← All cases

[2026] NSWSC 273

Paterson & Dowding Pty Ltd v Persons Unknown

Default judgment entered and orders made in terms of Annexure A

Catchwords

EQUITY – Equitable remedies – injunctions – where the plaintiffs seek leave to proceed pursuant to UCPR r 11.8AA – where plaintiffs seek injunctions by way of default judgment against persons whose identities are unknown, but who are defined in the statement of claim by reference to specified past conduct and/or communications with sufficient clarity that the injunctions do not operate against the world at large

Cases cited

  • Agar v Hyde (2000) 201 CLR 552;[2000] HCA 41
  • Ansell Limited v Persons Unknown[2026] NSWSC 65
  • Australian Medical Association (WA) Incorporated v Persons Unknown[2026] NSWSC 111
  • Brady v Brady[2025] NSWSC 217
  • Commonwealth of Australia v John Fairfax & Sons Ltd (1980) 147 CLR 39;[1980] HCA 44
  • DRJ v Commissioner of Victims Rights[2020] NSWCA 136
  • Del Casale v Artedomus (Aust) Pty Ltd (2007) 73 IPR 326;[2007] NSWCA 172
  • Fairfield City Council v Persons Unknown[2026] NSWSC 195
  • HWL Ebsworth Lawyers v Persons Unknown (2024) 113 NSWLR 418;[2024] NSWSC 71
  • Mid-City Skin & Laser Centre Pty Ltd v Zahedi-Anarak (2006) 67 NSWLR 569;[2006] NSWSC 844
  • Nationwide News Pty Ltd v Quami (2016) 93 NSWLR 384;[2016] NSWCCA 97
  • Qantas Airways Ltd v Persons Unknown[2025] NSWSC 776
  • Qantas Airways Ltd v Persons Unknown (No 2)[2025] NSWSC 1328
  • ReadyTech Holdings Ltd v Persons Unknown[2026] NSWSC 66
  • Rinehart v Welker (2011) 93 NSWLR 311;[2011] NSWCA 403
  • Streetscape Projects Australia Pty Ltd v City of Sydney (2013) 85 NSWLR 196;[2013] NSWCA 2
  • University of Notre Dame Australia v Persons Unknown[2025] NSWSC 550
  • Wentworth Partners Estate Agents Pty Ltd t/as Re Max Gold v Gordony[2007] NSWSC 1135
  • X v Twitter Inc (2017) 95 NSWLR 301;[2017] NSWSC 1300
  • X v Y & Z[2017] NSWSC 1214

Legislation cited

  • Court Suppression and Non-publication Orders Act 2010 (NSW), § 6, 7, 8
  • Uniform Civil Procedure Rules 2005 (NSW), § 11.8, 11.8AA, 14.26, 16.2, 16.3, 16.10

Judgment

Introduction

  1. [1]

    These reasons concern the plaintiff’s notice of motion filed on 24 February 2026 seeking leave to proceed pursuant to r 11.8AA of the Uniform Civil Procedure Rules 2005 (NSW) (UCPR), injunctive relief on a final basis by way of default judgment, non-publication orders pursuant to the Court Suppression and Non-Publication Orders Act 2010 (NSW), and an order restricting access by news media organisations to parts of the court file.

  2. [2]

    At the conclusion of the hearing of the motion on 20 March 2026, I entered default judgment and made orders in the terms sought by the plaintiff and reproduced in Annexure A hereto on the basis that my reasons for doing so would be published as soon as practicable. These are those reasons.

Salient facts

  1. [3]

    The following account of the factual matters relevant to the application are drawn from the plaintiff’s evidence, which has not been challenged as the defendants have not appeared.

  2. [4]

    The plaintiff is a boutique family law practice located in Western Australia which routinely acts for persons in a variety of family law matters, providing legal advice, representation and advocacy. The plaintiff has two directors and eleven employees.

