H v ENS Inc
In context of BEC (business email compromise) when should the law recognise a legal duty of care when invoices are sent for payment?
[131] The interests of the defendant as well as the society demand that a legal duty is recognised in this case. ENS is best placed to understand and prevent BEC (business email compromise). Individuals in society are generally not as well-placed to respond to the ever-evolving threat of cyber-crime, which is sophisticated and technical in nature. . . . All facts considered, accordingly, I am persuaded that considerations of legal and public policy require liability in this case. . . . “
Essence
Business email compromise considered in detail and HC decided conveyancing attorney liable for wrongful and negligent conduct relating to payment.
Decision
(13849/2020) [2023] ZAGPJHC 14 (16 January 2023)
Order:
Allowed claim for payment of capital amount, interest, expert’s fees and expenses and punitive costs.
Judges
AR Mudau J
Date of Hearing (Virtually): 18,19,20,21 and 22 October 2021.
1, 2, 3, 4, 7 and 8 March 2022 as well as 27 September 2022.
Date of Judgment: 16 January 2023.
Related books
Darcy du Toit et al: Labour Relations Law: A Comprehensive Guide 6ed 925 pages (LexisNexis 2015) at
Darcy du Toit et al: Labour Law Through The Cases – loose-leaf service updated 6 monthly (LexisNexis 2022)
Van Niekerk and Smit (Managing editors) et al: Law@Work 5ed (LexisNexis 2019) at
Garbers: The New Essential Labour Law Handbook 7ed (MACE 2019) at
Collier et al: Labour Law in South Africa: Context and Principles 1ed 5th imp 631 pages (OUP 2021) at
CG van der Merwe : Sectional Titles, Share Blocks and Time-sharing (LexisNexis regular service issues 2022) at
Overview
“[130] ENS was at fault on the basis of negligent conduct. I am not inclined to agree with submissions made by counsel on behalf of ENS that Ms H must take responsibility for her failure to protect herself against the known risk of relying on banking details received by email.
The defendant was an expert conveyancer and was facilitating and managing the transaction. Under these overall circumstances it not overly burdensome or unreasonable to impose liability on ENS. The risk of loss to Mrs H was highly foreseeable by ENS.
There is no risk of boundless liability as feared by ENS as the loss in this case is claimed by a single plaintiff and is finite in its extent. It is, accordingly, not unlimited or indeterminate.”
Judgment
Note: Footnotes omitted, emphasis added and certain personal details redacted to comply with law.
[1] The current action proceedings were launched during June 2020. The plaintiff, Ms JH (“Ms H”) issued summons against the defendant, Edward Nathan Sonnenbergs Incorporated (“ENS”), a firm of attorneys which practices as attorneys and conveyancers, for damages in the sum of R 5.5 million plus interest at the applicable prescribed rate per annum to date of payment. The matter served before me in terms of paragraph 8 of Chapter 2 of the Commercial Court Practice Directive.
[2] The matter has its origin in emails and attachments thereto that were received by the plaintiff on 21 August 2019, which were part and parcel of a type of fraud, which has become known as unlawful “business email compromise” “(BEC”) perpetrated by an unknown cybercriminal. The chain of events set in motion by the transmission and receipt of the said emails led plaintiff to transfer the amount of R5.5million – being the outstanding amount due in respect of her purchase of an immovable residential property – into a fraudulent account, which she thought was the bank account of the defendant (“the ENS account”).
[3] The plaintiff’s claim against ENS is delictual in nature. It is one for pure economic loss caused by omission. The pleadings consist of amended particulars of claim and an amended plea, together with requests for trial particulars and replies thereto, with the plaintiff alleging in the amended particulars of claim that ENS owed her a duty of care and that as a consequence of the breach of such duty she suffered damages in the amount of R5.5 million.
[4] Plaintiff pleaded further, alleging that in the course of its dealings with Plaintiff ENS owed Plaintiff a legal duty (“the legal duty”), inter alia,
-
- in the relevant communications (whether by letter, email or telephone), to warn Plaintiff of the danger of BEC and the increase in the prevalence of the BEC type of fraud in particular;
- to warn Plaintiff, before making any payment to ENS to ensure that she verified that the account into which payment will be made is a legitimate bank account of ENS; and
- to implement adequate security measures such as password protection of emails and/or attachments thereto or loading the ENS Trust Account as a public beneficiary in the FNB and Standard Bank online banking systems so that the bank account number does not require transmission by the medium of an unprotected and unsafe form of communication.
