Authored By: Bridget Emely Nonjabula Malaz
UNIVERSITY OF SOUTH AFRICA
- Case Citation and Basic Information
Full Case Name: Edward Nathan Sonnenberg Inc v Judith Mary Hawarden
Citation: (421/2023) [2024] ZASCA 90; 2024 (5) SA 9 (SCA)
Court: Supreme Court of Appeal of South Africa
Date of Decision: 10 June 2024
Bench: Ponnan JA, Dambuza JA and Goosen JA, and Tlaletsi AJA and Dawood AJA (Dawood AJA writing for a unanimous court)
- Introduction
Business email compromise (BEC) has become one of the most damaging forms of cybercrime affecting commercial and property transactions in South Africa, exploiting the routine practice of exchanging banking details by email. Edward Nathan Sonnenberg Inc v Hawarden is a significant Supreme Court of Appeal decision addressing who accepts the loss when a fraudster intercepts and manipulates email correspondence exchanged between a conveyancing firm and a member of the public who is not that firm’s own client. The case required the Court to determine whether a law firm owes a legal duty, sounding in delict, to warn a third-party purchaser of the risk that its emails might be hijacked and its banking details altered. The judgment is important because it clarifies, at appellate level, the boundaries of delictual liability for pure economic loss caused by cyber-enabled fraud, and the weight the law places on a claimant’s own capacity to protect herself.
- Facts of the Case
In May 2019, Judith Hawarden agreed to purchase immovable property from the Davidge Pitts Family Trust for R6 million. The estate agency handling the sale, Pam Golding Properties, emailed her on the day of purchase asking her to deposit a R500 000 holding amount into its trust account. That email warned her of the risk of cybercrime and advised her to telephone the agency to verify its banking details before paying. Ms Hawarden heeded this warning: she telephoned PGP’s agent, verified the account, and only then made payment.
Edward Nathan Sonnenberg Inc (ENS) was the Trust’s appointed conveyancing attorneys, responsible for transferring the property into Ms Hawarden’s name. In August 2019, ENS’s property secretary emailed Ms Hawarden the guarantee requirements and ENS’s banking details. Unknown to either of them, a cybercriminal had already gained unauthorised access to Ms Hawarden’s own email account some days earlier, and intercepted this correspondence. The following day, Ms Hawarden received a near-identical but fraudulent email from a spoofed address, in which a single letter of the domain name had been altered, substituting the firm’s genuine banking details with the fraudster’s own.
Ms Hawarden telephoned ENS to discuss payment and was told she could pay the balance directly by electronic transfer rather than by bank guarantee. A further genuine ENS email, again warning of BEC fraud, was sent to her but was intercepted and never reached her. Believing she held ENS’s correct details, Ms Hawarden attended her bank and, assisted by a bank official, transferred the balance using the fraudulent account details. She did not telephone ENS to confirm the account before transferring, despite speaking to ENS staff by telephone that same day. The fraudster subsequently intercepted and altered further exchanges to delay discovery. The fraud was only discovered on 29 August 2019, by which time the R5.5 million transferred could not be recovered.
- Legal Issues
Issue: Whether, in the absence of any contractual or client relationship between Edward Nathan Sonnenberg Inc and Ms Hawarden, ENS owed Ms Hawarden a legal duty to warn her of the risk that its email communications might be intercepted and its banking details fraudulently altered, such that its omission to do so was wrongful for the purposes of a delictual claim for pure economic loss.
- Arguments Presented
5.1 Ms Hawarden’s Arguments (Plaintiff/Respondent)
Ms Hawarden opposed that ENS and its staff owed her a legal duty, as a reasonable conveyancing firm, to advise her to secure the balance of the purchase price by bank guarantee rather than direct transfer, and to warn her explicitly of the danger of BEC fraud. She argued ENS should have alerted her that criminal syndicates commonly induce victims into paying fraudulent accounts
using emails that closely mimic genuine correspondence, should have advised her to verify banking details telephonically before payment, and should have used more secure means of transmitting sensitive information, such as password-protected or multi-factor-authenticated channels, rather than plain email. She submitted that imposing such a duty was justified on public policy grounds: ENS was a large, sophisticated law firm, whereas she was an elderly, divorced pensioner without the resources to protect herself against a form of crime that was, by contrast, well known within the legal profession.
5.2 ENS’s Arguments (Defendant/Appellant)
ENS denied owing Ms Hawarden any legal duty, emphasising that she was never its client; it had been appointed by the seller, and its dealings with her were incidental to that mandate. It pointed out that the compromise had occurred within Ms Hawarden’s own email account, not its systems, and that a genuine ENS email had in fact warned her of BEC risk, but that this warning was itself intercepted before it reached her. ENS argued that a duty to protect Ms Hawarden could not reasonably be imposed on it in these circumstances and pleaded, in the alternative, that she had been contributorily negligent in failing to verify its banking details before transferring so large a sum.
