Intervention Fraud: Court of Appeal Clarifies Liability

In the recent case of Logix Aero Ireland Limited v Siam Aero Repair Company Limited, the Court of Appeal dismissed the appeal by Logix and upheld the first instance decision in Siam Aero’s favour. The case involved intervention fraudsters interposing themselves in a transaction between the parties. The transaction was conducted by email, but the principles are applicable to any intervention frauds, whatever the means of communication. Thus, the case is likely to be relevant to all who undertake substantial business transactions as well as to cyber specialists. 

 

The Court of Appeal held that fraudsters' intervention in an email exchange in a transaction between Logix and Siam Aero in order to divert a payment to their own account was sufficient to break the chain of causation in the claim by Logix against Siam Aero, as explained further below.   

 

Background 

Logix, an Irish company, agreed to purchase two aircraft engines from Siam Aero, a Thai company, for a total price of USD935,000 (USD50,000 of which was payable by Logix within two days as a deposit), with a delivery at the facility of Sky Aeroservices SARL in France. The parties signed a Letter of Understanding on 4 July 2024, which was predominantly non-binding but contained a binding confidentiality clause prohibiting disclosure of information and documentation to third parties. 

Unknown fraudsters intercepted email correspondence between the parties by gaining access to an email sent by Siam Aero’s representative on 29 July 2024.  There was no evidence that either party’s IT systems had been compromised. The fraudsters inserted themselves between the parties using fake email addresses with subtly altered domain names (ending “.co” rather than “.com”).  Neither side noticed the changes.   

Siam Aero then sent purchase agreements to the fraudsters believing they were sending them to Logix. The fraudsters inserted details of their bank account in Vietnam and sent the agreements on to Logix and also returned to Siam Aero signed versions of the agreements in which Siam Aero's bank details had been reinstated. As a consequence, on 21 August 2024, Logix paid US$824,900 to the fraudsters’ account, believing it was paying Siam Aero.   

Logix commenced proceedings against Siam Aero.  

At first instance, the Court struck out the proceedings as disclosing no reasonable grounds for bringing the claim. The Court found that while it was arguable that Siam Aero breached the confidentiality clause by unwittingly “disclosing” documents and information to the fraudsters, it was not arguable that any such breach caused Logix’s loss. 

Logix sought to appeal, arguing that the Judge had been wrong to find that the chain of causation between the arguably wrongful provision of information by Siam Aero and Logix’s loss had been broken by the intervention of fraudsters. Logix argued that this was a failure to apply a binding precedent, known as the Macmillan case, in which a firm had drawn the cheque negligently, leaving gaps in the figures and words. These omissions were exploited by a fraudster to increase the amount of the cheque from £2 to £120. The House of Lords held that, notwithstanding the intervening fraud, the firm’s negligence in drawing the cheque facilitated the forgery and thus was the effective cause of the loss. As such, the firm was precluded from recovering its loss from the bank on the basis that, “forgery is not a remote but a very natural consequence of negligence of this description”. The Court of Appeal agreed to hear the appeal solely on the issue of causation.  Siam Aero opposed the appeal on the ground it was not arguable that its actions breached the confidentiality clause at all.  

 

The Court of Appeal’s decision 

The Court of Appeal dismissed the appeal, rejecting Logix’s arguments that the Judge failed to follow a binding precedent, known as the Macmillan case, holding that, “Macmillan is not authority for the proposition that the intervention of a third-party fraudster does not break the chain of causation”. Rather, that case was “firmly based on the existence of a specific contractual duty to prevent the very fraud which was in fact perpetrated (and the very loss which ensued), so that the loss was effectively caused by the breach, was within the scope of duty and was not unlikely to occur”. 

The Court of Appeal upheld the finding of the first instance judge that, “intervention of the fraudsters occurred before any assumed breach of contract by Siam Aero”. It noted that Siam Aero’s assumed breach was only, “one of a number of necessary stages in the fraud, brought about by the fraudsters as part of their overall fraudulent scheme which depended for its success on Logix being deceived and making payment to the wrong account”; importantly, “that final stage of deception by the fraudsters and mistaken payment by Logix occurred without any involvement of Siam Aero”; the Court concluded that this was, “a clear case of the breach being part (and only part) of the opportunity for the fraud rather than the cause of the fraud”. 

The Court of Appeal also upheld the distinction between this case and Macmillan, stating that “the confidentiality clause was primarily concerned with protecting the parties from commercial damage by reason of their documents and information falling into the hands of competitors”. There was, “no hint that it imposed a special duty to protect the other party from being deceived by fraudsters gaining sight of anodyne or otherwise publicly available information and manipulating it.” 

 

Key takeaways 

The Court of Appeal held that an assumed breach of a confidentiality clause was not the effective cause of loss where information was unwittingly disclosed to fraudsters. For businesses that use emails for business transactions (no doubt, most of us), the judgment highlights the difficulty of recovering losses from the counterparty, even where the counterparty may, to some extent, have breached its obligations. 

The prospects for a successful claim may turn on the extent and purpose of the breached duty. A confidentiality clause aimed at protecting commercial information from competitors is unlikely to support a damages claim where the loss is caused by third-party payment fraud. Even where a contractual obligation (such as a confidentiality clause) has arguably been breached, the deliberate and independent actions of fraudsters will ordinarily break the chain of causation.   

Parties wishing to protect themselves against intervention fraud such as email fraud will need to impose wider obligations on their counterparties that are explicitly intended to cover loss of the relevant type. They should consider drafting specific clauses addressing verification of payment instructions, rather than relying on general confidentiality provisions.  

The decision also provides a reminder that Macmillan is confined to its context: a specific contractual duty to prevent the very type of fraud that occurred.  

You can find the full judgment here

 

If you would like to discuss any of the points raised by this article, please do not hesitate to contact us. 

 

Related Expertise

Disclaimer: This publication is provided by Laytons LLP for informational purposes only. The information contained in this publication should not be construed as legal advice. Any questions or further information regarding the matters discussed in this publication can be directed to your regular contact at Laytons LLP or Laytons’ Disputes team.