ENS denies that its conduct was wrongful, negligent or caused the loss. The defendant denies, inter alia, that in a phone conversation, the plaintiff was advised or told that the outstanding amount could be transferred directly to the defendant.
Instead, the defendant pleads that ENS’ M simply undertook to send the defendant’s trust account details “in case the plaintiff chose to transfer the balance of the purchase price to ENS”.
[5] ENS has pleaded, in the alternative, that the plaintiff was contributorily negligent.
To wit, inter alia,
-
- that the plaintiff failed to exercise reasonable care to ensure that it was safe to pay the balance of the purchase price by electronic transfer;
- failed to exercise reasonable care to ensure that the number of the account to which she transferred the balance of the purchase price was correct; and
- that she failed to ask Ms M, Mr C (of the defendant) or her own bank whether it was safe to pay the balance of the purchase price to the account number received by email.
The issue for determination is whether ENS should be held delictually liable for Ms H’s loss.
Factual Background
. . . .
The plaintiff’s second expert witness – Mark Heyink
[51] Mr Mark Heyink (“Heyink”), the plaintiff’s second expert witness, is an attorney and an expert in information and communications technology law, data protection law, and information security practices, with a particular focus on organisational security safeguards necessary for information governance, management, and security. Mr Heyink’s evidence included a description of information security generally, technical and organisational measures to protect information security, and information management systems and governance.
[52] Heyink testified that the risk of business email compromise had been publicised in various advisories and publications for many years, including articles that he wrote, and that it was a well-known risk. On his version, technological safeguards are of little value if the people who use the technology are not sufficiently aware of the risks and of how to mitigate them. In this instance, the defendant’s employees were not adequately trained or aware of the risks of BEC.
[53] Since 2018, Heyink authored several articles on behalf of the Law Society of South Africa attempting to create awareness among attorneys on the issue. These articles dealt with the risks of BEC and precautions to be taken.
Heyink observed that the defendant’s witness statements revealed inadequate awareness among the defendant’s staff of BEC. Heyink was referred to the defendant’s ‘Acceptable Use Policy’ that was in place in 2019, and in particular, the sections relating to email and instant messaging usage. Paragraph 10.5 stated:
“No transmission is totally secure and therefore confidential/sensitive information must be password protected. The password must be sent in a separate communication.”
He explained that the provision recognised that electronic communications were not secure and it recognised a mechanism of trying to provide security, but which had not been complied with in the present matter.
[54] During cross-examination, the fact that in November 2018, Heyink had sent his bank account details to Mr Aslam Moosajee of the defendant by way of an unprotected/unencrypted MS Word attachment was taken up with him, which he conceded.
He also conceded that “most attorneys send their invoices to their clients by way of pdf attachments to ordinary emails”.
Also that his evidence reflects what he thinks ought to be done and not what actually happens in the market.
. . . .
Discussion
[102] Ms H contends that ENS’s conduct was wrongful in its omissions or failure to warn or advise her in regard to the risks of BEC. She contends that ENS was well-aware of this type of fraud before the fraud in this case took place, which is apparent from the warnings contained in the defendant’s investment mandate sent to the plaintiff after the payment took place but before the discovery of the fraud.
She also contends that a finding in her favour would only impose such a duty on conveyancers and attorneys, who already owe a duty to third party purchasers on the authority of Bruwer v Pocock & Bailey Ingelyf and to the public when dealing with trust funds based on the SCA decision of Du Preez and Others v Zwiegers .
The evidence in this case shows that BEC attacks are rife, especially in the conveyancing industry. The parties’ experts agreed that BEC has been around for many years, particularly in the context of the conveyancing industry , and that the risk of BEC was well-known before 2019.
[103] In Bruwer , the court held that, because the attorney held the depositor’s money in trust, it owed him a duty to exercise care in the way it disposed of the money.
In Du Preez , the plaintiff made an unsolicited deposit in an attorney’s trust account. The SCA held that the attorney owed the depositor a duty to exercise reasonable care in dealing with his money and put it thus:
“I find it difficult to see what possible scope there is for the contention that there was no legal duty in this situation. An attorney is under a legal duty to deal with trust account money in such a way that loss is not negligently caused, inter alia, to the depositor.”