  3. [5]

    The plaintiff stores data on computerised servers located in Western Australia (the Paterson & Dowding Servers), including:

    1. (1)

      information provided to the plaintiff by its clients which discloses non-public aspects of the clients’ personal or business affairs, work product of the plaintiff that incorporates such client data, legal advice provided by the plaintiff to its clients, and other communications and documents made or prepared for the dominant purpose of providing legal advice or in anticipation of legal proceedings;

    2. (2)

      information recording the internal, non-public operations of the plaintiff, including client lists, financial information, and information relating to the plaintiff’s directors and current and former employees; and

    3. (3)

      non-public information collected by the plaintiff which records information provided by counter-parties involved in litigation, disputes, or negotiations with clients of the plaintiff,

  4. [6]

    On or about 9 October 2025, unnamed persons claiming to be part of a named ransomware group gained unauthorised access to the Paterson & Dowding Servers and left a text file on the plaintiff’s systems stating that the plaintiff’s files had been encrypted and private data had been downloaded from the plaintiff’s network. The note invited the plaintiff to engage with them through a site on the dark web, and threatened that the data would be published if the plaintiff did not reach an agreement with them. In these reasons, the unnamed persons are referred to collectively as the Threat Actor.

  5. [7]

    The plaintiff did not engage with the Threat Actor, and focussed instead on investigating the incident with the assistance of external expert advisers.

  6. [8]

    The plaintiff’s investigations subsequently ascertained that the Threat Actor had exfiltrated approximately 280,000 files (or 228,000 files after de-duplication) from the Paterson & Dowding Servers. Due to the sheer number of files, it is not feasible for the plaintiff to enumerate each individual file exfiltrated. However, the plaintiff’s investigations to date indicate that a significant portion of the files are or include Paterson & Dowding Data of the kind referred to at [5] above.

  7. [9]

    I refer to all of the data stored on the Paterson & Dowding Servers which the Threat Actor accessed without authorisation as the Impacted Dataset. I refer to the data that was exfiltrated from the Servers by the Threat Actor as the Exfiltrated Dataset.

  8. [10]

    The Threat Actor published the Exfiltrated Dataset on its dark web leak site on 24 October 2025. The plaintiff has adduced evidence from an expert in cybersecurity and digital forensics that the dark web leak site is not accessible via the open web, except via a link published on one particular open web site and only then with the use of specialised software. The expert is unable to determine to what extent the Exfiltrated Dataset has been downloaded by third parties from the Threat Actor’s dark web leak site because the site does not require authentication and does not provide public download statistics. However, searches conducted by the expert and their team have not identified any evidence that the Exfiltrated Dataset has been published to other locations on the dark web outside the Threat Actor’s leak site. Nor have those searches identified any evidence of the Exfiltrated Dataset being published on the open web.

  9. [11]

    To date, there have been 17 online posts and articles referring to the incident in general terms, without referring to any specific Exfiltrated Data or individuals whose information is contained within the Exfiltrated Dataset. Those online posts do not contain direct links to the Threat Actor’s dark web leak site where the Exfiltrated Dataset is available. Google searches conducted by the plaintiff’s solicitor in respect of a sample of the names of individuals whose personal data is contained within the Exfiltrated Dataset indicates that their information is not discoverable on the open web through those means.

  10. [12]

    The plaintiff treats the Paterson & Dowding Data as confidential and has not itself published that data.

  11. [13]

    The plaintiff owes obligations under applicable privacy legislation to take reasonable steps to ensure that the personal information it holds about individuals is protected from misuse, interference and loss, and from unauthorised access, modification or disclosure. The plaintiff also owes professional and contractual obligations to preserve the confidentiality of information provided to it in confidence by its clients and staff. In addition, the plaintiff is subject to certain restrictions on communicating accounts and lists of family law proceedings pursuant to Part XIVB of the Family Law Act 1975 (Cth) and Part 11A of the Family Court Act 1997 (WA).

  12. [14]

    The plaintiff took precautions to protect the confidentiality of the Paterson & Dowding Data, including by implementing technical security barriers to the data stored on the Paterson & Dowding Servers.

  13. [15]

    The plaintiff wishes to take steps to prevent the Threat Actor (or other third parties acting on behalf of the Threat Actor) from accessing, further disclosing or disseminating, or carrying out any action in relation to the Exfiltrated Dataset so as to prevent harm that will otherwise flow, including: (1) reputational and financial damage to the clients, staff, and directors of the plaintiff whose information is included in the Exfiltrated Dataset; (2) financial, operational and reputational damage to the plaintiff itself from the disclosure of information relating to the plaintiff’s operations in the Exfiltrated Dataset; and (3) immense distress and emotional and financial harm to clients and employees of the plaintiff, opposing parties in family law disputes in which the plaintiff has been instructed, and third parties whose personal information may have been disclosed to and stored on the Paterson & Dowding Servers in the course of the plaintiff’s work on client matters and disputes and included in the Exfiltrated Dataset.

