Home » Blog » Edward Nathan Sonnenberg Inc v Judith Mary Hawarden

Edward Nathan Sonnenberg Inc v Judith Mary Hawarden

Authored By: Bridget Emely Nonjabula Malaz

UNIVERSITY OF SOUTH AFRICA

  1. Case Citation and Basic Information 

Full Case Name: Edward Nathan Sonnenberg Inc v Judith Mary Hawarden

Citation: (421/2023) [2024] ZASCA 90; 2024 (5) SA 9 (SCA) 

Court: Supreme Court of Appeal of South Africa 

Date of Decision: 10 June 2024 

Bench: Ponnan JA, Dambuza JA and Goosen JA, and Tlaletsi AJA and Dawood AJA (Dawood  AJA writing for a unanimous court) 

  1. Introduction 

Business email compromise (BEC) has become one of the most damaging forms of cybercrime  affecting commercial and property transactions in South Africa, exploiting the routine practice of  exchanging banking details by email. Edward Nathan Sonnenberg Inc v Hawarden is a significant  Supreme Court of Appeal decision addressing who accepts the loss when a fraudster intercepts  and manipulates email correspondence exchanged between a conveyancing firm and a member of  the public who is not that firm’s own client. The case required the Court to determine whether a  law firm owes a legal duty, sounding in delict, to warn a third-party purchaser of the risk that its  emails might be hijacked and its banking details altered. The judgment is important because it  clarifies, at appellate level, the boundaries of delictual liability for pure economic loss caused by  cyber-enabled fraud, and the weight the law places on a claimant’s own capacity to protect herself. 

  1. Facts of the Case 

In May 2019, Judith Hawarden agreed to purchase immovable property from the Davidge Pitts  Family Trust for R6 million. The estate agency handling the sale, Pam Golding Properties, emailed  her on the day of purchase asking her to deposit a R500 000 holding amount into its trust account.  That email warned her of the risk of cybercrime and advised her to telephone the agency to verify  its banking details before paying. Ms Hawarden heeded this warning: she telephoned PGP’s agent,  verified the account, and only then made payment.

Edward Nathan Sonnenberg Inc (ENS) was the Trust’s appointed conveyancing attorneys,  responsible for transferring the property into Ms Hawarden’s name. In August 2019, ENS’s  property secretary emailed Ms Hawarden the guarantee requirements and ENS’s banking details.  Unknown to either of them, a cybercriminal had already gained unauthorised access to Ms  Hawarden’s own email account some days earlier, and intercepted this correspondence. The  following day, Ms Hawarden received a near-identical but fraudulent email from a spoofed  address, in which a single letter of the domain name had been altered, substituting the firm’s  genuine banking details with the fraudster’s own. 

Ms Hawarden telephoned ENS to discuss payment and was told she could pay the balance directly  by electronic transfer rather than by bank guarantee. A further genuine ENS email, again warning  of BEC fraud, was sent to her but was intercepted and never reached her. Believing she held ENS’s  correct details, Ms Hawarden attended her bank and, assisted by a bank official, transferred the  balance using the fraudulent account details. She did not telephone ENS to confirm the account  before transferring, despite speaking to ENS staff by telephone that same day. The fraudster  subsequently intercepted and altered further exchanges to delay discovery. The fraud was only  discovered on 29 August 2019, by which time the R5.5 million transferred could not be recovered. 

  1. Legal Issues 

Issue: Whether, in the absence of any contractual or client relationship between Edward Nathan  Sonnenberg Inc and Ms Hawarden, ENS owed Ms Hawarden a legal duty to warn her of the risk  that its email communications might be intercepted and its banking details fraudulently altered,  such that its omission to do so was wrongful for the purposes of a delictual claim for pure economic  loss. 

  1. Arguments Presented 

5.1 Ms Hawarden’s Arguments (Plaintiff/Respondent) 

Ms Hawarden opposed that ENS and its staff owed her a legal duty, as a reasonable conveyancing  firm, to advise her to secure the balance of the purchase price by bank guarantee rather than direct  transfer, and to warn her explicitly of the danger of BEC fraud. She argued ENS should have  alerted her that criminal syndicates commonly induce victims into paying fraudulent accounts 

using emails that closely mimic genuine correspondence, should have advised her to verify  banking details telephonically before payment, and should have used more secure means of  transmitting sensitive information, such as password-protected or multi-factor-authenticated  channels, rather than plain email. She submitted that imposing such a duty was justified on public  policy grounds: ENS was a large, sophisticated law firm, whereas she was an elderly, divorced  pensioner without the resources to protect herself against a form of crime that was, by contrast,  well known within the legal profession. 

5.2 ENS’s Arguments (Defendant/Appellant) 

ENS denied owing Ms Hawarden any legal duty, emphasising that she was never its client; it had  been appointed by the seller, and its dealings with her were incidental to that mandate. It pointed  out that the compromise had occurred within Ms Hawarden’s own email account, not its systems,  and that a genuine ENS email had in fact warned her of BEC risk, but that this warning was itself  intercepted before it reached her. ENS argued that a duty to protect Ms Hawarden could not  reasonably be imposed on it in these circumstances and pleaded, in the alternative, that she had  been contributorily negligent in failing to verify its banking details before transferring so large a  sum. 