[104] It is however, also trite, as ENS contends, that our common law does not generally render people liable in delict for the loss they cause others by omission, that is, by their failure to prevent the loss.
In support hereof, reference was made to Professors Neethling, Potgieter and Visser who put it as follows:
“As a general rule, a person does not act wrongfully for the purposes of the law of delict if he omits to prevent harm to another person. Thus, the point of departure is that a person is generally not liable where his omission or omissio — his failure to act positively to prevent loss — factually infringes the interests of others. Omissions are therefore prima facie lawful” .
[105] In Hawekwa Youth Camp v Byrne , the Supreme Court of Appeal reminds us that:
“The principles regarding wrongful omissions have been formulated by this court on a number of occasions in the recent past. These principles proceed from the premise that negligent conduct that manifests itself in the form of a positive act causing physical harm to the property or person of another is prima facia wrongful. By contrast, negligent conduct in the form of an omission is not regarded as prima facie wrongful. Its wrongfulness depends on the existence of a legal duty.
The imposition of this legal duty is a matter for judicial determination, involving criteria of public and legal policy consistent with constitutional norms. In the result, a negligent omission causing loss will only be regarded as wrongful and therefore actionable if public or legal policy considerations require that such omission, if negligent, should attract legal liability for the resulting damages”.
[106] To determine wrongfulness in a case such as this one, which falls into both categories of exception because the plaintiff claims pure economic loss caused by omission, the trite approach as advocated by the SCA in Minister of Safety and Security v Van Duivenboden at para 21, since endorsed by the Constitutional Court in Country Cloud Trading v MEC, Department of Infrastructure Development being that,
“When determining whether the law should recognise the existence of a legal duty in any particular circumstances what is called for is not an intuitive reaction to a collection of arbitrary factors but rather a balancing against one another of identifiable norms”.
In Country Cloud, the Constitutional Court recognised the risk of indeterminate liability as the main policy consideration that militates against the recognition of liability for pure economic loss . But, the loss in a case of this nature would always be quantifiable and determinate, as it would be limited to the quantum of the payment paid into the account of a fraudster.
[107] The SCA also cautioned in Fourway Haulage that the determination of wrongfulness in claims for pure economic loss is a principled exercise based on considerations of public policy and not on the idiosyncratic views of an individual judge about what is reasonable and fair.
It went on to caution that
“[T]he first policy consideration is the law’s concern to avoid the imposition of liability in an indeterminate amount for an indeterminate time to an indeterminate class” .
The judicial determination in this regard culminates in a value judgment, as to what is either acceptable (reasonable) or sufficiently legally-reprehensible (unreasonable) to warrant a delictual remedy .
It is recognised that the nature of reasonableness in the wrongfulness inquiry should not be confused with the nature of reasonableness in the negligence inquiry.
In the wrongfulness context, the issue is the reasonableness of imposing liability on the defendant for the harm resulting from that conduct .
[108] The wrongfulness test is open-ended and flexible .
The Constitutional Court reminds us aptly that our common law should not “be trapped within the limitations of the past” .
Accordingly, the common law is supposed to adapt to changing needs, and not be static regardless of the evolving perils of cyber-fraud crimes. Whether a duty of care exists would depend on the facts of the case and the identities of the parties.
Such a duty clearly exists between a purchaser in a conveyancing transaction and the conveyancing attorney handling the transaction, but would not exist in many other cases.
[109] ENS criticises the plaintiff for saying that she had never before handled such large sums of money, when in fact she had received or paid various large amounts in May and June 2019.
This criticism is unfounded. It completely ignores the plaintiff’s explanation that the transactions under scrutiny all related to her divorce settlement and related house purchase, which related to the very incident before this Court. The criticism in this regard is accordingly without merit.
[110] Also, ENS criticises the defendant’s evidence on the Pam Golding warnings, and says that she attempted to conceal the Pam Golding fraud warnings despite the defendant’s request for disclosure of third-party warnings. The plaintiff allowed the defendant to make a full copy of her computer and to search it for relevant evidence, which opportunity the defendant took full advantage thereof.
Despite its thorough search of the plaintiff’s computer, the defendant obtained the Pam Golding warning under subpoena of Pam Golding. Evidently, therefore, the Pam Golding emails were not on the plaintiff’s computer.