  14. [16]

    The identity of the Threat Actor is not known and its precise location cannot be ascertained. The application for default judgment proceeded on the assumption that the Threat Actor is located outside Australia. The evidence adduced by the plaintiff supports that inference.

  15. [17]

    The plaintiff commenced these proceedings on an urgent basis on 12 November 2025 against the defendant “Persons Unknown”, described as any person or entity which:

    1. (1)

      carried out, participated in, or assisted in the exfiltration of some or all of the plaintiff’s Impacted Dataset; or

    2. (2)

      in respect of the Exfiltrated Dataset, communicated extortionate demands or threats to the plaintiff (directly or indirectly), or posted some or all of the Exfiltrated Dataset online.

  16. [18]

    The Court made interim orders on an ex parte basis on that date:

    1. (1)

      restraining the defendants (by themselves, their agents, or by any third party in possession of some or all of the Exfiltrated Dataset) until 5:30pm on 17 November 2025 from doing any of the following without the plaintiff’s written consent:

    2. (2)

      requiring the defendants to take all steps to immediately remove all and any of the Impacted Dataset (including the Exfiltrated Dataset) from all accessible internet locations (including dark web locations).

  17. [19]

    The orders made on 12 November 2025 also included orders for substituted service on the defendants by sending a message to an email address specified by the Threat Actor in its communication with the plaintiff containing a Dropbox link through which copies of the statement of claim and other documents can be downloaded. The plaintiff was granted leave to redact from the copies of the documents served all references to the names, identifying details, and contact details of the plaintiff’s legal representatives, information technology and cyber-security experts, and certain other material. Interim non-publication orders were made pursuant to s 7(b) of the Court Suppression and Non-Publication Orders Act 2010 (NSW). Time for service was abridged to 2:00pm on 13 November 2025.

  18. [20]

    Service was effected by an email sent to the Threat Actor’s email address at 3:12pm on 13 November 2025 and otherwise in accordance with the substituted service orders.

  19. [21]

    On 17 November 2025, the orders referred to at [18] above were extended until further order and the time for service was extended nunc pro tunc to 3:15pm on 13 November 2025.

  20. [22]

    The orders made on 17 November 2025 were subsequently served by email to the Threat Actor’s email address.

Consideration and determination

  1. [23]

    The applicable legal principles are well established. Much of what follows draws heavily on recent judgments in which I have summarised those principles by reference to earlier judgments of this Court. [1] I have been greatly assisted by the detailed submissions made by counsel for the plaintiff in relation to the application of those principles in the circumstances of this case.

  2. [24]

    As I mentioned in passing above, the plaintiff has adduced evidence that the Threat Actor was served on 13 November 2025 with a Form 161 notice, the plaintiff’s statement of claim and notice of motion filed on 12 November 2025, the affidavit relied on by the plaintiff in support of the interim relief claimed in that notice of motion and the exhibit to that affidavit, together with the orders made by the Court on that date, redacted as permitted by the Court’s orders and in accordance with the substituted service orders. The plaintiff’s solicitors received a response to that email, in terms which it is not necessary to recount here. The response establishes that the proceedings have come to the notice of the Threat Actor.

  3. [25]

    Rule 11.8AA of the UCPR is engaged because the defendants, or at least some of them, are most likely located outside Australia and so have been served outside Australia. No appearance has been entered on behalf of any person or persons identifying themselves as a defendant in these proceedings. The time for doing so expired 42 days after service on 13 November 2025, being 25 December 2025. [2]

  4. [26]

    I respectfully agree with Brereton J’s conclusion in University of Notre Dame Australia v Persons Unknown (Notre Dame) [3] that, when considering an unopposed application under r 11.8AA, leave should be granted if:

    1. (1)

      there is proof of service;

    2. (2)

      the Court is satisfied that the originating process, on its face, reveals that the claim engages r 11.4 of the UCPR; and

    3. (3)

      there are no apparent countervailing considerations that would cause the Court to exercise its discretion to decline to grant leave.

