Skip to content

An email scam cautionary tale

By Nancy Rubin, K.C. and Levi Parsche

What happens if a person accidentally makes payment to a hacker, instead of to the person they actually owe money? Should they have to pay again? In the recent decision, Jane Group Limited v. Heritage Gas Limited, 2022 NSSM 36, a small claims court adjudicator said yes.

EFT Payment Scam

In the case, two companies had agreed to split the costs to repair a sidewalk after a natural gas line was installed. Shortly after the repairs were completed, Jane Group emailed Heritage Gas seeking payment of its share. Heritage Gas responded, requesting an invoice for the repairs, and indicated it could pay by electronic funds transfer (“EFT”) or via cheque. So far, so good.

Then, Heritage Gas received what it assumed was a response from Jane Group, providing banking information and instructions to send payment via EFT. Unfortunately, this email was actually from an online hacker who had intercepted previous communications. The hacker, representing themselves as the Jane Group president, provided information for a fraudulent bank account, and asked for the money to be deposited that same day.

Heritage Gas emailed Jane Group again indicating it needed an invoice before it could make a payment. In response, (and from a different email address) Jane Group provided an invoice, which indicated payment should be made by cheque to a mailing address.

Unfortunately, upon receipt of the invoice, Heritage Gas followed the earlier EFT instructions that had been sent, depositing the payment into the fraudulent bank account provided by the hacker.

Decision

Having not received payment, Jane Group sued for recovery from Heritage Gas.  Counsel for Jane Group argued that there were several “red flags” in the email from the hacker (spacing and typographical errors) which should have triggered a follow-up by Heritage Gas, not to mention the discrepancy in the direction to pay via EFT or cheque.

On the other hand, counsel for Heritage Gas argued that the loss of money was due to Jane Group’s “carelessness” and lack of cybersecurity.

In the end, Adjudicator Darling found that both parties were innocent victims of the hacker and ruled that as neither party had exhibited blameworthy conduct, the case must be decided in favour of the Claimant, Jane Group.

Key Takeaway

As we move towards an increasingly digital world, this case serves as a reminder to keep an eye out for fraudulent activity. Take extra steps to make sure your electronic funds transfers are secure.  Watch out for email red flags (typos, suspicious links, misspellings, a sense of urgency) and confirm payment details via an additional method – otherwise you might end up on the hook and have to pay twice!


This update is intended for general information only. If you have questions about the above, please contact the authors.

Click here to subscribe to Stewart McKelvey Thought Leadership.

SHARE

Archive

Search Archive


 
 

Discovery: Atlantic Education & the Law – Issue 10

June 24, 2022

We are pleased to present the tenth issue of Discovery, our very own legal publication targeted to educational institutions in Atlantic Canada. As we settle into a summer having rounded out the end of another…

Read More

Pay Transparency: Recent Changes to PEI’s Employment Standards Act

June 10, 2022

Murray Murphy and Kate Profit Changes to Prince Edward Island’s Employment Standards Act (“ESA”) regarding pay transparency received royal assent on November 17, 2021 and has recently come into force as of June 1, 2022.…

Read More

Discovering a Denial: Recent Ontario decision sheds light on discoverability of claims against LTD insurers

June 3, 2022

Michelle Chai & Jennifer Taylor1   A recent Ontario case offers insight on when the limitation period starts to run for an action against a disability insurer. In Kumarasamy v Western Life Assurance Company, the…

Read More

Pension update – CAPSA releases consultation draft of CAP Guideline No. 3 for comment

May 30, 2022

Level Chan and Annelise Harnanan Background On May 13, 2022 the Canadian Association of Pension Supervisory Authorities (CAPSA) released and invited feedback on a Consultation Draft of revisions to CAPSA Guideline No. 3 – Guidelines…

Read More

Accountability and Oversight: Nova Scotia’s new Powers of Attorney Act

May 9, 2022

Richard Niedermayer, QC, TEP, Sarah Almon, TEP, and Madeleine Coats Updated: July 7, 2022 Long-awaited amendments to the Province’s currently short-and-sweet Powers of Attorney Act1 received Royal Assent on Friday, April 22, 2022.  The amended Powers of Attorney…

Read More

Prince Edward Island’s new Non-Disclosure Agreements Act

May 5, 2022

Jacob Zelman and Kate Profit Prince Edward Island’s Non-Disclosure Agreements Act (“Act”) received royal assent on November 17, 2021 and is set to come into force on May 17, 2022. The purpose of the Act…

Read More

New Brunswick’s new Intimate Images Unlawful Distribution Act

April 28, 2022

Chad Sullivan and Tiffany Primmer Increasingly, employers are finding themselves faced with addressing the uncomfortable situation of an employee who has shared an intimate image of another employee. While not directly applicable to what an…

Read More

Provincial Non-Resident Deed Transfer Tax Guidelines

April 19, 2022

Brian Tabor, QC and Eyoab Begashaw On April 8, 2022, the Nova Scotia Department of Finance and Treasury Board (Provincial Tax Policy and Administration Division) released the Provincial Non-Resident Deed Transfer Tax Guidelines (“Guidelines”) with…

Read More

Federal pension update: OSFI seeks input on proposed investment risk management guidance

April 14, 2022

Dante Manna and Hannah Brison Background The Office of the Superintendent of Financial Institutions (“OSFI”) is seeking feedback from stakeholders on its March 2022 Consultation Paper (“Consultation Paper”), which introduces proposed pension investment risk management…

Read More

Unvaccinated employees placed on unpaid leave – who pays the price?

April 11, 2022

Julie Morris COVID-19 has caused many employers to be “caught between a rock and a hard place” – particularly when it comes to managing employee vaccination and attendance at work. Arbitrator Augustus Richardson used this…

Read More

Search Archive


Scroll To Top