[111] The plaintiff said in her witness statement that she could not find some emails and believed that emails were deleted from her mailbox by the fraudsters. There are no valid grounds for accusing the plaintiff of trying to conceal anything in these circumstances.
The plaintiff said that she had forgotten about the Pam Golding warning when she responded to the defendant’s request for disclosure. I find this to be a satisfactory explanation on a purely collateral issue. The plaintiff’s reply under cross-examination on a purely collateral matter is considered final and conclusive. I am satisfied that plaintiff testified satisfactorily and was a good witness. He evidence was not seriously challenged.
[112] ENS contends that, if this court holds ENS liable to Ms H, it would expose all conveyancers, big and small alike, to claims of the same kind by third parties, with whom they have no relationship, for losses they suffered at the hands of fraudsters who hacked their own email accounts.
ENS contends that the ripple effect thereof would not only extend to all firms of attorneys but indeed to all businesses who send their invoices, with their banking details, to their clients by email, which is a near-universal practice for all firms and indeed all businesses to do so, as supported by Van’t Wout’s evidence and that of Jordaan.
[113] ENS contends more so, because the near-universal practice in the market is that it is the responsibility of the debtor, who chooses to make an electronic payment, to ensure that it is paid into the right account.
ENS submits in this regard that the court should decline to extend liability for pure economic loss in this case because it will, in the words of the Constitutional Court, create
“liability in an indeterminate amount for an indeterminate time to an indeterminate class” .
[114] The vexed question is whether the law provided the plaintiff with adequate means to protect herself in the circumstances of her case.
In Country Cloud the Constitutional Court said the following, on the topic of vulnerability to risk:
“where a plaintiff has taken, or could have reasonably taken, steps to protect itself from or to avoid loss suffered, this is an important factor counting against a finding of wrongfulness in pure economic loss cases” .
In such circumstances the plaintiff is not ‘vulnerable to risk’ and, on that basis “reasoned, there is no pressing need for the law of delict to step in to protect the plaintiff against loss” .
[115] It is further stated importantly that ,
“This is not to suggest that a delictual claim is precluded whenever a party puts herself in a position where there is a risk of harm. Far from it. We expose ourselves to risk, for example, every time we elect to travel on public roads and that would not excuse from liability those who culpably crash into us. But where a transaction involves a substantial and highly foreseeable risk of loss, which a commercially sophisticated and well-advised plaintiff nevertheless accepts because of the promise of significant financial gain inextricably linked to it, there is often no pressing need for the law of delict to intervene.”
[116] The SCA held in AB Ventures that,
“…there was no call for the law to be extended when the existing law provided adequate means for the plaintiff to protect itself against loss”.
[117] However, the cases cited by the defendant show sophisticated commercial entities failing to protect themselves, or being unable to protect themselves, through contractual mechanisms as opposed to the plaintiff in this matter who did not have a contract with the defendant, as counsel for the plaintiff also contended.
In this matter, as stated, the investment mandate was only sent to the plaintiff after payment was made.
It is true that in this case Ms H had no direct contractual relationship, with ENS but dealt with it directly for conveyancing purposes before the investment mandate was sent.
[118] ENS contends in this case, that the Ms H could have avoided her loss by asking Ms M or Mr C to confirm ENS’ bank details when she spoke to them while she was at her bank or sought the help of her bank. Ms H specifically asked the bank to help her make the transfer to ENS.
[119] But as for the various concessions made by Ms M, they confirmed that her training and awareness in regard to BEC was hopelessly inadequate.
That she apparently considered the plaintiff to be in “professional hands” as counsel for the plaintiff pointed out, is irrelevant in a context where Ms M was not conscious of the relevant dangers and precautions. She did not consider the situation unsafe to begin with, and so would not have conducted herself any differently even if the plaintiff was making the payment without the assistance of her bank. Ms M was oblivious to the relevant risks at the time. She could not have been “reassured” by the bank’s role, because she did not think knew that the plaintiff was at risk.
[120] In contrast to Ms M, Mr C by his version knew and understood the risks of BEC. He knew that the defendant had put the plaintiff at risk by emailing its bank details to her, and yet he stayed silent. That he considered the defendant to be in safe hands at her bank as contended, is unsatisfactory in circumstances where he knew that the plaintiff was at risk. C spoke to the plaintiff on the telephone while knowing of all the relevant risks.