  5. [27]

    I respectfully agree with and adopt his Honour’s reasons for that conclusion and his analysis of Agar v Hyde. [4]

  6. [28]

    I am satisfied by the plaintiff’s evidence referred to at [24] above that the Threat Actor has been served with the documents there referred to. As the plaintiff submitted, neither the application for leave under r 11.8AA nor the application for default judgment was required to be served. [5]

  7. [29]

    I accept the plaintiff’s submission that the relief claimed in the statement of claim includes an injunction to restrain the dissemination of the Exfiltrated Dataset at any location on the internet, which must necessarily encompass dissemination in Australia. That engages r 11.4 of the UCPR, which permits service of the statement of claim outside Australia without prior leave of the Court, because the case is of the kind referred to in paragraph (d)(i) of Schedule 6 to the UCPR. [6]

  8. [30]

    Neither the statement of claim nor the evidence that I have summarised at [4]-[16] above reveal any countervailing considerations that would cause the Court to decline to grant leave in this case.

  9. [31]

    No defence has been filed on behalf of any person or persons identifying themselves as a defendant in these proceedings. Irrespective of whether the defendants are permitted 28 days under r 14.3(1) or 42 days under r 11.8 of the UCPR to file a defence, the time for doing so has expired. [7] The defendants are therefore in default for the purpose of Part 16 of the UCPR. [8] The Court therefore has power to enter default judgment, including by granting injunctive relief. [9] Service having been established, the likelihood that the defendants are outside Australia is no obstacle to this Court granting such relief. [10]

  10. [32]

    The Court may give such judgment against the defendants in default as the plaintiff appears to be entitled to on its statement of claim. [11]

  11. [33]

    As the plaintiff submitted, an equitable duty of confidence arises when confidential information comes to the knowledge of a person in circumstances where they have notice that the information is confidential, so that it would be just in all the circumstances that they should be precluded from disclosing the information to others. In order to obtain an equitable remedy for a breach or apprehended breach of the duty, a plaintiff will typically need to identify the information specifically, and establish that it is of a confidential nature and that there has been actual or threatened unauthorised use of the information by the defendant to the detriment of the plaintiff. The requirement to identify the information specifically does not require a plaintiff to individually itemise documents in a case where the defendant has gained unauthorised access to a very large volume of the plaintiff’s confidential information. Such a requirement would be oppressive. The confidential quality of the information is generally demonstrated by the information not being public property and public knowledge, by the plaintiff having expended effort in the creation or collection of the information, and by the plaintiff having taken steps to protect the information and keep it largely to itself. In cases such as the present where a defendant has gained unauthorised access to, encrypted, and taken the plaintiff’s information to extort money from the plaintiff under threat that the information will otherwise be published, it can readily be concluded that the defendants obtained the information with knowledge that it was confidential. [12]

  12. [34]

    The plaintiff’s pleaded case, which is supported by the affidavit evidence, is compelling, in my opinion.

  13. [35]

    The weight of authority favours the view that, in circumstances where the defendant has failed to file a defence to the statement of claim, the factual allegations pleaded in the statement of claim are taken to have been admitted. [13]

  14. [36]

    The plaintiff’s statement of claim pleads facts, the deemed admission of which provides ample support for findings that the plaintiff’s information to which the Threat Actor gained unauthorised access was protected by the plaintiff and included significant volumes of information of the kind referred to at [5] above which is confidential (including because the plaintiff has expended effort in creating or collecting it, its secrecy is guarded by the plaintiff, and it includes privileged legal advice provided by the plaintiff to its clients and information of a private and personal nature concerning the plaintiff’s clients and third parties involved in disputes or litigation with the plaintiff’s clients), [14] that the Threat Actor was on notice that the information was confidential, and that its conduct in surreptitiously exfiltrating the information before making extortionate threats to publish the information make it just that the Threat Actor should be restrained from transmitting, publishing, or disclosing the information to others and should be restrained from using the information. The evidence summarised at [4]-[14] above provides further support for such findings. This is a case in which it would be oppressive to require the plaintiff to individually itemise the confidential information, which has been described in sufficient detail in my opinion in the statement of claim and in the affidavits read by the plaintiff. The evidence referred to at [10]-[11] above establishes that the information has been published on one site on the dark web, but that it has not been re-posted to other sites on the dark web or published on the open web, and that the substance of the information has not been disclosed in any media articles or posts referring to the incident. I accept the plaintiff’s submission that this extent of dissemination by the Threat Actor has not undermined the confidential character of the information and that the information therefore warrants protection. [15]

