Barts Health NHS Trust v Persons Unknown
| Jurisdiction | England & Wales |
| Court | King's Bench Division |
| Judge | Mr Justice Cavanagh |
| Judgment Date | 08 December 2025 |
| Neutral Citation | [2025] EWHC 3230 (KB) |
| Year | 2025 |
| Docket Number | Case No: KB-2025-004501 |
Mr Justice Cavanagh
Case No: KB-2025-004501
IN THE HIGH COURT OF JUSTICE
KING'S BENCH DIVISION
WITHOUT NOTICE
Royal Courts of Justice
Strand, London, WC2A 2LL
Robin Hopkins (instructed by DAC Beachcroft) for the Claimant
Hearing date: 8 December 2025
Approved Judgment
This is a without notice pre-action application for an injunction. It is brought against a Defendant or Defendants whose identities are unknown and who have perpetrated a cyberattack upon the Claimant NHS Trust's IT systems. I will call them the Defendants. Through the cyberattack, the Defendants have exfiltrated certain confidential information and have made it available on the dark web.
This application is being heard on a day when I am the Court 37 and Out of Hours judge. As a result, this judgment will be relatively brief. However, I have had a full opportunity to read the skeleton argument, witness statement, exhibit, draft order, and key authorities that I need to read.
The relief that is sought is an order requiring the Defendant (i) not to use, publish, communicate or disclose the exfiltrated Information to any other person, (ii) to make no further attempts to obtain documents or data from the Trust's IT systems, (iii) to deliver up and/or delete and/or destroy the Information in their possession, custody or control, and (iv) to identify themselves to the Trust's solicitors and provide a witness statement.
It has also been necessary for me to consider whether to hear this application without notice, whether to do so in private, and whether this is an appropriate case in which to give relief against persons unknown. Further, I have been asked to ensure that certain confidential details relating to this case are not made public, in this judgment or elsewhere, and that restrictions are placed on the court file.
I have been assisted by reading Synnovis Services LLP v Persons Unknown [2024] EWHC 2127 (KB), in which Stacey J had to deal with very similar issues to those in this case, and also the cases cited therein, especially the judgment of Ritchie J in Armstrong Watson v Persons Unknown [2023] EWHC 762 (KB). I have further reminded myself of the helpful guidance given as regards the principle of open justice by Nicklin J in PMC v A Local Health Board [2024] EWHC 2969 (KB) at paragraphs 26–37. An appeal against that judgment to the Court of Appeal was successful, but this guidance is nonetheless relevant, and the Court of Appeal did not cast doubt on Nicklin J's general statement of the law relating to open justice: see [2025] EWCA Civ 1126, at paragraph 24. I have also reminded myself that it is necessary to consider whether any derogation from open justice is justified as being strictly necessary both by reference to common law principles and by reference to the relevant articles of the ECHR, as I said in XY v AB [2025] EAT 66.
The Claimant Trust has been represented by Mr Robin Hopkins of Counsel. I am very grateful to Mr Hopkins for his clear and concise submissions.
The facts
The facts are set out in the witness statement of an employee of the Trust, whom I will call Witness A. I do not propose to name the witness because I am persuaded that it would be wrong to do so, primarily because of the risk that the witness might be made subject to reprisals from the Defendants or their associates.
It is only necessary to summarise the facts in broad terms. They are set out in Witness A's witness statement and exhibits. I take the summary largely from the Trust's skeleton argument.
The Cyberattack was perpetrated on the Trust's IT systems over the period August-September 2025. It appears likely – though there is no way this can be established conclusively – that it was perpetrated by a well-known criminal cyberattack and ransomware group known as “CL0P” (whom the Claimant calls the “Threat Actor”). The Cyberattack was carried out by the exploitation of a business management application of Oracle Corporation UK Limited (“Oracle”), the Oracle Business E-Suite, which is a financial system for invoicing, accounts payable and general ledger requirements. The evidence suggests this was part of, or mirrored, a wider wave of attacks on a number of organisations around the world, deploying the same attack methodology. Once Oracle discovered the vulnerability that the Threat Actor had exploited, it alerted its customers to the necessary patching steps on 6 October 2025. The Trust acted promptly to apply the patch.