[121] As for N, it was obviously misleading for N to refer this court to 23 redacted emails which, save for 3, had nothing to do with invoices and payments. Her other two surveys proved to be completely irrelevant because they dealt with vendors and law firms that were generally pre-loaded as beneficiaries on the defendant’s system. The evidence of Ms N was accordingly unsatisfactory.
[122] ENS owed at least, a general duty of care to a purchaser of property, in this case Ms H.
ENS, as Ms H contends, had control over the way in which its bank account details were conveyed to her. It chose to do this by way of an unprotected email attaching its bank account details as a PDF document, which could easily be manipulated as the evidence clearly established. In facilitating the transaction, ENS failed to safely communicate its bank details, using technical safety measures or multi-channel verification (in-person or telephonic confirmation).
The legal duty of care owed to the purchaser, arises from the moment the defendant accepted the brief to act as conveyancer in the transaction. There is no reason in principle for only recognizing the duty from the date of payment. It is from the (earlier) moment, when the defendant is appointed as the conveyancer, that the plaintiff depended on the defendant to act professionally.
Even if the plaintiff was not at that point a client of the defendant, she was in the care of the defendant. Its duties in this regard included its duty to warn defendant of the known risk of BEC and to take the necessary precautions against it to protect itself.
[123] Ms H explained adequately why she did not check ENS’ bank details or ask the bank to do so. She repeatedly said that the Pam Golding experience was three months before. As indicated above, emphasised that she was going through a difficult time on account of her divorce. She repeatedly stated she trusted ENS, the source of the email and “assumed they would take care of anything that was not safe”.
[124] It is indeed so that the totality of the evidence shows that it was a near-universal practice for conveyancers, and indeed for other businesses, to send their banking details to others by email but for some exceptions thereto.
It does not absolve the defendant of its unsafe behaviour, which it knew at the time was unsafe and knew to take precautions against.
It is not as if the defendant didn’t know better. Its own investment mandate is, as the plaintiff contends, wholly destructive of defendant’s reliance upon the alleged “near-universal practice”.
[125] Viewed objectively, the plaintiff cannot be faulted for placing her trust in the defendant who she knew was a very large and reputable law firm.
On her version, which I accept and cannot fault, she did not think she needed to seek advice as she was dealing with a law firm whose reputation went before it. She, as indicated, gave credible and consistent evidence that the possibility of BEC did not occur to her and that she trusted the defendant. Under such circumstances, a duty clearly exists between a purchaser in a conveyancing transaction and the conveyancing attorney handling the transaction.
[126] I have no difficulty in finding that the defendant’s banking details were financially sensitive information regarding this matter and needed to be treated as such. I have no difficulty in concluding that the risk of BEC was foreseen by ENS.
ENS is undoubtedly an experienced conveyancer, which understood the risks inherent in conveyancing transactions.
The implications of its own investment mandate confirms its knowledge at the relevant time of the dangers of BEC. This is clear from the warnings contained in its investment mandate and its Acceptable Use Policy, and the numerous concessions to this effect made by its witnesses.
In the present case, ENS was, I find, the proximate cause of the loss in that it provided its own bank account details and was responsible for their accuracy and for the safety of their transmission. In doing so ENS acted wrongfully in light of legal convictions of community.
[127] In my view, the plaintiff’s case established clearly that sending bank details by email is inherently dangerous, and so must either be avoided in favour of, for example, a secure portal or it must be accompanied by other precautionary measures like telephonic confirmation or appropriate warnings which are securely communicated.
The parties’ experts agreed that email is not secure.
In this case the parties’ experts also agreed that secure portals were available in 2019, and would have averted the fraud.
Accordingly, the fact that large firms like CDH and the defendant chose not to use effective technologies and measures that were available and were used by smaller conveyancers does not avail them in making a “common practice” argument, as plaintiff contended.
[128] Password protected email was contemplated by the defendant’s own Acceptable Use Policy.
The experts agreed that there were other mitigating technologies available in 2019, which could have been implemented by the defendant’s in-house IT personnel or which would have been outsourced at a cost R2000 – R8000 per month, which is not an unreasonable amount.
