 March 2026.

Unofficial copy. Source: NSW Caselaw. Refer to the official version for authoritative text.