← All cases

[2026] NSWSC 296

Creata Holdings Pty Ltd v Persons Unknown

Default judgment entered and orders made in terms of Annexure A

Catchwords

EQUITY – Equitable remedies – injunctions – where the plaintiffs seek leave to proceed pursuant to UCPR r 11.8AA – where plaintiffs seek injunctions by way of default judgment against persons whose identities are unknown, but who are defined in the statement of claim by reference to specified past conduct and/or communications with sufficient clarity that the injunctions do not operate against the world at large

Cases cited

  • Agar v Hyde (2000) 201 CLR 552;[2000] HCA 41
  • Ansell Limited v Persons Unknown[2026] NSWSC 65
  • Australian Medical Association (WA) Incorporated v Persons Unknown[2026] NSWSC 111
  • Brady v Brady[2025] NSWSC 217
  • Commonwealth of Australia v John Fairfax & Sons Ltd (1980) 147 CLR 39;[1980] HCA 44
  • DRJ v Commissioner of Victims Rights[2020] NSWCA 136
  • Del Casale v Artedomus (Aust) Pty Ltd (2007) 73 IPR 326;[2007] NSWCA 172
  • Fairfield City Council v Persons Unknown[2026] NSWSC 195
  • HWL Ebsworth Lawyers v Persons Unknown (2024) 113 NSWLR 418;[2024] NSWSC 71
  • Mid-City Skin & Laser Centre Pty Ltd v Zahedi-Anarak (2006) 67 NSWLR 569;[2006] NSWSC 844
  • Nationwide News Pty Ltd v Quami (2016) 93 NSWLR 384;[2016] NSWCCA 97
  • Paterson & Dowding v Persons Unknown[2026] NSWSC 273
  • Qantas Airways Ltd v Persons Unknown[2025] NSWSC 776
  • Qantas Airways Ltd v Persons Unknown (No 2)[2025] NSWSC 1328
  • ReadyTech Holdings Ltd v Persons Unknown[2026] NSWSC 66
  • Rinehart v Welker (2011) 93 NSWLR 311;[2011] NSWCA 403
  • Streetscape Projects Australia Pty Ltd v City of Sydney (2013) 85 NSWLR 196;[2013] NSWCA 2
  • University of Notre Dame Australia v Persons Unknown[2025] NSWSC 550
  • Wentworth Partners Estate Agents Pty Ltd t/as Re Max Gold v Gordony[2007] NSWSC 1135
  • X v Twitter Inc (2017) 95 NSWLR 301;[2017] NSWSC 1300
  • X v Y & Z[2017] NSWSC 1214

Legislation cited

  • Court Suppression and Non-publication Orders Act 2010 (NSW), § 6, 7, 8
  • Uniform Civil Procedure Rules 2005 (NSW), § 11.8, 11.8AA, 14.26, 16.2, 16.3, 16.10

Judgment

Introduction

  1. [1]

    These reasons concern the plaintiffs’ notice of motion filed on 16 February 2026 seeking leave to proceed pursuant to r 11.8AA of the Uniform Civil Procedure Rules 2005 (NSW) (UCPR), injunctive relief on a final basis by way of default judgment, non-publication orders pursuant to the Court Suppression and Non-Publication Orders Act 2010 (NSW), and an order restricting access by news media organisations to parts of the court file.

  2. [2]

    At the conclusion of the hearing of the notice of motion on 27 March 2026, I made orders in the terms sought by the plaintiffs and reproduced in Annexure A hereto on the basis that my reasons for doing so would be published as soon as practicable. These are those reasons.

Salient facts

  1. [3]

    The following account of the factual matters relevant to the application are drawn from the plaintiffs’ evidence, which has not been challenged as the defendants have not appeared.

