https://www.polity.org.za
Deepening Democracy through Access to Information
Home / Legal Briefs / All Legal Briefs RSS ← Back
Edward Nathan Sonnenberg|PSG Wealth Financial Planning|SchoemanLaw|Canada|South Africa|United Kingdom|Business Email Compromise|Cybercrimes Act|Cybersecurity|Delict|Protection Of Personal Information Act|Kerri Stewart
|||
edward-nathan-sonnenberg|psg-wealth-financial-planning|schoemanlaw|canada|south-africa|united-kingdom|business-email-compromise|cybercrimes-act|cybersecurity|delict|protection-of-personal-information-act|kerri-stewart
Close

Email this article

separate emails by commas, maximum limit of 4 addresses

Sponsored by

Close

Article Enquiry

Liability in cyberspace: Business email compromise and the limits of legal duty


Close

Liability in cyberspace: Business email compromise and the limits of legal duty

Should you have feedback on this article, please complete the fields below.

Please indicate if your feedback is in the form of a letter to the editor that you wish to have published. If so, please be aware that we require that you keep your feedback to below 300 words and we will consider its publication online or in Creamer Media’s print publications, at Creamer Media’s discretion.

We also welcome factual corrections and tip-offs and will protect the identity of our sources, please indicate if this is your wish in your feedback below.


Close

Embed Video

Liability in cyberspace: Business email compromise and the limits of legal duty

SchoemanLaw

25th August 2026

ARTICLE ENQUIRY      SAVE THIS ARTICLE      EMAIL THIS ARTICLE

Font size: -+

Few risks have transitioned as decisively from the technical domain into the legal sphere as business email compromise (“BEC”). Its mechanics are deceptively simple: a third party gains access to an email account, monitors correspondence, and at an opportune moment substitutes fraudulent banking details for those of the intended recipient. The sophistication lies not in the technology employed, but in the timing and precision of the intervention. 

The legal difficulty does not lie in identifying wrongdoing, but in allocating loss. In most instances, the perpetrator is beyond reach, leaving two innocent parties to contend with the consequences. South African law has now provided a clear, though carefully circumscribed, answer to that problem, grounded not in a novel doctrine of cyber liability, but in established principles of delict. 

Advertisement

Pure Economic Loss and the Problem of Omission 

A defining feature of BEC claims is that the loss suffered is purely patrimonial. There is no damage to person or property; the harm arises from a misdirected payment. Equally significant is that liability is typically premised on an omission: a failure to warn, to verify, or to implement protective measures. 

Advertisement

South African law approaches such claims with caution. It is well established that an omission causing pure economic loss is not prima facie wrongful. Wrongfulness must be positively established, with reference to considerations of legal and public policy. The courts have consistently resisted extending delictual liability in circumstances where doing so would impose indeterminate or disproportionate burdens. 

Edward Nathan Sonnenberg Inc v Hawarden: The Leading Authority 

The leading authority on BEC in South African law is Edward Nathan Sonnenberg Inc v Hawarden 2024 (5) SA 9 (SCA). The matter arose from a property transaction in which Ms Hawarden, having received ENS’s banking details via email, ultimately paid R5.5 million into an account controlled by a fraudster after her own email account had been compromised. 

Having made a second payment to complete the transaction, she instituted a delictual claim against ENS, contending that it owed her a legal duty to warn her of the risk of BEC. The High Court upheld the claim. On appeal, however, the Supreme Court of Appeal overturned that decision. 

The SCA confined its enquiry to wrongfulness. It emphasised that there was no contractual relationship between the parties, that the compromise occurred within the plaintiff’s own email system, and that she had previously been warned of the risk. Despite engaging with ENS employees prior to payment, she did not verify the banking details or seek confirmation from her bank. 

In rejecting the imposition of a legal duty, the Court held that to require creditors generally to protect debtors against the risk of intercepted communications would be untenable. Such a finding would effectively render every creditor responsible for the integrity of its counterparty’s email environment. 

Central to the Court’s reasoning was the principle that the plaintiff had the means to protect herself against a known risk, yet failed to do so. In those circumstances, the law would not shift the loss. The appeal was accordingly upheld, and the claim dismissed with costs. 

Notably, the Court also observed that, on the facts, any warning by ENS would likely have been ineffective, as the compromise had already occurred within the plaintiff’s mailbox. 

Vulnerability to Risk as the Organising Principle 

The judgment in Hawarden reflects a broader doctrinal theme: vulnerability to risk. Where a party has taken, or could reasonably have taken, steps to protect itself, that factor weighs heavily against a finding of wrongfulness. 

This enquiry is distinct from an assessment of reasonableness or fault. It does not ask whether the defendant acted commendably, but whether the law should impose liability at all. A party who is capable of self-protection is not considered legally vulnerable, and the loss will ordinarily remain where it falls. 

