21 August 2026 7 min

Liability in Cyberspace - Business Email Compromise and the Limits of Legal Duty

Written by: Kerri Stewart, SchoemanLaw Inc. Save to Instapaper
Liability in Cyberspace -  Business Email Compromise and the Limits of Legal Duty

Few risks have transitioned as decisively from the technical domain into the legal sphere as business email compromise (“BEC”). Its mechanics are deceptively simple: a third party gains access to an email account, monitors correspondence, and at an opportune moment substitutes fraudulent banking details for those of the intended recipient. The sophistication lies not in the technology employed, but in the timing and precision of the intervention.

The legal difficulty does not lie in identifying wrongdoing, but in allocating loss. In most instances, the perpetrator is beyond reach, leaving two innocent parties to contend with the consequences. South African law has now provided a clear, though carefully circumscribed, answer to that problem, grounded not in a novel doctrine of cyber liability, but in established principles of delict.

Pure Economic Loss and the Problem of Omission

A defining feature of BEC claims is that the loss suffered is purely patrimonial. There is no damage to person or property; the harm arises from a misdirected payment. Equally significant is that liability is typically premised on an omission: a failure to warn, to verify, or to implement protective measures.

South African law approaches such claims with caution. It is well established that an omission causing pure economic loss is not prima facie wrongful. Wrongfulness must be positively established, with reference to considerations of legal and public policy. The courts have consistently resisted extending delictual liability in circumstances where doing so would impose indeterminate or disproportionate burdens.

Edward Nathan Sonnenberg Inc v Hawarden: The Leading Authority

The leading authority on BEC in South African law is Edward Nathan Sonnenberg Inc v Hawarden 2024 (5) SA 9 (SCA). The matter arose from a property transaction in which Ms Hawarden, having received ENS’s banking details via email, ultimately paid R5.5 million into an account controlled by a fraudster after her own email account had been compromised.

Having made a second payment to complete the transaction, she instituted a delictual claim against ENS, contending that it owed her a legal duty to warn her of the risk of BEC. The High Court upheld the claim. On appeal, however, the Supreme Court of Appeal overturned that decision.

The SCA confined its enquiry to wrongfulness. It emphasised that there was no contractual relationship between the parties, that the compromise occurred within the plaintiff’s own email system, and that she had previously been warned of the risk. Despite engaging with ENS employees prior to payment, she did not verify the banking details or seek confirmation from her bank.

In rejecting the imposition of a legal duty, the Court held that to require creditors generally to protect debtors against the risk of intercepted communications would be untenable. Such a finding would effectively render every creditor responsible for the integrity of its counterparty’s email environment.

Central to the Court’s reasoning was the principle that the plaintiff had the means to protect herself against a known risk, yet failed to do so. In those circumstances, the law would not shift the loss. The appeal was accordingly upheld, and the claim dismissed with costs.

Notably, the Court also observed that, on the facts, any warning by ENS would likely have been ineffective, as the compromise had already occurred within the plaintiff’s mailbox.

Vulnerability to Risk as the Organising Principle

The judgment in Hawarden reflects a broader doctrinal theme: vulnerability to risk. Where a party has taken, or could reasonably have taken, steps to protect itself, that factor weighs heavily against a finding of wrongfulness.

This enquiry is distinct from an assessment of reasonableness or fault. It does not ask whether the defendant acted commendably, but whether the law should impose liability at all. A party who is capable of self-protection is not considered legally vulnerable, and the loss will ordinarily remain where it falls.

Where Liability Does Arise

The position alters materially where a contractual relationship exists. In such cases, liability is determined primarily by the terms of the agreement and the parties’ respective obligations.

In Gerber v PSG Wealth Financial Planning (Pty) Ltd [2023] ZAGPJHC 270, the defendant acted on fraudulent instructions purporting to originate from its client, resulting in the misdirection of investment proceeds. The High Court held the defendant contractually liable, emphasising its failure to adhere to its own verification procedures.

The decisive consideration was not the occurrence of fraud, but the breach of agreed safeguards. The case illustrates that, within a contractual framework, liability is less concerned with abstract notions of wrongfulness and more with whether the party discharged its obligations.

A similar approach is evident in comparative jurisdictions. In Sell Your Car With Us Ltd v Sareen [2019] EWHC 2332 (Ch), the English High Court declined to imply a duty on the seller to secure his email account, instead placing the loss on the paying party, which had failed to follow its own internal checks.

Likewise, Canadian courts have generally been reluctant to shift loss absent contractual allocation or demonstrable fault on the part of the recipient.

Across these authorities, three principles emerge with consistency:

First, contract governs. Where a relationship exists, the enquiry centres on the parties’ agreed procedures and whether they were followed.

Secondly, delict operates as a narrow residual remedy. Claims based on omission and pure economic loss face significant doctrinal constraints.

Thirdly, self-protection is decisive. The party best positioned to prevent the loss will ordinarily bear it.

The Statutory Overlay

The absence of delictual liability does not imply regulatory compliance. Organisations processing personal information remain subject to the Protection of Personal Information Act 4 of 2013 (“POPIA”), which requires the implementation of appropriate, reasonable technical and organisational measures to safeguard data.

The Cybercrimes Act 19 of 2020 introduces an additional layer, criminalising the underlying conduct and imposing reporting obligations in defined circumstances.

These statutory duties operate independently of delictual principles. A finding that conduct is not wrongful for the purposes of a damages claim does not equate to compliance with information security obligations.

Practical and Strategic Considerations

In practice, the response to BEC risk is primarily procedural rather than litigious. The most effective safeguards are those embedded in contractual arrangements and operational processes.

Parties should ensure that agreements expressly regulate the verification of banking details and allocate the risk of unverified electronic payment instructions. A standing rule that banking details will not be amended on the strength of email communications alone remains a critical control measure, ideally supplemented by telephonic verification using known contact details.

Internally, dual authorisation for changes to beneficiary information and the use of secure communication platforms materially reduce exposure. From a risk management perspective, insurance cover should be carefully reviewed to ensure that it responds to scenarios involving authorised payments made under fraudulent instruction.

Finally, the speed of response remains crucial. Immediate notification to the receiving bank and law enforcement significantly improves the prospects of recovery, which diminish rapidly with time.

Conclusion

Liability for business email compromise in South African law reflects the application of established principles rather than the development of a new legal framework. The courts have declined to impose a general duty on creditors to safeguard their counterparties against cyber risk, instead locating responsibility with the party best positioned to prevent the loss.

This allocation does not diminish the importance of robust cybersecurity or regulatory compliance. Rather, it underscores the central role of contractual clarity and procedural discipline. In the context of BEC, as in commercial relationships more broadly, the outcome is determined less by the occurrence of the fraud than by the measures adopted in anticipation of it.

Contact an expert at SchoemanLaw Inc in Cape Town or Paarl for assistance with your legal needs.

https://schoemanlaw.co.za/services/litigation-and-dispute-resolution/

Kerri Stewart | SchoemanLaw Inc

Attorney

Total Words: 1276

Submitted on behalf of

Press Release Submitted By

  • Agency/PR Company: SchoemanLaw Inc.
  • Contact person: Kerri Stewart
  • Contact #: 021 4255604
  • Website
  • LinkedIn

SchoemanLaw Inc

344 Press Release Articles

SchoemanLaw Inc Attorneys, Conveyancers and Notaries Public is a boutique law firm offering its clients access to high quality online legal documents and agreements, together with a wide range of legal services. The firm has an innovative and entrepreneurial mindset that distinguishes it from other law firms. We apply our first-hand understanding of the challenges facing entrepreneurs... Read More