  2. [4]

    The twelve plaintiffs are a group of companies in the business of supporting major retail brands by delivering promotional campaigns, product design, manufacturing, and digital experiences to enhance brand visibility and customer interaction. The plaintiffs trade under the name “Creata” and I will refer to them collectively as the Creata Group. The first, second and third plaintiffs are Australian private companies. The fourth to twelfth plaintiffs are foreign companies. The fourth, seventh, eleventh and twelfth plaintiffs are wholly owned subsidiaries of the first plaintiff. The Creata Group has offices in multiple jurisdictions, including at Thornleigh in New South Wales, the United States, the United Kingdom, Brazil, Germany, China and Hong Kong. All of the plaintiffs, including those who are not subsidiaries of the first plaintiff or another member of the Creata Group, carry on the global business of the Creata Group together and use the servers and collect and use the data that are the subject of these proceedings.

  3. [5]

    The Creata Group holds data and information within computerised servers operated by or on behalf of the Creata Group, including physical on-premises servers at the Creata Group offices in Thornleigh, Chicago, Shenzhen, and Hong Kong, and cloud-based infrastructure hosted in a third-party data centre located in Melbourne, Victoria (the Servers). The data stored on the Servers includes personal information relating to the plaintiffs’ employees, personal information relating to the plaintiffs’ clients and the customers of their clients, and the plaintiffs’ client lists and client-related commercial data.

  4. [6]

    On or about 8 November 2025, the plaintiffs became aware that unnamed persons claiming to be part of a named group had gained unauthorised access to the Servers and encrypted them with ransomware. In the course of investigating this activity, the plaintiffs discovered a ransom note which claimed that their network/system had been encrypted, that the unnamed persons had downloaded compromising and sensitive data from the network/system (including some of the kinds of information referred to at [5] above), and that the data would be published if the plaintiffs refused to communicate or failed to come to an agreement with the unnamed persons. The ransom note included instructions for the plaintiffs to communicate with the unnamed persons only through a specified chat room. In these reasons, the unnamed persons are referred to collectively as the Threat Actor.

  5. [7]

    The Threat Actor posted a message in the chatroom repeating its claim to have encrypted the plaintiffs’ data and to have exfiltrated compromising and sensitive data from the plaintiffs’ systems and network, and demanding payment of a specified sum in return for the Threat Actor providing decryption tools and a complete list of all files they had taken from the Servers.

  6. [8]

    The Creata Group has not paid the ransom demanded by the Threat Actor, and has no present intention to do so. Nor has it paid any other sum to the Threat Actor.

  7. [9]

    The Creata Group’s investigations have ascertained that the Threat Actor exfiltrated approximately 3.3 terabytes of data from the Servers. The full extent of the exfiltration remains under investigation and cannot be determined due to the available logs and the destruction of evidence by the Threat Actor. For this reason, and due to the large number of files that are presently known to have been encrypted and exfiltrated, it is not feasible to enumerate all of the specific files that the Threat Actor exfiltrated from the Servers. However, having regard to the nature of the data stored on the Servers (as referred to at [5] above) and the nature of the data that the Threat Actor claimed to have exfiltrated in the ransom note referred to at [6] above, it is probable that the Exfiltrated Dataset includes a significant quantity of personal information and commercial data of the kind referred to at [5] above. The Creata Group presently estimates that approximately 128GB of the Exfiltrated Data (in excess of 1,000 files) comprises personal information relating to the Creata Group employees and customers of Creata Group’s clients.

  8. [10]

    I refer to all of the data stored on the Servers which the Threat Actor accessed without authorisation as the Impacted Dataset. I refer to the data that was exfiltrated from the Servers by the Threat Actor as the Exfiltrated Dataset.

  9. [11]

    The Creata Group has notified various government agencies and regulators of the incident, including the Australian Cyber Security Centre, the Office of the Australian Information Commissioner, and the Department of Home Affairs.

  10. [12]

    The Creata Group takes precautions to prevent unauthorised access to and use of its data and information on the Servers by employing physical barriers to the Servers and technical security barriers to the data stored on them. The Creata Group has never itself published the Exfiltrated Dataset online.

  11. [13]

    The Creata Group wishes to take all reasonable steps within its power to protect its relationships with its clients and their customers, and its relationships with its employees, whose personal information is stored on the Servers and who may be exposed to the risk of identity theft or fraud as a result of the Threat Actor’s exfiltration of and threat to publish that information. The Creata Group wishes to protect the interests of those affected persons, and also to protect itself from potential legal liability that may arise under third-party contractual arrangements as a result of the incident and to prevent harm to its operations that would result from any publication of the Exfiltrated Dataset.

