Executing a transfer of funds is quickly becoming a white-knuckle moment for those involved in large commercial transactions. There grows a looming spectre of so-called Business Email Compromise attacks (‘BEC attacks’) in which fraudsters access genuine company email addresses and, by sending notice of new account details, redirect EFT payments into their own bank accounts. The misappropriated funds are quickly dispersed, and the fraudsters vanish. This kind of fraud leaves two victims in its wake: those who mistakenly transfer money into fraudulent accounts, and those deprived of the money they expected.

Dealing with the fallout of BEC attacks is a complex question for the courts. On one hand, the compromised party is deprived of the payment they expected pursuant to an agreement, and can point to the party who acted in reliance on the fraudulent communications as having failed to meet their obligations under such an agreement. On the other hand, the party acting in detrimental reliance on fraudulent communications may do so in good faith and without notice of the fraud, and can point to the compromised party as having failed in their obligation to maintain effective cybersecurity to prevent fraud. The tension between these two approaches is only partially resolved in Australian cases to date.

Factory Direct Fencing Pty Ltd v Kong AH International Company Limited [2013] QDC 239

In Factory Direct, a fraudster intervened in a transaction between a Chinese exporter of fencing products and an Australian importer. The fraudster used a similar but not identical email address to Kong AH’s genuine email address to redirect payment to a fraudulent bank account. This practice of creating misleading email addresses is known as ‘spoofing,’ and usually involves the registration of new domain names and email addresses with minor typographical differences like swapped letters or substituted characters. Once the fraud was discovered, Factory Direct demanded that the transfer of goods be finalised because a) they had made payment in accordance with the instructions of Kong AH, or b) in the alternative, that Kong AH had breached a duty to ensure its customers were not the victim of fraudulent emails.

Both arguments failed. The Queensland District Court held that the impugned communications did not come from Kong AH, but instead an unauthorised third-party fraudster. Further, Kong AH did not owe a duty to its customers to protect them from misdirecting or fraudulent emails. Kong AH was entitled to the payment of the invoice, leaving Factory Direct doubly out of pocket.

Importantly in this case, the Court considered that Factory Direct could have taken reasonable steps to verify the payment details, particularly given the payment was initially rejected by their bank on the grounds that the details had changed. This case was the starting point in a line of reasoning by Australian courts which places the burden on the buyer to ensure that they are paying the correct account, rather than on the seller to ensure that no fraudster intervenes in the transaction.

Mobius Group Pty Ltd v Inoteq Pty Limited [2024] WADC 114

Almost a decade after Factory Direct, the decision in Mobius provided a significant update. In this case, fraudsters gained access to an email account belonging to a director of Mobius Group and sent an email to Inoteq requesting payment to a new account. A key point of difference here is the fact that the email address used by the fraudster was not ‘spoofed’ (as was the case in Factory Direct) but was the genuine email address of a Mobius director. Despite the Court hearing evidence about best practice for cybersecurity, no arguments were advanced that Mobius’ cybersecurity systems were inadequate or unsuitable.

Inoteq argued that the fraudulent email constituted written notice of a change in account details. Even though the actual sender of the email was a fraudster, Inoteq argued that because the communication came from a genuine email address, they were entitled to rely on it in good faith. The WA District Court disagreed. The Court found that the email did not constitute written notice and pointed to Inoteq’s attempt to verify the account details by phone as evidence that they had doubts about the email’s legitimacy.

A question arising from this case concerns the extent to which a seller has a duty to maintain the security of their email accounts. Inoteq argued that it was reasonably foreseeable that if Mobius did not exercise control over its email account then fraudulent communications could be sent from that account which would cause economic loss to a potential buyer. Astonishingly, the Court did not find that such a duty could apply to the circumstances of the case, holding that ‘ultimately only the defendant was in a position to be able to take measures to stop itself from being the victim of a fraud.’ [153] This decision suggests that, at law, sellers are not subject to a duty to ensure they have adequate cybersecurity controls in place to protect against fraud.

MJ Concepts Kotara Pty Ltd v Pandora Jewellery Pty Ltd (No 2) [2026] NSWDC 262

A new decision by the NSW District Court continues this line of reasoning. In this case, a genuine MJC email account belonging to employee Donna Matthews was compromised, and new bank account details sent to Pandora. Pandora paid money owing under an Asset Sale Agreement into the fraudster’s account. MJC subsequently claimed Pandora had failed to meet its obligations under the ASA.

The Court first considered whether the fraudster’s email from the genuine MJC email address could constitute genuine notice of a change in account details. The Court applied the same reasoning as in Factory Direct and Mobius, holding that the actual sender of the email (i.e. the fraudster) had no actual or apparent authority to make representations on behalf of MJC – therefore MJC could not be bound by the actions of a fraudster.

A novel argument was advanced by Pandora, that MJC was estopped from pursing its claim because MJC represented that Ms Matthews had plenary authority to act on its behalf, and Pandora reasonably relied on that authority by acting in accordance with an email they reasonably believed was from Ms Matthews. This argument was rejected on the basis that MJC had not, in fact, represented that Ms Matthews had plenary authority and Pandora could not have reasonably relied on it.

The Court pointed to factors which should have raised Pandora’s suspicion, including:

  • the very request for payment into a new and different account
  • the ‘unusual and suspicious time’ of 2:16am that the email was sent
  • the inconsistent text size in the part of the email containing the bank account
  • some irregularities in one attachment to the email including typographical error ‘The National Australia Bank of Australia,’ a signature that did not match the purported signatory, and the absence of contact details.

Ultimately, the court held that ‘although both parties were innocent to the fraud, … the loss should fall … on Pandora by whose indiscretion it has been occasioned.’ [420]

Rationale for the developing approach?

The courts’ developing approach is based on three central propositions. First, that defendants / transferors are better placed to take precautions to protect themselves from fraud than plaintiffs / transferees. But while transferors can undertake due diligence by phone to ensure account details are accurate, the fraud is enabled by deficiencies or weaknesses in the transferee’s IT security systems which are exploited by fraudsters. The instigating vulnerability is not of the transferor but the transferee. It may then be appropriate for the transferee to bear the loss of the fraud, rather than the transferor who is a victim of fraud through no fault of their own.

Second, placing the burden of responsibility on the transferor guards against wilful blindness by transferors and reflects ‘commercial reality.’ While it is certainly reasonable to expect a high level of scrutiny by transferors when making payments, the line of cases described in this article represent a ballooning category of circumstances under which transferees ought to have had their suspicions aroused. From the ‘spoofed’ email addresses in Factory Direct to now the finer typographical points of email attachments in MJ Concepts, the authorities are trending in a direction which risks truly innocent and unsuspecting transferors ending up on the hook for third party fraud.

Third, courts have suggested that placing the burden of responsibility on transferees would ‘encourage other fraudsters who could operate on the basis that no checks needed to be made by payers.’ (Mobius, [186]) Respectfully, this reasoning does not hold water. So long as the burden of responsibility falls on either the transferee or transferor and not the fraudster themselves, BEC attacks will continue. Adequate cybersecurity controls must be in place for transferees, and due diligence must be conducted by transferors. The question really is how best to apportion the loss between the two victims in the circumstances. Presently, it seems the scales are tipped.