The defendant’s own expert agreed that there was much more the defendant could have done to avoid the fraud. The precautions that the defendant should have and could have implemented but failed to implement would have prevented the fraud regardless how or why the plaintiff’s email was hacked. Although the plaintiff was not a client of the defendant, she was, as stated, still in the care of the defendant and vulnerable to risk.
[129] As for the element of causation, it has by now become well settled that, in the law of delict, causation involves two distinct enquiries.
- First, there is the enquiry into factual causation which is generally conducted by applying the ‘but-for test’ as described in International Shipping Co (Pty) Ltd v Bentley . The facts that are common cause and as found regarding this matter leave no doubt in my mind that, but for the negligent transmission of its account details and failure to warn Ms H upfront of the inherent danger of BEC, she would not have suffered the loss.
- On the second enquiry, under the rubric of legal causation, namely whether the negligent conduct of ENS is linked sufficiently closely or directly to the loss suffered by Ms H for legal liability to ensue, or whether the loss is too remote, I conclude, on the established facts, that it was not too remote.
It was accordingly, reasonably foreseeable under the circumstances, I find, for ENS that Ms H might suffer loss as she did.
[130] ENS was at fault on the basis of negligent conduct.
I am not inclined to agree with submissions made by counsel on behalf of ENS that Ms H must take responsibility for her failure to protect herself against the known risk of relying on banking details received by email. The defendant was an expert conveyancer and was facilitating and managing the transaction.
Under these overall circumstances it not overly burdensome or unreasonable to impose liability on ENS. The risk of loss to Mrs H was highly foreseeable by ENS.
There is no risk of boundless liability as feared by ENS as the loss in this case is claimed by a single plaintiff and is finite in its extent. It is, accordingly, not unlimited or indeterminate.
Conclusion
[131] The interests of the defendant as well as the society demand that a legal duty is recognised in this case. ENS is best placed to understand and prevent BEC. Individuals in society are generally not as well-placed to respond to the ever-evolving threat of cyber-crime, which is sophisticated and technical in nature.
As stated in Estate Van der Byl v Swanepoel,
“where one of two innocent parties has to suffer a loss arising from the misconduct of a third party it is for the public advantage that the loss should fall…on that one of the two who could most easily have prevented the happening or the recurrence of the mischief”.
All facts considered, accordingly, I am persuaded that considerations of legal and public policy require liability in this case. Accordingly, the plaintiff’s claim is upheld.
Costs
[132] Ordinarily, costs follow the result. The plaintiff seeks a punitive costs order.
Attorney and client costs have frequently been awarded against parties for conduct which is vexatious and an abuse of legal process “even though there is no intention to be vexatious”.
As counsel for Ms H pointed out, the plaintiff’s right to privacy was breached by including numerous documents in the trial bundle, which have no relevance to the issues in the case.
It is inexcusable for the defendant to have done so. Nowhere and at no stage was there however an explanation or apology offered to plaintiff by any of defendant’s witnesses or representatives for
- the egregious inclusion in the Trial Bundle of patently irrelevant (but highly personal and sensitive documents pulled from the plaintiff’s laptop); or
- the breach of the specific undertaking not to take copies of these documents; or
- the subsequent addition thereof to the Trial Bundle.
[133] Aggravating this conduct, as was earlier pointed out, is the defendant’s breach of the undertaking (given by its attorney of record) on 6 August 2021 per email not to take copies of these documents which were stored on plaintiff’s hard-drive which itself was made available to defendant’s expert to copy and perform a forensic investigation to determine where the hacking occurred.
On 13 October 2021 however, in breach of the undertaking of 6 August 2021, the defendant (represented by its attorney acting on its instructions) blatantly made or received copies of the irrelevant (but, for plaintiff, very personal and highly confidential) documents and to compound matters, added the documents to the trial bundle. This alone warrants a punitive costs order.
It is therefore unnecessary to deal with the two other remaining grounds relied upon by Ms H in relation to the unsatisfactory aspect of N’s testimony as well as unwarranted criticism of S’s evidence in support hereof.
[134] For all the reasons given, the following order is granted:
Order
134.1 The defendant is ordered to pay the sum of R 5 500 000 (five million and five hundred thousand Rands) to the plaintiff;
134.2 The defendant is ordered to pay interest on the aforesaid amount calculated at the prescribed rate of 10,25% (ten comma twenty-five percent) per annum from 21 August 2019 to date of payment;
134.3 The defendant is liable for the costs of suit, including the costs of two counsel one of whom is a senior counsel;
134.4 It is declared that the plaintiff’s expert witnesses, Messrs Mark Heyink and Anton van’t Wout are necessary witnesses and it is directed that their qualifying fees and expenses be allowed in full.