  12. [14]

    The identity of the Threat Actor is not known and its precise location cannot be ascertained. The application for default judgment proceeded on the assumption that the Threat Actor is located outside Australia. The evidence adduced by the Creata Group supports that inference.

  13. [15]

    The Creata Group commenced these proceedings on an urgent basis on 8 December 2025 against the defendant “Persons Unknown”, described as any person or entity which:

    1. (1)

      carried out, participated in or assisted in the exfiltration of some or all of the Creata Group’s Impacted Dataset; or

    2. (2)

      in respect of the Exfiltrated Dataset, communicated payment demands or threats to the Creata Group (directly or indirectly), or posted some or all of the Exfiltrated Dataset online (whether for sale or otherwise).

  14. [16]

    The Court made interim orders on an ex parte basis on that date:

    1. (1)

      restraining the defendants (by themselves, their agents, or by any third party in possession of some or all of the Exfiltrated Dataset) until 5:00pm on 11 December 2025 from doing any of the following without the plaintiffs’ written consent:

    2. (2)

      requiring the defendants to take all steps to immediately remove any of the Impacted Dataset (including the Exfiltrated Dataset) from all accessible internet locations (including “dark web” locations).

  15. [17]

    On 11 December 2025, those orders were extended until further order.

  16. [18]

    The orders made on 8 December 2025 also included orders for substituted service on the defendants by sending a message to the chatroom specified by the Threat Actor containing a Dropbox link through which copies of the statement of claim and other documents can be downloaded. The plaintiffs were granted leave to redact from the copies of the documents served all references to the names, identifying details, and contact details of the plaintiffs’ legal representatives, information technology and cyber-security experts, and certain other material. Interim non-publication orders were made pursuant to s 7(b) of the Court Suppression and Non-Publication Orders Act 2010 (NSW). Time for service was abridged to 2:00pm on 9 December 2025.

  17. [19]

    At the time of the hearing of the application for default judgment, the Threat Actor has not published the Exfiltrated Dataset online insofar as the Creata Group has been able to ascertain. However, having regard to the ransom note, there remains an ongoing material risk that the Threat Actor will publish or otherwise disseminate the Exfiltrated Dataset. The incident has been referred to in some media articles, but those articles do not disclose the contents of the Exfiltrated Dataset.

Consideration and determination

  1. [20]

    The applicable legal principles are well established. Much of what follows draws heavily on recent judgments in which I have summarised those principles by reference to earlier judgments of this Court. [1] I have been greatly assisted by the detailed submissions made by counsel for the Creata Group in relation to the application of those principles in the circumstances of this case.

  2. [21]

    The Creata Group has adduced evidence that, on 9 December 2025, the Threat Actor was served in accordance with the substituted service orders made on 8 December 2025 with: a Form 161 notice; the plaintiffs’ statement of claim and notice of motion filed on 8 December 2025; the affidavit relied on by the plaintiffs in support of the interim relief claimed in the notice of motion and the exhibit to that affidavit; and the written submissions made by counsel for the plaintiffs at the hearing on 8 December 2025, together with the orders made by the Court on that date, redacted as permitted by the Court’s orders.

  3. [22]

    Rule 11.8AA of the UCPR is engaged because the defendants, or at least some of them, are most likely located outside Australia and so have been served outside Australia. No appearance has been entered on behalf of any person or persons identifying themselves as a defendant in these proceedings. The time for doing so expired 42 days after service on 9 December 2025, being 20 January 2026. [2]

  4. [23]

    I respectfully agree with Brereton J’s conclusion in University of Notre Dame Australia v Persons Unknown (Notre Dame) [3] that, when considering an unopposed application under r 11.8AA, leave should be granted if:

    1. (1)

      there is proof of service;

    2. (2)

      the Court is satisfied that the originating process, on its face, reveals that the claim engages r 11.4 of the UCPR; and

    3. (3)

      there are no apparent countervailing considerations that would cause the Court to exercise its discretion to decline to grant leave.

