DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Paradise Papers firm tries to prevent further releases of data

Posted on January 23, 2018 by Dissent

Ian Health reports that Appleby, a firm at the centre of the Paradise Papers data leak, has hired a high-profile media lawyer to help block further releases of confidential client data. Health reports:

Appleby have maintained that the documents were illegally hacked from their files and have since initiated legal proceedings against the BBC and the Guardian, who they claim have not co-operated with information requests they have made.

The firm issued a claim for breach of confidence on 4 December, as well as an application for disclosure and information. Appleby says that it needs to know what documents were taken from its files so it can advise its clients.

Read more on Jersey Evening Post.

For its part, Appleby issued the following media statement to explain its reasons for its litigation:

“The first procedural hearing in relation to Appleby’s legal action against the Guardian and the BBC took place on Tuesday 16 January. Mrs Justice Rose has reserved her decision and both parties will be notified when this decision is reached.

Appleby issued a claim for breach of confidence against the BBC and The Guardian on 4 December 2017. It simultaneously issued an application for disclosure and information from the BBC and the Guardian.

Appleby’s main objective of this application, and indeed the proceedings as a whole, is to understand which of our confidential and privileged documents were stolen by hackers so that we can for example respond meaningfully to clients and colleagues about what information, relating to them, has been taken. This is something that we have repeatedly requested over a period of months and has always been refused by BBC and Guardian journalists.

This case is not about trying to identify journalistic sources or suppressing freedom of speech. We do not understand how us being informed of what documents have been taken could lead to the identification of any source. In addition, correspondence shows that we did all we could to co-operate with the BBC and the Guardian before their publication deadlines.

This case is about taking reasonable and proportionate steps to identify what information has been stolen from us. Our claim is narrow in its main focus. It is for breach of confidentiality including most importantly in legally privileged documents.

Reluctantly we have concluded that in the absence of any voluntary co-operation from the BBC and the Guardian, the only way for us to find out what information has been stolen, which we are morally obliged to provide to our clients and colleagues, is through the courts”.

Please ensure this statement is published or included in its entirety in any article and attributed to Appleby.

Appleby wish to make no further comment in this regard.

So… what do you think about the litigation now that you’ve read their statement? Do you think they have a valid justification?

If this case was here, the media could use the data they had been provided and would have no obligation not to publish it. Could a victim here get an injunction barring further releases of data from a hack or leak under the circumstances of this case? I almost think they couldn’t, but then, IANAL and all those other disclaimers.

But that’s just one aspect: further disclosure. The other issue is providing a victim with information on the scope of a hack or breach. If this was in the U.S., it would not be the BBC’s or the Guardian’s responsibility to provide forensics or breach investigation help to Appleby. But what about in the U.K.?  What is the law there?

I’m intrigued that Appleby has retained Hugh Tomlinson QC.  I can understand Tomlinson representing them on the issue of further disclosure, as he has represented clients who wished to suppress publication of embarrassing details. But does Tomlinson accepting this case mean that he actually believes that the media has a duty to not publish material of high public interest and import and/or to assist breach victims by revealing what data they received? I’m somewhat shocked if that would be his position, so I’ll be watching this case.

 


Related:

  • PowerSchool commits to strengthened breach measures following engagement with the Privacy Commissioner of Canada
  • Hungarian police arrest suspect in cyberattacks on independent media
  • Two more entities have folded after ransomware attacks
  • British institutions to be banned from paying ransoms to Russian hackers
  • Data breach feared after cyberattack on AMEOS hospitals in Germany
  • Microsoft Releases Urgent Patch for SharePoint RCE Flaw Exploited in Ongoing Cyber Attacks
Category: Breach IncidentsBusiness SectorNon-U.S.Of Note

Post navigation

← MS: Fast Response by Singing River Health System May Have Averted Major PHI Hack
Major data breach at University of Windsor law school →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • BreachForums — the one that went offline in April — reappears with a new founder/owner
  • Fans React After NASCAR Confirms Ransomware Breach
  • Allianz Life says ‘majority’ of customers’ personal data stolen in cyberattack
  • Infinite Services notifying employees and patients of limited ransomware attack
  • The safe place for women to talk wasn’t so safe: hackers leak 13,000 user photos and IDs from the Tea app
  • Au: Qantas hackers gave airline 72-hour deadline
  • Honeywell vulnerability exposes building systems to cyber attacks
  • Recent public service announcements of note — parents should take special note of these
  • Au: Junior doctor faces fresh toilet spying charges as probe widens to other major hospitals
  • Average Brit hit by five data breaches since 2004

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Microsoft’s controversial Recall feature is now blocked by Brave and AdGuard
  • Trump Administration Issues AI Action Plan and Series of AI Executive Orders
  • Indonesia asked to reassess data privacy terms in new U.S. trade deal
  • Meta Denies Tracking Menstrual Data in Flo Health Privacy Trial
  • Wikipedia seeks to shield contributors from UK law targeting online anonymity
  • British government reportedlu set to back down on secret iCloud backdoor after US pressure
  • Idaho agrees not to prosecute doctors for out-of-state abortion referrals

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.