Where Liability Does Arise 

The position alters materially where a contractual relationship exists. In such cases, liability is determined primarily by the terms of the agreement and the parties’ respective obligations. 

In Gerber v PSG Wealth Financial Planning (Pty) Ltd [2023]ZAGPJHC 270, the defendant acted on fraudulent instructions purporting to originate from its client, resulting in the misdirection of investment proceeds. The High Court held the defendant contractually liable, emphasising its failure to adhere to its own verification procedures. 

The decisive consideration was not the occurrence of fraud, but the breach of agreed safeguards. The case illustrates that, within a contractual framework, liability is less concerned with abstract notions of wrongfulness and more with whether the party discharged its obligations. 

A similar approach is evident in comparative jurisdictions. In Sell Your Car With Us Ltd v Sareen [2019] EWHC 2332 (Ch), the English High Court declined to imply a duty on the seller to secure his email account, instead placing the loss on the paying party, which had failed to follow its own internal checks.  

Likewise, Canadian courts have generally been reluctant to shift loss absent contractual allocation or demonstrable fault on the part of the recipient. 

Across these authorities, three principles emerge with consistency: 

  • First, contract governs. Where a relationship exists, the enquiry centres on the parties’ agreed procedures and whether they were followed. 
  • Secondly, delict operates as a narrow residual remedy. Claims based on omission and pure economic loss face significant doctrinal constraints. 
  • Thirdly, self-protection is decisive. The party best positioned to prevent the loss will ordinarily bear it. 

The Statutory Overlay 

The absence of delictual liability does not imply regulatory compliance. Organisations processing personal information remain subject to the Protection of Personal Information Act 4 of 2013 (“POPIA”), which requires the implementation of appropriate, reasonable technical and organisational measures to safeguard data. 

The Cybercrimes Act 19 of 2020 introduces an additional layer, criminalising the underlying conduct and imposing reporting obligations in defined circumstances. 

These statutory duties operate independently of delictual principles. A finding that conduct is not wrongful for the purposes of a damages claim does not equate to compliance with information security obligations. 

Practical and Strategic Considerations 

In practice, the response to BEC risk is primarily procedural rather than litigious. The most effective safeguards are those embedded in contractual arrangements and operational processes. 

Parties should ensure that agreements expressly regulate the verification of banking details and allocate the risk of unverified electronic payment instructions. A standing rule that banking details will not be amended on the strength of email communications alone remains a critical control measure, ideally supplemented by telephonic verification using known contact details. 

Internally, dual authorisation for changes to beneficiary information and the use of secure communication platforms materially reduce exposure. From a risk management perspective, insurance cover should be carefully reviewed to ensure that it responds to scenarios involving authorised payments made under fraudulent instruction. 

Finally, the speed of response remains crucial. Immediate notification to the receiving bank and law enforcement significantly improves the prospects of recovery, which diminish rapidly with time. 

Conclusion 

Liability for business email compromise in South African law reflects the application of established principles rather than the development of a new legal framework. The courts have declined to impose a general duty on creditors to safeguard their counterparties against cyber risk, instead locating responsibility with the party best positioned to prevent the loss. 

This allocation does not diminish the importance of robust cybersecurity or regulatory compliance. Rather, it underscores the central role of contractual clarity and procedural discipline. In the context of BEC, as in commercial relationships more broadly, the outcome is determined less by the occurrence of the fraud than by the measures adopted in anticipation of it. 

Written by Kerri Stewart, Attorney, SchoemanLaw Inc  

 

EMAIL THIS ARTICLE      SAVE THIS ARTICLE      ARTICLE ENQUIRY      FEEDBACK

To subscribe email subscriptions@creamermedia.co.za or click here
To advertise email advertising@creamermedia.co.za or click here


About

Polity.org.za is a product of Creamer Media.
www.creamermedia.co.za

Other Creamer Media Products include:
Engineering News
Mining Weekly
Research Channel Africa

Read more

Subscriptions

We offer a variety of subscriptions to our Magazine, Website, PDF Reports and our photo library.

Subscriptions are available via the Creamer Media Store.

View store

Advertise

Advertising on Polity.org.za is an effective way to build and consolidate a company's profile among clients and prospective clients. Email advertising@creamermedia.co.za

View options

Email Registration Success

Thank you, you have successfully subscribed to one or more of Creamer Media’s email newsletters. You should start receiving the email newsletters in due course.

Our email newsletters may land in your junk or spam folder. To prevent this, kindly add newsletters@creamermedia.co.za to your address book or safe sender list. If you experience any issues with the receipt of our email newsletters, please email subscriptions@creamermedia.co.za