  5. [24]

    I respectfully agree with and adopt his Honour’s reasons for that conclusion and his analysis of Agar v Hyde. [4]

  6. [25]

    In the present case, I am satisfied by the evidence referred to at [21] above that the Threat Actor has been served with the documents there referred to. As the Creata Group submitted, neither the application for leave under r 11.8AA nor the application for default judgment was required to be served. [5]

  7. [26]

    I accept the Creata Group’s submission that the relief claimed in the statement of claim includes an injunction to restrain the dissemination of the Exfiltrated Dataset at any location on the internet, which must necessarily encompass dissemination in Australia. That engages r 11.4 of the UCPR, which permits service of the statement of claim outside Australia without prior leave of the Court, because the case is of the kind referred to in paragraph (d)(i) of Schedule 6 to the UCPR. [6]

  8. [27]

    Neither the statement of claim nor the evidence that I have summarised at [4]-[19] above reveal any countervailing considerations that would cause the Court to decline to grant leave in this case.

  9. [28]

    No defence has been filed on behalf of any person or persons identifying themselves as a defendant in these proceedings. Irrespective of whether the defendants are permitted 28 days under r 14.3(1) or 42 days under r 11.8 of the UCPR to file a defence, the time for doing so has expired. The defendants are therefore in default for the purpose of Part 16 of the UCPR. [7] The Court therefore has power to enter default judgment, including by granting injunctive relief. [8] Service having been established, the likelihood that the defendants are outside Australia is no obstacle to this Court granting such relief. [9]

  10. [29]

    The Court may give such judgment against the defendants in default as the plaintiffs appear to be entitled to on their statement of claim. [10]

  11. [30]

    As the plaintiffs submitted, an equitable duty of confidence arises when confidential information comes to the knowledge of a person in circumstances where they have notice that the information is confidential, so that it would be just in all the circumstances that they should be precluded from disclosing the information to others. In order to obtain an equitable remedy for a breach or apprehended breach of the duty, a plaintiff will typically need to identify the information specifically, and establish that it is of a confidential nature and that there has been actual or threatened unauthorised use of the information by the defendant to the detriment of the plaintiff. The requirement to identify the information specifically does not require a plaintiff to individually itemise documents in a case where the defendant has gained unauthorised access to a very large volume of the plaintiff’s confidential information. Such a requirement would be oppressive. The confidential quality of the information is generally demonstrated by the information not being public property and public knowledge, by the plaintiff having expended effort in the creation or collection of the information, and by the plaintiff having taken steps to protect the information and keep it largely to itself. In cases such as the present where a defendant has gained unauthorised access to, encrypted, and taken the plaintiff’s information to extort money from the plaintiffs under threat that the information will otherwise be published, it can readily be concluded that the defendants obtained the information with knowledge that it was confidential. [11]

  12. [31]

    The plaintiffs’ pleaded case, which is supported by the affidavit evidence, is compelling, in my opinion.

  13. [32]

    The weight of authority favours the view that, in circumstances where the defendant has failed to file a defence to the statement of claim, the factual allegations pleaded in the statement of claim are taken to have been admitted. [12]

  14. [33]

    The plaintiffs’ statement of claim pleads facts, the deemed admission of which provides ample support for findings that the plaintiff’s information to which the Threat Actor gained unauthorised access was protected by the Creata Group and included significant volumes of personal and commercial information of the kind referred to at [5] above which is confidential (including because the Creata Group has developed effort in creating or collecting it, its secrecy is guarded by the Creata Group, and it includes information of a private and personal nature concerning the Creata Group’s clients and customers of those clients), [13] that the Threat Actor was on notice that the information was confidential, and that its conduct in surreptitiously exfiltrating the information before making extortionate threats to publish the information make it just that the Threat Actor should be restrained from transmitting, publishing, or disclosing the information to others and should be restrained from using the information. The evidence summarised at [4]-[13] above provides further support for such findings. This is a case in which it would be oppressive to require the plaintiffs to individually itemise the confidential information, which has been described in sufficient detail in my opinion in the statement of claim and in the affidavits read by the plaintiffs. As there has been no transmission, publication or dissemination of the information to date, I accept the submission that the information retains its quality of confidence and warrants protection.

