HWL Ebsworth, a prominent Australian law firm, suffered a ransomware attack by the ALPHV (BlackCat) group, resulting in the exfiltration of sensitive client data. In response, the firm obtained a court injunction intended to prevent the hackers from publishing or sharing the stolen data, as well as to restrict its dissemination by third parties, including journalists and security researchers. Despite being served with the injunction, the threat actors openly mocked the legal action and proceeded to release a substantial amount of the compromised data online, demonstrating the limited practical effect of such legal measures on criminal actors. The injunction, however, provided a legal basis for HWL Ebsworth to request that online platforms refrain from hosting or distributing the stolen data, potentially limiting its spread among legitimate entities. This case highlights the challenges organizations face in controlling the aftermath of a data breach, especially when dealing with transnational cybercriminals who are unlikely to respect legal orders. The incident also raises concerns about the balance between protecting sensitive information and the ability of journalists and security professionals to analyze and report on breaches for the public good. Meanwhile, law enforcement agencies continue to target cybercrime infrastructure, as evidenced by the recent seizure of BreachForums, a notorious platform for trading stolen data. The seizure was carried out by a coalition of U.S. and French authorities, including the Department of Justice, FBI, BL2C, and JUNALCO, and resulted in the takedown of both the clear net and onion versions of the forum. At the time of the seizure, the group ScatteredLAPSUS$Hunters was threatening to leak data from 39 Salesforce customers unless a ransom was paid, with high-profile companies such as Qantas, Air France & KLM, Disney/Hulu, UPS, FedEx, Home Depot, Gucci, and Toyota Motors among the potential victims. The law enforcement action included changing the name servers of the forum's domains to those controlled by the FBI, effectively cutting off access to the site and its backup domains. Despite these efforts, some elements of the criminal infrastructure, such as alternative onion sites, remained operational, illustrating the resilience and adaptability of cybercriminal networks. The seizure of BreachForums was met with mixed reactions in underground communities, with some users expressing defeat and others urging continued resistance. These events underscore the ongoing cat-and-mouse dynamic between cybercriminals and law enforcement, as well as the limitations of both legal and technical interventions in fully mitigating the risks and impacts of major data breaches. Organizations targeted by ransomware and data theft must navigate a complex landscape of legal, technical, and reputational challenges in their response efforts. The effectiveness of court injunctions and law enforcement takedowns is often constrained by the global and decentralized nature of cybercrime. Both incidents demonstrate the need for comprehensive, multi-layered strategies to address the evolving threat landscape and protect sensitive data from exposure and misuse.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
A published analysis argued that court injunctions are an ineffective response to data breaches, characterizing them as largely symbolic rather than materially helpful. The supplied content does not tie this commentary to a separate dated operational event.
References indicate that BreachForums was seized again, marking a renewed law-enforcement or infrastructure takedown action against the cybercrime forum. No additional dated details are provided in the supplied content beyond the reporting date.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.