  15. [37]

    Injunctions in terms similar to those sought by the plaintiff have been granted by way of default judgment in previous cases arising out of unauthorised access to and exfiltration of a plaintiff’s data, including confidential information, by persons who cannot be identified. [16]

  16. [38]

    The defendants have been defined in the statement of claim as persons unknown who have engaged in, or participated in or assisted with, specified conduct, or who made certain communications to the plaintiff. The injunction sought will not operate against the world at large. In my view, the defendants are described with sufficient clarity to identify those included and excluded. [17]

  17. [39]

    Although the terms of the injunction sought mention third parties, it is in the form discussed by Brereton J in Notre Dame, which I consider is appropriate for the same reasons as his Honour gave in that case. [18]

  18. [40]

    I accept the plaintiff’s submission that the injunctions sought have utility, notwithstanding that there is a possibility that the Threat Actor may not obey the injunction. As Slattery J said in HWL Ebsworth, a reputation for wilful disobedience to the law does not confer immunity from injunctions. Moreover, as the plaintiff submitted, it will be open to it to notify third parties of the injunction. [19] Such third parties, properly advised, would be aware that they should not take any step that would frustrate the effectiveness of this Court’s orders. [20]

  19. [41]

    Under s 7 of the Court Suppression and Non-Publication Orders Act, the Court has power to make non-publication orders on one or more of the grounds set out in s 8 of the Act.

  20. [42]

    The plaintiff sought non-publication orders under that Act in the terms set out in paragraph 4 of Annexure A hereto. The information to which those non-publication orders apply falls into three broad categories:

    1. (1)

      certain information about the plaintiff’s information technology systems and data arrangements, its security response to the incident and remediation measures, and its concerns about the effects of public disclosure of the Exfiltrated Data: paragraphs 4(c)(ii) and (vi) of Annexure A;

    2. (2)

      the plaintiff’s knowledge about the Threat Actor and its intentions, its communications with the Threat Actor, and the specific communication channels provided by the Threat Actor to the plaintiff for the purpose of communicating with the Threat Actor: paragraphs 4(c)(iii), (iv) and (vii) of Annexure A; and

    3. (3)

      the names and identifying details and contact details of any person or firm included in documents filed in these proceedings (including witnesses, experts, lawyers and law firms): paragraphs 4(c)(i) and (v) of Annexure A.

  21. [43]

    Taking into account that a primary objective of the administration of justice is to safeguard the public interest in open justice, [21] I am satisfied that the evidence adduced by the plaintiff demonstrates that the non-publication orders in the terms of paragraph 4 of Annexure A are necessary, in the strong sense in which that word is used in this context, [22] to prevent prejudice to the proper administration of justice [23] and/or to protect the safety of any person [24] and/or to serve the public interest in resisting the growing scourge of digital extortion crimes which significantly outweighs the public interest in open justice to the extent that open justice would otherwise inadvertently assist the Threat Actor or other potential threat actors. [25]

  22. [44]

    The evidence adduced by the plaintiff establishes that there is a risk of the Threat Actor, or other potential threat actors, being inadvertently assisted by publication of the first and second categories of information referred to above, including by arming the Threat Actor with information about Paterson & Dowding’s information systems after the incident that would assist the Threat Actor in adapting tactics for further attacks, and disclosing contact details for the Threat Actor to third parties who have no entitlement to the Exfiltrated Dataset but who may wish to acquire or access that data for their own benefit or gain. Indeed, those risks are rather obvious as a matter of common sense, having regard to the increasing incidence of digital extortion which is a matter of common knowledge and is illustrated by the judgments of this Court in previous proceedings arising out of such incidents. [26] It would be contrary to the public interest for the Threat Actor, other potential threat actors or third parties, to be inadvertently assisted in this way by the publication of the first and second categories of information. [27]