  15. [34]

    Injunctions in terms similar to those sought by the plaintiff have been granted by way of default judgment in previous cases arising out of unauthorised access to and exfiltration of a plaintiff’s data, including confidential information, by persons who cannot be identified. [14]

  16. [35]

    The defendants have been defined in the statement of claim as persons unknown who have engaged in, or participated in or assisted with, specified conduct, or who directly or indirectly made certain communications to the plaintiffs. The injunction sought will not operate against the world at large. In my view, the defendants are described with sufficient clarity to identify those included and excluded. [15]

  17. [36]

    Although the terms of the injunctions sought mention third parties, it is in the form discussed by Brereton J in Notre Dame, which I consider is appropriate for the same reasons as his Honour gave in that case. [16]

  18. [37]

    I accept the Creata Group’s submission that the injunctions sought have utility, notwithstanding that there is a possibility that the Threat Actor may not obey the injunction. As Slattery J said in HWL Ebsworth, a reputation for wilful disobedience to the law does not confer immunity from injunctions. Moreover, as the Creata Group submitted, it will be open to it to notify third parties of the injunction. [17] Such third parties, properly advised, would be aware that they should not take any step that would frustrate the effectiveness of this Court’s orders. [18]

  19. [38]

    Under s 7 of the Court Suppression and Non-Publication Orders Act, the Court has power to make non-publication orders on one or more of the grounds set out in s 8 of that Act.

  20. [39]

    The Creata Group sought non-publication orders under the Act in the terms set out in paragraph 4 of Annexure A hereto. The information to which those non-publication orders apply falls into three broad categories:

    1. (1)

      certain information about the Creata Group’s information technology systems and data arrangements, its security response to the incident and remediation measures, and its concerns about the effects of public disclosure of the Exfiltrated Data: paragraphs 4(c)(2) and (6) of Annexure A;

    2. (2)

      the Creata Group’s knowledge about the Threat Actor and its intentions, its communications with the Threat Actor, and the specific communication channels provided by the Threat Actor to the Creata Group for the purpose of communicating with the Threat Actor: paragraphs 4(c)(3), (4) and (7) of Annexure A; and

    3. (3)

      the names and identifying details and contact details of any person or firm included in documents filed in these proceedings (including witnesses, experts, lawyers and law firms): paragraphs 4(c)(1) and (5) of Annexure A.

  21. [40]

    Taking into account that a primary objective of the administration of justice is to safeguard the public interest in open justice, [19] I am satisfied that the evidence adduced by the Creata Group demonstrates that the non-publication orders in the terms of paragraph 4 of Annexure A are necessary, in the strong sense in which that word is used in this context, [20] to prevent prejudice to the proper administration of justice [21] and/or to protect the safety of any person [22] and/or to serve the public interest in resisting the growing scourge of digital extortion crimes which significantly outweighs the public interest in open justice to the extent that open justice would otherwise inadvertently assist the Threat Actor or other potential threat actors. [23]

  22. [41]

    The Creata Group has adduced evidence of a risk that publication of the first and second categories of information referred to above may inadvertently assist the Threat Actor or other potential threat actors, including by disclosing contact details for the Threat Actor to third parties who have no entitlement to the Exfiltrated Data but who may wish to acquire or access that data for their own benefit or gain. Indeed, those risks are rather obvious as a matter of common sense, having regard to the increasing incidence of digital extortion which is a matter of common knowledge and is illustrated by the judgments of this Court in previous proceedings arising out of such incidents. [24] It would be contrary to the public interest for the Threat Actor, other potential threat actors or third parties, to be inadvertently assisted in this way by the publication of the first and second categories of information. [25]

  23. [42]

    It would also be prejudicial to the administration of justice in these proceedings if the price of the Creata Group adducing the evidence required to support its application for substantive relief was to directly or indirectly aid the Threat Actor, or other potential threat actors. The very harm that the Creata Group seeks to prevent by commencing and prosecuting these proceedings would be likely to be exacerbated, and it would be likely to be exposed to an increased risk of further incidents of unauthorised access to and exfiltration of its confidential information. Looking to the broader concept of the administration of justice, such a price would be inherently likely to deter prospective future plaintiffs who are the victims of similar incidents from commencing proceedings of this kind in this Court. [26]