134.5 All costs payable by the defendant are to be taxed on the scale as between an attorney and his client.
Summary
Summary
Law of delict- whether the defendant as the conveyancer is liable in delict for pure economic loss – wrongfulness –plaintiff vulnerable to risk- delictual liability established.
The judgment deals with the vexed question of whether or not to impose liability for pure economic loss sustained by the plaintiff who fell victim to cyber- crime through business email compromise (‘BEC’) as a result of the defendant’s negligent omission to forewarn the plaintiff of the known risks of BEC and to take the necessary safety precautions that are designed to safeguard against the risk of harm occasioned by BEC from eventuating.
The plaintiff purchased an immovable property from a third party seller who appointed the defendant, ENS attorneys, as the conveyancer in the sale transaction. The plaintiff paid the deposit required under the sale agreement and thereafter chose to pay the balance of the purchase price of R5.5 million by way of electronic transfer of funds directly into the defendant’s trust account (‘the ENS account’) for the benefit of the seller pending registration of transfer.
The plaintiff made an electronic payment of the amount of R5.5 million into what she believed was the ENS account, details of which had been emailed to her by a conveyancing secretary in the employ of the defendant. The ENS account details were set out in a pdf attachment under cover of an email. Unbeknown to the plaintiff, her email account was hacked and the email containing the ENS account details was intercepted by an unknown fraudster and altered to reflect the fraudster’s bank account details, resulting in the funds electronically transferred by the plaintiff being deposited in the fraudster’s bank account as opposed to the ENS account.
Notwithstanding the discovery of the fraud, the defendant called upon the plaintiff to make payment of the balance of the purchase price, which had discernibly not been received by the former as required under the sale transaction. The parties were unable to resolve the impasse that followed, resulting in the plaintiff instituting action against the defendant for the loss of R5.5 million sustained by her as a result of the cyber fraud.
The evidence at trial established that the defendant was aware of the risks of BEC prior to the fraudulent incident and that it had failed to warn the plaintiff of the known risks of email and pdf manipulation or of precautions that could be taken against BEC prior to the plaintiff effecting the electronic payment. It was also not in contention that BEC attacks are rife, especially in the conveyancing industry. Further, the defendant had control over the way in which it conveyed its bank account details to the plaintiff – in an unprotected pdf attachment to an email it transmitted to the plaintiff – whilst technically safe measures, amongst others, multi-channel verification (in-person or telephonic confirmation of bank details) were available to be employed by it to avert cyber fraud.
Held that,
- a duty of care exists between a purchaser in a conveyancing transaction and the conveyancing attorneys handling the transaction to prevent harm resulting from the conveyancer’s failure to warn the depositor of the dangers of cyber hacking and spoofing of emails or of the fact that pdf attachments to emails containing sensitive information such as bank account details are not invulnerable to BEC.
- as an experienced conveyancer, the defendant understood the risks inherent in conveyancing transactions by virtue of its own prior knowledge of the dangers of BEC. The risk of BEC was thus foreseeable and the defendant was under a duty to guard against the harm eventuating. Its omission to do so was negligent in the circumstances.
- the defendant was the proximate cause of the plaintiff’s loss in that it provided its own bank account details and was responsible for their accuracy and for the safety of their transmission. In failing to safeguard the safety of their transmission, the defendant acted wrongfully.
- as regards the element of wrongfulness, the plaintiff’s loss in a case of this nature is both quantifiable and determinate and the risk of indeterminate liability as a policy consideration that militates against the recognition of liability for pure economic loss is thus averted.
- factual causation was established in that but for the negligent transmission by the defendant of its bank account details including its failure to inform the plaintiff, as depositor, of the dangers of BEC, the plaintiff would not have suffered the loss. Legal causation was likewise established as the negligent conduct of the defendant was linked sufficiently closely to the loss suffered by the plaintiff for legal liability to ensue, given that the loss was reasonably foreseeable under the circumstances.
Order: The plaintiff’s claim was upheld with costs on the scale as between an attorney and his client including the costs occasioned by the employment of two counsel.