In the interim, the Threat Actor sent a ransom demand to NHS England on 29 September 2025, indicating that they were “CL0P”. That demand was an obvious attempt at extortion and blackmail. The nature of the systems and data affected by the attack referred to in those emails was not clear. On advice, and in accordance with a wider public sector policy of not engaging with ransom attackers, NHS England did not communicate with the Threat Actor, but instead liaised with the relevant policing and cybersecurity authorities.
On 13 November 2025, all or the substantial majority of the Information was published on the dark web, where it has been made available at one location, from which it has been downloaded by a limited number of parties.
On 14 November 2025, the Trust was alerted to the fact that the Information was its data. The Trust promptly commenced its investigations into this matter, including liaising with NHS England, police authorities and the National Crime Agency. The Trust's investigation work continues, as does its evaluation of any necessary and appropriate steps for communicating with the individuals whose data is contained in the Information (the “Compromised Data Subjects”).
The Information relates to patients of the Trust and also to patients of Barking, Havering and Redbridge University Hospitals NHS Trust (“BHRUT”), for whom the Trust acted as a data processor in respect of certain payment processes. The Information is particularised in Witness A's statement, but in broad terms it concerns payments, and is not patient or medical data in the wide sense.
In common with NHS England's approach, the Trust has not contacted the Threat Actor. The Trust has no realistic way of preventing further misuse of the Information, absent an order from the Court. The Trust issued its application for an injunction on 4 December 2025 (19 days after it was informed of the Cyberattack and the exfiltration of the Information).
The application is made before the claim form has been issued
This application has been made before the claim form has been issued. I am satisfied that the application should proceed on this basis, given its importance and the urgency. The Claimant is required to, and does, undertake to issue the claim form immediately: CPR 25.8(2).
Hearing in private
The first issue is whether, exceptionally, the hearing should take place in private. I have decided that it should. The general rule, of course, is that a hearing should be in public. See CPR 39.2(1). A hearing in private is a derogation from open justice. I bear in mind the fundamental principle of open justice, both at common law and in accordance with Art 6 of the ECHR, and of the importance of freedom of expression. I am satisfied that in the circumstances of this case, it is strictly necessary to proceed in private because publicity would defeat the object of the hearing ( CPR 39.2(3)(a)) and because publicity would damage the confidentiality with which this hearing is concerned ( CPR 39.2(3)(c)). A public hearing would run the inescapable risk of making public details of the Cyberattack and its consequences, and may also give rise to the identification of witness A. Importantly, publication may assist those who were minded to exploit the information that was obtained in the Cyberattack. On the evidence before me, the Defendants appear to have been engaged in criminal activity and they have no overriding countervailing rights which override the necessity for a private hearing. As this is a hearing without notice, there is no restriction on the Defendants' freedom of speech.
Hearing without notice
It is now well-established that it is appropriate for the court to sit in private to deal with an application relating to theft of confidential information and blackmail (see Armstrong Watson, paragraph 18 and the cases referred to therein), though each case must considered on its own merits.
I am also satisfied that there are overwhelmingly strong reasons to proceed without notice to the Defendants, pursuant to CPR 25.3(2). There is very strong evidence before me that the Defendants, whoever they are, are criminals who are seeking to blackmail and to extort and to cause harm to a Health Trust and to its patients to achieve their aims. The aim of this application is to obstruct their criminal enterprise and to limit its adverse effects. Nor would any purpose be served by adjourning to give the Claimant an opportunity to identify the Defendants. There is a real risk that if the Defendants became aware that the Claimants were on their trail, they would retaliate by taking steps to cause further harm to the Trust. At the very least, it may give them an...
Get this document and AI-powered insights with a free trial of vLex and Vincent AI
Get Started for FreeStart Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting
Start Your Free Trial of vLex and Vincent AI, Your Precision-Engineered Legal Assistant
-
Access comprehensive legal content with no limitations across vLex's unparalleled global legal database
-
Build stronger arguments with verified citations and CERT citator that tracks case history and precedential strength
-
Transform your legal research from hours to minutes with Vincent AI's intelligent search and analysis capabilities
-
Elevate your practice by focusing your expertise where it matters most while Vincent handles the heavy lifting