  24. [43]

    The proposed non-publication orders in respect of the first and second categories of information do not interfere with the Court from giving reasons for judgment in this case that are amenable to meaningful public scrutiny. Moreover, as counsel for the Creata Group submitted, any person permitted to access the court file will be able to view the information that is the subject of order 4. The order only prohibits the publication of that information by disseminating or providing access to the information to the public or a section of the public by any means.

  25. [44]

    Insofar as they apply to the information in the first and second categories, the operation of the non-publication orders for a period of five years will impact on the open justice principle only to the extent that is, in my opinion, necessary to protect the public interest and to avoid prejudice to the administration of justice in this case and in the broader sense.

  26. [45]

    In relation to the third category of information referred to above, the evidence adduced by the Creata Group establishes that its solicitors are a specialist legal and advisory firm that provides a range of services in relation to cyber, privacy and digital risk in Australia and New Zealand. In the relatively short period of time since the firm was established, it has frequently acted on multiple cyber incidents involving the same threat actor or group of threat actors. The firm receives instructions on a regular basis to make applications for injunctive relief of the kind sought in the present proceedings.

  27. [46]

    The evidence adduced by the Creata Group also establishes that threat actors are prone to engaging in retaliation and pressure campaigns against individual lawyers, firms, and other individuals such as expert witnesses and expert consultants, who are named in documents filed in court proceedings of this kind as acting for or providing expert advice or assistance to or giving evidence for the plaintiff whose confidential data has been exfiltrated and who has been subjected to ransom demands. The evidence establishes that such campaigns may include sending threatening messages to named individuals, publishing or distributing information about named individuals in a way that may expose them to fraud attempts, phishing and other forms of cyber-attack, or attempting to track the movements and whereabouts of named individuals with a view to threatening their physical security.

  28. [47]

    An order for the non-publication of the names and identifying details of those individuals, without going so far as to suppress their identity, is a means of mitigating those risks to their personal safety, and I am satisfied that such orders are necessary for that purpose in this case. The impact of the order on the public interest in open justice is very slight, as it will have no bearing on the substance of the Court’s reasons for judgment and will not preclude the public from scrutinising the work of the Court in this case. It prevents prejudice to the public interest and to the broader administration of justice by mitigating serious personal risks that might otherwise deter experts from providing professional services to plaintiffs who are the victims of cyber-crimes, and that might otherwise deter individual legal practitioners and firms from accepting instructions to appear from plaintiffs in matters of this kind. The ability of parties to proceedings to obtain legal representation should they wish to do so and to engage legal practitioners of their choosing, and the assistance that legal practitioners provide to the Court, is of central importance to the administration of justice in any proceeding.

  29. [48]

    I am satisfied that the three-year duration of the non-publication orders in relation to identifying details of solicitors and law firms and the six-month duration of the orders in relation to counsel is necessary to ameliorate the risks to their safety and to serve the public interest and prevent the prejudice to the administration of justice described above, having regard to the frequency with which the law firm acting for the plaintiff acts in matters of this kind. In seeking only a six-month duration for the order insofar as it applies to identifying details of counsel, counsel accepted that they were in a slightly different position from the law firm. Amongst other things, the role of counsel does not extend to communicating directly with threat actors for the purpose of serving them with proceedings.

  30. [49]

    I am satisfied that the five-year duration of the non-publication orders in relation to identifying details of other named persons is necessary to ameliorate the risks to their safety, and to serve the public interest in plaintiffs being able to obtain such expert assistance as they may require in response to incidents of the kind that gave rise to the present proceedings, without the personal safety of those experts being placed at risk.

Orders

  1. [50]

    For all of the foregoing reasons, I made the orders set out in Annexure A to these reasons on 27 March 2026.

Unofficial copy. Source: NSW Caselaw. Refer to the official version for authoritative text.