  23. [45]

    It would also be prejudicial to the administration of justice in these proceedings if the price of the plaintiff adducing the evidence required to support its application for substantive relief was to directly or indirectly aid the Threat Actor, or other potential threat actors. The very harm that the plaintiff seeks to prevent by commencing and prosecuting these proceedings would be likely to be exacerbated, and it would be likely to be exposed to an increased risk of further incidents of unauthorised access to and exfiltration of its confidential information. Looking to the broader concept of the administration of justice, such a price would be inherently likely to deter prospective future plaintiffs who are the victims of similar incidents from commencing proceedings of this kind in this Court. [28]

  24. [46]

    Non-publication of the first and second categories of information in this case does not preclude the Court from giving reasons for judgment that are amenable to meaningful public scrutiny. Moreover, as counsel for the plaintiff submitted, any person permitted to access the court file will be able to view the information that is the subject of order 4. The order only prohibits the publication of that information by disseminating or providing access to the information to the public or a section of the public by any means.

  25. [47]

    Insofar as they apply to the information in the first and second categories, the operation of the non-publication orders for a period of five years will impact on the open justice principle only to the extent that is, in my opinion, necessary to protect the public interest and to avoid prejudice to the administration of justice in this case and in the broader sense.

  26. [48]

    In relation to the third category of information referred to above, the evidence adduced by the plaintiff establishes that actions taken to disrupt the Threat Actor’s operations – such as the commencement of legal proceedings – heightens the risk of the Threat Actor taking retaliatory action. Previous cases have referred to the known risk of such actions including retaliation and pressure campaigns against individual lawyers, firms, and other individuals such as expert witnesses and expert consultants, who are named in documents filed in court proceedings of this kind as acting for or providing expert advice or assistance to or giving evidence for the plaintiff whose confidential data has been exfiltrated and who has been subjected to ransom demands. Such campaigns may include sending threatening messages to named individuals, publishing or distributing information about named individuals in a way that may expose them to fraud attempts, phishing and other forms of cyber-attack, or attempting to track the movements and whereabouts of named individuals with a view to threatening their physical security.

  27. [49]

    An order for the non-publication of the names and identifying details of those individuals, without going so far as to suppress their identity, is a means of mitigating those risks to their personal safety, and I am satisfied that such orders are necessary for that purpose in this case. The impact of the order on the public interest in open justice is very slight, as it will have no bearing on the substance of the Court’s reasons for judgment and will not preclude the public from scrutinising the work of the Court in this case. It prevents prejudice to the public interest and to the broader administration of justice by mitigating serious personal risks that might otherwise deter experts from providing professional services to plaintiffs who are the victims of cyber-crimes, and that might otherwise deter individual legal practitioners and firms from accepting instructions to appear from plaintiffs in matters of this kind. The ability of parties to proceedings to obtain legal representation should they wish to do so and to engage legal practitioners of their choosing, and the assistance that legal practitioners provide to the Court, is of central importance to the administration of justice in any proceeding.

  28. [50]

    I am satisfied that the three-year duration of the non-publication orders in relation to identifying details of solicitors and law firms and the six-month duration of the orders in relation to counsel is necessary to ameliorate the risks to their safety and to serve the public interest and prevent the prejudice to the administration of justice described above. In seeking only a six-month duration for the order insofar as it applies to identifying details of counsel, counsel accepted that they were in a slightly different position from the law firm. Amongst other things, the role of counsel does not extend to communicating directly with threat actors for the purpose of serving them with proceedings.

  29. [51]

    I am satisfied that the five-year duration of the non-publication orders in relation to identifying details of other named persons is necessary to ameliorate the risks to their safety, and to serve the public interest in plaintiffs being able to obtain such expert assistance as they may require in response to incidents of the kind that gave rise to the present proceedings, without the personal safety of those experts being placed at risk.

Orders

  1. [52]

    For all of the foregoing reasons, I made the orders set out in Annexure A to these reasons on 20 March 2026.

Unofficial copy. Source: NSW Caselaw. Refer to the official version for authoritative text.