Barts Health NHS Trust v Persons Unknown

[2025] EWHC 3230 (KB)

Case details

Case citations
[2025] EWHC 3230 (KB)
Court
High Court (King's Bench Division)
Judgment date
8 December 2025
Judgment text

This feature is available to zoomLaw Pro members.

Subjects
Civil procedure Confidentiality and privacy Interim injunctions
Keywords
cyberattack breach of confidence persons unknown without-notice injunction dark web confidential information anti-hacking injunction unmasking order delivery up service outside the jurisdiction
Outcome
application granted
Judicial consideration

This feature is available to zoomLaw Pro members.

Summary

Interim injunctive relief may be granted against persons unknown to restrain the misuse and dissemination of confidential information obtained through an unlawful cyberattack. The court should consider the ordinary interim-relief principles, subject to the stricter requirement under Human Rights Act 1998 section 12 where freedom of expression is engaged.

Where the evidence shows unlawful exfiltration for extortion, the information does not lose its confidential character merely because the attackers have published it on the dark web. Damages may be inadequate where confidentiality and privacy require protection. Mandatory delivery-up, unmasking and anti-hacking orders may be made where they are reasonable, proportionate and just and convenient.

Factual background

This was a without-notice pre-action application by an NHS Trust following a cyberattack in which confidential payment-related information concerning patients was exfiltrated and published on the dark web. The Trust sought orders restraining publication and disclosure, preventing further unauthorised access, requiring delivery up or destruction of the information, and requiring the unknown defendants to identify themselves.

The court also considered whether the hearing should be private, whether relief could be granted against persons unknown, restrictions on access to the court file, and service outside the jurisdiction by email. The central issues were whether interim relief was justified, whether the proceedings could properly proceed without notice, and what ancillary and procedural orders were appropriate.

Held

  1. Procedure and confidentiality. The application could proceed before issue of the claim form, subject to the undertaking to issue it immediately under Civil Procedure Rules 1998 rule 25.8(2). The hearing was properly conducted in private because publicity would risk defeating the object of the hearing and damaging confidentiality. Restrictions on non-party access to the claim documents were also strictly necessary and proportionate.
  2. Without-notice relief. There were overwhelmingly strong reasons not to notify the unknown defendants. Notice could lead to retaliation, further harm or the covering of tracks, and attendance was unrealistic. The requirements for proceeding in the defendants’ absence under Human Rights Act 1998 section 12(2)(b) were therefore met, if applicable. The Trust had complied with its duty of full and frank disclosure.
  3. Interim injunction. Applying American Cyanamid v Ethicon [1975 AC] 396 and Human Rights Act 1998 section 12(3), there was a serious issue to be tried and, assuming the Act was engaged, the Trust was more likely than not to establish that publication should not be allowed. The information retained the necessary quality of confidence despite limited dark-web dissemination by the attackers themselves. No credible defence, public-interest justification or protectable right was apparent.
  4. Damages were plainly inadequate because the primary objective was to protect the confidentiality and privacy of affected data subjects, and the defendants would not respect a damages award. The balance of convenience strongly favoured relief. The court rejected as misconceived the argument that an injunction should be refused because the defendants might disobey it.
  5. Mandatory delivery-up and destruction orders were reasonable and proportionate. Unmasking and anti-hacking orders were also appropriate, given the apparently unlawful conduct, anonymity of the attackers and risk of further unauthorised access. The injunction and ancillary orders were granted.
  6. Permission was granted for service outside the jurisdiction by email addresses supplied by the threat actor. The service-out tests, including a reasonable prospect of success and England and Wales being the proper forum, were satisfied.

The court’s approach to earlier authorities

This feature is available to zoomLaw Pro members.

Key cases cited

This feature is available to zoomLaw Pro members.

Cases citing this case

This feature is available to zoomLaw Pro members.