Generali Central life Insurance with Bombay High Court 
Litigation News

Bombay High Court restrains hacker group from leaking data stolen from insurer Generali Central

Generali told the Court that the insurer’s confidential and customer data had been hacked and that the unknown perpetrator had demanded USD 500,000 in ransom.

S N Thyagarajan

The Bombay High Court has granted urgent ad-interim relief to Generali Central Life Insurance Company Limited after it was hit by a ransomware attack, allegedly carried out by a hacker group identifying itself as “Medusa" [Generali Central Life Insurance Company Limited Vs Union of India].

Justice Arif S Doctor on October 16, directed the Union of India through the Department of Telecommunications (DoT) and other authorities to immediately block and disable all accounts, domain names, and communication channels associated with the breach.

The gravity of the consequences that may follow if the applicant’s confidential data is made public or traded is overwhelming. The balance of convenience is clearly in favour of the applicant for the grant of ad-interim relief,” the Court said

Justice Arif Doctor

Generali told the Court that the insurer’s confidential and customer data had been hacked and that the unknown perpetrator had demanded $500,000 in ransom. The threat was posted on X (formerly Twitter), warning that the data would be made available “to anyone willing to pay” unless the demand was met.

A screenshot produced before the Court displayed three ransom options:
(a) Add time 1 day – $10,000;
(b) Delete all data – $500,000; and
(c) Download all data – $500,000

Since the identity of the hacker was unknown, Generali impleaded the alleged attacker as John Doe. The company sought immediate injunctions restraining the entity from publishing, distributing, or selling any of its stolen confidential data.

The Court restrained the hacker group going by Medusa (defendant 3) and all persons acting on its behalf from using, copying, transmitting, or disclosing Generali’s confidential information “by any medium or on any platform whatsoever.”

It further directed the Union Department of Telecommunications and related authorities to:

1. Remove, delete, block, and disable any accounts, domain names, phone numbers, or email addresses linked to the stolen data;

2. Act within 24 hours of intimation from Generali of any further such stolen data to disable any such new content or accounts misusing its confidential information or likeness; and

3. File an affidavit of compliance before the Court confirming the steps taken to comply with these directives.

Generali relied on an earlier Bombay High Court order in HDFC Life Insurance Co. Ltd. v. Meta Platforms Inc., where similar reliefs were granted to restrain an unknown hacker from misusing confidential corporate information following a cyber-attack.

Generali was represented by Senior Advocate Venkatesh Dhond with Advocates Vishal Kanade, Aruna Roy, Devashish Godbole, and Prasad Nagargoje.

Senior Advocate Venkatesh Dhond

Advocate Ashish Mehta (instructed by Ethos Legal Alliance) appeared for the Union of India and DoT.

[Read Order]

Generali Life Insurance Vs Union of India.pdf
Preview

AP High Court seeks Centre's response on plea challenging BNSS provision allowing handcuffing of accused

Punjab & Haryana High Court confers Senior designation on 76 advocates

NCLT Ahmedabad admits BluSmart subsidiary to CIRP over unpaid Google Maps services

Karnataka High Court seeks State’s response to plea challenging Udupi Civil Court shift to Brahmavar

Bombay High Court imposes ₹50 lakh costs on litigant for suppressing facts to obtain injunction

SCROLL FOR NEXT