Global Privacy and Cybersecurity Law Updates and Analysis
On December 20, 2022, the English High Court has granted the victim of a cyber attack a permanent injunction against cyber attackers whilst the victim organization maintains its anonymity. Generally, a claimant’s identity is public in English court proceedings. Injunctions can be made against unknown and unidentifiable defendants enabling them to be granted against individuals who are acting in breach or threatening to commit a breach.
Background
The claimant provided technology services and its databases contained information concerning various “security-sensitive and highly classified projects of national significance.” The unknown defendant sent a ransom note stating they had downloaded the claimant’s databases and servers and had encrypted some of the claimant’s files. The hackers demanded over U.S. six million in exchange for decryption and non-disclosure of the information via e-mail. The affected data was made up of three main categories: (1) security sensitive; (2) commercially sensitive; and (3) personal data.
Shortly after becoming aware of the cyber attack, the claimant received an ultimatum from the defendant stating it would start to disclose the data on their platform on the “Dark Web.” The claimant immediately sought a without notice injunction to prohibit the defendant from doing so, which the court granted. The claimant then commenced proceedings for breach of confidence, seeking permanent injunctions and damages, without receiving any further communications from the defendant.
Issues Before the High Court and the Decision
The key issues before the High Court and its decision were as follows:
Hunton Andrews Kurth’s Privacy and Cybersecurity practice helps companies manage data at every step of the information life cycle. The firm is a leader in its field and for the fourth consecutive year has been ranked by Computerworld magazine in a survey of more than 4,000 corporate privacy leaders as the top law firm globally for privacy and data security. Chambers and Partners also rated Hunton Andrews Kurth the top privacy and data security practice in its Chambers Global, Chambers USA and Chambers UK guides.
Hunton Andrews Kurth’s award-winning Privacy & Information Security Law Blog is among the top-ranked legal blogs.