- Court’s Reasoning and Analysis
Writing for a unanimous court, Dawood AJA confined the enquiry to a single question: whether Ms Hawarden had established wrongfulness, the element of delictual liability required where loss is purely economic and caused by an omission rather than a positive act. The Court reaffirmed the settled principle that, unlike physical harm, pure economic loss is not prima facie wrongful; a negligent omission attracts liability only where public and legal policy, applied consistently with constitutional norms, justify imposing a legal duty on the defendant.
The Court held that this policy enquiry turns significantly on the plaintiff’s ‘vulnerability to risk’ where a plaintiff has taken, or could reasonably have taken, steps to protect herself from the loss, this weighs heavily against a finding of wrongfulness, because there is no pressing need for the law of delict to intervene. Applying this principle, the Court found that Ms Hawarden was not vulnerable. She had no contractual relationship with ENS, and her loss arose because her own email account, not ENS’s systems, had been compromised. Critically, she had already shown she
understood how to protect herself three months earlier, when PGP warned her of the same risk, she telephoned the agent and verified its details before paying. She failed to take the equivalent, readily available step with ENS, despite speaking to ENS staff by telephone the day she made the transfer. The Court also considered that any warning ENS might have given would have been of limited value in any event, since the cybercriminal was already embedded in her email account by that stage.
The Court further reasoned that extending liability to ENS would carry troubling implications beyond this case. If a conveyancing firm owes a duty to protect every person who transacts with it by email from the risk of its own account being hacked, then, by parity of reasoning, every creditor who transmits banking details by email would owe an equivalent duty to every debtor. Endorsing the Constitutional Court’s reasoning in Country Cloud Trading, the Court treated the risk of indeterminate liability, in an indeterminate amount, to an indeterminate class, as a decisive policy consideration against recognising such a duty. On this basis, the high court’s finding of wrongfulness could not stand.
- Judgment and Ratio Decidendi
The Supreme Court of Appeal upheld ENS’s appeal with costs, including the costs of two counsel, and set aside the high court’s order, substituting an order dismissing Ms Hawarden’s claim, with costs.
Ratio Decidendi: A defendant’s omission to warn a claimant of the risk of business email compromise fraud is not wrongful, for the purposes of a delictual claim for pure economic loss, where the claimant was not ‘vulnerable to risk’ because she had, or reasonably could have had, the means to protect herself, for example by independently verifying banking details before transferring funds. Where a claimant is not vulnerable in this sense, and recognising a duty would expose an indeterminate class of creditors to indeterminate liability, no legal duty to warn arises, and the omission cannot found delictual liability.
- Critical Analysis
8.1 Significance of the Decision
The judgment is among the first appellate authorities in South Africa to apply the established delictual test for wrongful omissions, developed in cases such as Country Cloud and Cape Empowerment Trust, to losses caused specifically by cyber-enabled fraud. It confirms that existing delictual principles, rather than any bespoke ‘cyber-duty’, govern the allocation of BEC risk, and it firmly locates the enquiry in the claimant’s own vulnerability rather than in the sophistication or resources of the defendant.
8.2 Implications and Impact
The decision has practical consequences for the conveyancing and broader professional services sector. It confirms that attorneys, estate agents, and other professionals transacting by email are not, without more, exposed to open-ended delictual liability for losses caused by third-party interception of their correspondence, provided the claimant had a reasonable opportunity to verify payment details independently. For prospective claimants, the case is a caution that receiving a specific, timely warning of BEC risk and failing to apply the same vigilance to a later, materially similar transaction will make it difficult to shift the resulting loss onto the professional party by way of a delictual claim.
8.3 Critical Evaluation
The Court’s reasoning is a careful and orthodox application of established wrongfulness doctrine, and its concern about indeterminate liability is legitimate: a contrary finding could have exposed every professional firm handling client funds by email to claims from an unbounded class of counterparties. At the same time, the judgment arguably underplays the significant information and resource asymmetry between a sophisticated law firm, well placed to adopt secure payment portals or multi-factor verification, and an individual member of the public with no specialised knowledge of BEC fraud. The Court’s emphasis on Ms Hawarden’s earlier vigilance with PGP, while relevant, arguably places a heavy burden on an ordinary consumer to replicate that vigilance perfectly across a single transaction, without corresponding weight given to the professional party’s superior capacity to prevent the harm at its source.
- Conclusion
Edward Nathan Sonnenberg Inc v Hawarden confirms that South African delictual law will not, without more, impose liability on professionals whose email correspondence is intercepted and manipulated by cybercriminals, where the claimant had a reasonable and readily available opportunity to protect herself and failed to take it. The key takeaway is that ‘vulnerability to risk’ remains the decisive lens through which South African courts assess wrongfulness in pure economic loss claims, including those arising from cybercrime, and that this enquiry is fact
specific. The judgment will likely be remembered as an early, influential appellate statement on the allocation of BEC-related losses in South African law, offering conveyancers, banks, and estate agents a measure of certainty, while leaving open, for future litigation, the harder question of how the law should respond where a claimant genuinely lacked any realistic means of self-protection, or where a professional party’s own security practices fell demonstrably short of a reasonable standard.
- Reference(S):
Edward Nathan Sonnenberg Inc v Hawarden (421/2023) [2024] ZASCA 90; 2024 (5) SA 9 (SCA).

