DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

Bombay High Court Orders Department of Telecommunications to Block Medusa Accounts After Generali Insurance Data Breach

Posted on October 22, 2025October 22, 2025 by Dissent

If the court continues issuing such injunctions, the Department of Telecommunications may need an entire department and staff just to respond to these situations. Should the responsibility be on the DoT, or is there a better way?

Azdhan reports:

The Bombay High Court has granted urgent ad-interim relief to Generali Central Life Insurance Company after the insurer reportedly suffered a ransomware attack by an anonymous hacker group identifying itself as “Medusa.” The Mumbai-based insurance firm is a joint venture between the Central Bank of India and the Generali Group, which is a global insurance and asset management group operating in over 50 countries.

Venkatesh Dhond, arguing on behalf of the insurance company, said the applicant was the victim of a cyberattack that compromised sensitive and confidential data, as mentioned in their submission to the court. He also said the applicant does not yet know the hacker’s identity, except that the global anonymous group calls itself “Medusa”. As a result, authorities identified the alleged hacker group as John Doe, a legal term used to refer to unknown individuals.

After hearing the case, Justice Arif S. Doctor ordered a temporary injunction restraining the unknown perpetrators and their associates from using, publishing, or disclosing any confidential data stolen from the plaintiff until the court delivers a final verdict. As part of this, he directed the Union of India and the Department of Telecommunications, listed as Defendants, to immediately remove, block, and disable all accounts, content, domain names, phone numbers, and email addresses linked to the stolen data of the insurance firm.

The court ordered the authorities to block or remove any accounts or content linked to the data breach or using the complainant’s name, likeness, or trademarks within 24 hours of receiving notice from the complainant insurance firm. It also directed the authorities to file an affidavit of compliance, an official statement confirming full adherence to the court’s orders.

Read more at Medianama.

From the above, it sounds like anyone reporting on the breach might find their accounts or content blocked or removed by authorities. That is more extreme than other injunctions we have seen in other cases, like the Qantas or Legal Aid Agency injunctions.

The specific language of the interim injunction, which is in effect until November 12, 2025, reads, in part:

a. Pending hearing and final disposal of this Suit, this Hon’ble Court be pleased to:

i. pass an order of temporarily injunction restraining Defendant No.3 and their directors, proprietors, operators, partners, employees, agents, servants and affiliates and any persons claiming through them from using, copying, publishing, distributing, transmitting, communicating or disclosing to any person the Confidential Data stolen by Defendant No.3 from the Plaintiff and any other information relating to the Plaintiff that is not available in the public domain by any medium whatsoever or on any platform whatsoever;
iv. pass an order directing Defendant Nos. 1 and 2 to take all steps necessary to: (1) forthwith remove, delete, block and disable accounts, content, domain names, and phone numbers and email addresses in relation to the Confidential Data stolen by Defendant No.3 from the Plaintiff, and (2) within 24 hours of intimation by the Plaintiff remove, delete, block and disable accounts, content, domain names, and phone numbers and email addresses associated with such accounts that may use, copy, publish, distribute, transmit, communicate or otherwise disclose any Confidential Data stolen by Defendant No.3 from the Plaintiff and/or any Confidential Data relating to the Plaintiff, and file an affidavit of compliance in that regard before this Hon’ble Court;
v. pass an order directing Defendant Nos. 1 and 2 to take all necessary steps to remove, delete, block and disable accounts, content, domain names, and phone numbers and email addresses associated with such accounts, that use the Plaintiff’s name, likeness or marks within 24 hours of intimation by the Plaintiff and file an affidavit of compliance in that regard before this Hon’ble Court;”

[Note: No subparts ii or iii appeared in the public document]

It is one thing to try to prohibit the publication of stolen data, but this injunction makes the Union of India and the Department of Telecommunications defendants in the order and requires THEM to do all the censorship/blocking/removal within 24 hours of being notified by Generali.

As with other injunctions this site has reported on previously, its authority is limited to its jurisdiction, or in this case, the defendants’ authority over domains, sites, and accounts. But Generali operates in many countries. Nothing in this injunction will prevent publication or distribution of data in those other countries.

The Medusa attack is reported in additional detail in the Medianama article. It appears to be a typical Medusa attack and attempt to extort its victims.  As of this publication, there are 3 days left on a countdown clock, and the leak site displays screenshots as proof of claims. There is also a directory and file tree already available. The latter, even without access to the files themselves, already reveals a lot in filenames and subject lines.

Will Injunctions Become Routine?

In securing the injunction, Generali’s attorneys pointed to a previous case as precedent. This may be the second injunction this court has ever issued, but will it become a trend or routine for entities to seek injunctions? Perhaps, but while it may be effective in their own area, it just may be another example of the Streisand Effect, and result in more people wanting to go look at the data, download it, publish it, or leak it elsewhere. This post is a case in point. DataBreaches would have had no awareness of, or interest in, reporting on the Generali incident but for spotting an article that a court had issued an injunction concerning it. 

 


Related:

  • Just days before its data might be leaked, Qantas Airways obtained a permanent injunction
  • Qantas obtains injunction to prevent hacked data’s release
  • Jefferson County judge issues injunction barring GoDaddy from hosting hacked law enforcement data
  • HCRG Care's lawyers claimed an injunction issued in a "private" hearing required us to remove two posts. We didn't comply.
  • Ie: MTU obtains temporary emergency injunction against BlackCat; Order prohibits anyone from leaking or publishing any confidential data
  • Waikato DHB wins injunction to stop Radio NZ using hacked data
Category: Commentaries and AnalysesHackNon-U.S.Of Note

Post navigation

← KT Chief to Resign After Cybersecurity Breach Resolution
Hotel and Casino near Las Vegas Strip suffers data breach, documents say →

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Defense Bill Would Require New Cyber Requirements for Some DoD Telecom Contracts
  • Tell the truth, or someone will tell it for you — Trumbull County, Ohio edition (1)
  • US Posts $10 Million Bounty for Iranian Hackers
  • South Korea police raid e-commerce giant Coupang over data leak; govt schedules hearing
  • FinCEN Report: Reported Ransomware Incidents and Payments Reached All-Time High in 2023
  • Leavenworth, Kansas cyberattack disrupts city services
  • They’ve escaped a lot of media attention, but Anubis RaaS is a threat to the medical sector (1)
  • “In the most expedient time possible…”
  • Portugal updates cybercrime law to exempt security researchers
  • LockBit 5’s “new secure blog domain” infra leaked already

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • FTC Denies Petition from SpyFone App CEO to Vacate 2021 Order
  • Privacy concerns raised as Grok AI found to be a stalker’s best friend
  • PRIVACY—S.D. Cal.: Employee did not waive privacy right in personal email data on company provided laptop, (Dec 5, 2025)
  • EU justice chief draws red line on privacy reforms
  • Kaiser Permanente to Pay Up to $47.5M in Web Tracker Lawsuit

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net
Security Issue: security[at]databreaches.net
Mastodon: Infosec.Exchange/@PogoWasRight
Signal: Dissent.73
DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.