  1. Court’s Reasoning and Analysis 

Writing for a unanimous court, Dawood AJA confined the enquiry to a single question: whether  Ms Hawarden had established wrongfulness, the element of delictual liability required where loss  is purely economic and caused by an omission rather than a positive act. The Court reaffirmed the  settled principle that, unlike physical harm, pure economic loss is not prima facie wrongful; a  negligent omission attracts liability only where public and legal policy, applied consistently with  constitutional norms, justify imposing a legal duty on the defendant. 

The Court held that this policy enquiry turns significantly on the plaintiff’s ‘vulnerability to risk’ where a plaintiff has taken, or could reasonably have taken, steps to protect herself from the loss,  this weighs heavily against a finding of wrongfulness, because there is no pressing need for the  law of delict to intervene. Applying this principle, the Court found that Ms Hawarden was not  vulnerable. She had no contractual relationship with ENS, and her loss arose because her own  email account, not ENS’s systems, had been compromised. Critically, she had already shown she 

understood how to protect herself three months earlier, when PGP warned her of the same risk,  she telephoned the agent and verified its details before paying. She failed to take the equivalent,  readily available step with ENS, despite speaking to ENS staff by telephone the day she made the  transfer. The Court also considered that any warning ENS might have given would have been of  limited value in any event, since the cybercriminal was already embedded in her email account by  that stage. 

The Court further reasoned that extending liability to ENS would carry troubling implications  beyond this case. If a conveyancing firm owes a duty to protect every person who transacts with it  by email from the risk of its own account being hacked, then, by parity of reasoning, every creditor  who transmits banking details by email would owe an equivalent duty to every debtor. Endorsing  the Constitutional Court’s reasoning in Country Cloud Trading, the Court treated the risk of  indeterminate liability, in an indeterminate amount, to an indeterminate class, as a decisive policy  consideration against recognising such a duty. On this basis, the high court’s finding of  wrongfulness could not stand. 

  1. Judgment and Ratio Decidendi 

The Supreme Court of Appeal upheld ENS’s appeal with costs, including the costs of two counsel,  and set aside the high court’s order, substituting an order dismissing Ms Hawarden’s claim, with  costs. 

Ratio Decidendi: A defendant’s omission to warn a claimant of the risk of business email  compromise fraud is not wrongful, for the purposes of a delictual claim for pure economic loss,  where the claimant was not ‘vulnerable to risk’ because she had, or reasonably could have had, the  means to protect herself, for example by independently verifying banking details before  transferring funds. Where a claimant is not vulnerable in this sense, and recognising a duty would  expose an indeterminate class of creditors to indeterminate liability, no legal duty to warn arises,  and the omission cannot found delictual liability. 

  1. Critical Analysis 

8.1 Significance of the Decision

The judgment is among the first appellate authorities in South Africa to apply the established  delictual test for wrongful omissions, developed in cases such as Country Cloud and Cape  Empowerment Trust, to losses caused specifically by cyber-enabled fraud. It confirms that existing  delictual principles, rather than any bespoke ‘cyber-duty’, govern the allocation of BEC risk, and  it firmly locates the enquiry in the claimant’s own vulnerability rather than in the sophistication or  resources of the defendant. 

8.2 Implications and Impact 

The decision has practical consequences for the conveyancing and broader professional services  sector. It confirms that attorneys, estate agents, and other professionals transacting by email are  not, without more, exposed to open-ended delictual liability for losses caused by third-party  interception of their correspondence, provided the claimant had a reasonable opportunity to verify  payment details independently. For prospective claimants, the case is a caution that receiving a  specific, timely warning of BEC risk and failing to apply the same vigilance to a later, materially  similar transaction will make it difficult to shift the resulting loss onto the professional party by  way of a delictual claim. 

8.3 Critical Evaluation 

The Court’s reasoning is a careful and orthodox application of established wrongfulness doctrine,  and its concern about indeterminate liability is legitimate: a contrary finding could have exposed  every professional firm handling client funds by email to claims from an unbounded class of  counterparties. At the same time, the judgment arguably underplays the significant information  and resource asymmetry between a sophisticated law firm, well placed to adopt secure payment  portals or multi-factor verification, and an individual member of the public with no specialised  knowledge of BEC fraud. The Court’s emphasis on Ms Hawarden’s earlier vigilance with PGP,  while relevant, arguably places a heavy burden on an ordinary consumer to replicate that vigilance  perfectly across a single transaction, without corresponding weight given to the professional  party’s superior capacity to prevent the harm at its source. 

  1. Conclusion

Edward Nathan Sonnenberg Inc v Hawarden confirms that South African delictual law will not,  without more, impose liability on professionals whose email correspondence is intercepted and  manipulated by cybercriminals, where the claimant had a reasonable and readily available  opportunity to protect herself and failed to take it. The key takeaway is that ‘vulnerability to risk’  remains the decisive lens through which South African courts assess wrongfulness in pure  economic loss claims, including those arising from cybercrime, and that this enquiry is fact 

specific. The judgment will likely be remembered as an early, influential appellate statement on  the allocation of BEC-related losses in South African law, offering conveyancers, banks, and estate  agents a measure of certainty, while leaving open, for future litigation, the harder question of how  the law should respond where a claimant genuinely lacked any realistic means of self-protection,  or where a professional party’s own security practices fell demonstrably short of a reasonable  standard. 

  1. Reference(S):

Edward Nathan Sonnenberg Inc v Hawarden (421/2023) [2024] ZASCA 90; 2024 (5) SA 9 (SCA).

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top