Bombay HC Restrains Hacker Group from Leaking School Children's Sensitive Data Under DPDPA 2023

The Bombay High Court, in an ex parte ad-interim order dated June 12, 2026, restrained the hacker group FulcrumSec from publishing, leaking, or disclosing sensitive personal data of school children. Justice Arif S Doctor, hearing Suit (L) No. 19692 of 2026 filed by Pratiksha Foundation Charitable Trust (referred to as XYZ Charitable Trust in anonymised filings), directed Google and other intermediaries to block the email identifiers used by the hackers. The case raises critical questions at the intersection of the Digital Personal Data Protection Act (DPDPA) 2023, the Information Technology Act 2000, and the Bharatiya Nyaya Sanhita (BNS) 2023.
Facts of the Case
FulcrumSec allegedly breached the systems of multiple schools in Mumbai and abroad, gaining access to highly sensitive records of thousands of children. The stolen data included medical records, mental health assessments, daily movement logs, and parents' financial and occupational details. The group demanded a ransom of USD 750,000, threatening to publish the data if the demand was not met.
On June 10, 2026, the hackers escalated their threats by sending an email to a parent that disclosed confidential information about the mental health of children enrolled in one of the affected schools. This direct disclosure to third parties prompted the Trust to seek urgent judicial intervention.
The Court's Order
Justice Arif Doctor granted the ex parte ad-interim injunction on the basis that disclosing children's sensitive personal data would cause irreparable harm that could not be compensated by damages. The Court restrained FulcrumSec and any person acting on its behalf from publishing, leaking, selling, or otherwise disclosing the data. Google was directed to block the email IDs used by the hackers to communicate their threats. The next hearing is scheduled for July 1, 2026.
Children's Data Under Section 9 of the DPDPA 2023
The DPDPA 2023 creates a distinct and heightened protection regime for children's personal data. Section 9(1) mandates that before processing any personal data of a child (defined under Section 2(f) as any individual who has not completed 18 years), a Data Fiduciary must obtain verifiable consent from the child's parent or lawful guardian. Section 9(2) prohibits any processing that is likely to cause a detrimental effect on the well-being of a child. Section 9(3) goes further by prohibiting tracking, behavioural monitoring, or targeted advertising directed at children.
For a detailed analysis of data fiduciary obligations under the DPDPA: DPDPA 2023: Complete Guide to Data Fiduciary Obligations in India.
IT Act 2000 Provisions at Issue
Section 43A of the IT Act 2000 imposes liability on any body corporate that possesses, deals with, or handles sensitive personal data or information in a computer resource, and is negligent in implementing and maintaining reasonable security practices. The section provides for compensation to persons who suffer wrongful loss or wrongful gain as a result of such negligence.
Section 72A of the IT Act punishes any person who, while providing services under a lawful contract, has secured access to personal information about another person and discloses that information without consent or in breach of the contract. The punishment is imprisonment for up to three years, or a fine of up to Rs 5 lakh, or both. This provision is directly relevant where the hackers may have initially gained access through exploiting service-provider relationships.
For a comprehensive treatment of cyber crime offences and remedies under the IT Act: Cyber Crime Offences Under IT Act 2000: Sections, Penalties, and Legal Remedies.
Criminal Liability Under the BNS 2023
The hackers' conduct also attracts criminal liability under the Bharatiya Nyaya Sanhita 2023. Section 308 BNS (replacing Section 384 IPC on extortion) applies where a person intentionally puts any person in fear of any injury and thereby dishonestly induces the person to deliver property or valuable security. Section 351 BNS (replacing Sections 503 and 506 IPC on criminal intimidation) covers threats made through any communication, including electronic communication, with punishment extending to seven years where the threat is of death or grievous hurt. Additionally, Section 66C of the IT Act addresses identity theft, carrying imprisonment of up to three years and a fine of up to Rs 1 lakh.
For an overview of the key changes introduced by the new criminal code: Bharatiya Nyaya Sanhita 2023: Key Changes from IPC Every Citizen Must Know.
Significance of the Order
This order is significant for several reasons. First, it is among the earliest judicial orders that directly confronts a ransomware-style data extortion attempt targeting children's data in India. Second, the Court's direction to Google to block the hackers' email identifiers represents a proactive approach to cutting off the channels of further harm, going beyond merely restraining the respondents. Third, the case highlights the real-world consequences of data breaches involving children's records: mental health information, daily movement data, and medical records are exactly the type of sensitive data that the DPDPA was designed to protect with heightened safeguards.
For a broader perspective on data protection compliance under the DPDP Rules 2025: DPDP Rules 2025: What Indian Businesses Must Do Before the Compliance Deadlines.
Related Reading
This article is for general informational purposes only and does not constitute legal advice. For advice specific to your situation, consult a qualified advocate.

Comments