An email scam cautionary tale
By Nancy Rubin, K.C. and Levi Parsche
What happens if a person accidentally makes payment to a hacker, instead of to the person they actually owe money? Should they have to pay again? In the recent decision, Jane Group Limited v. Heritage Gas Limited, 2022 NSSM 36, a small claims court adjudicator said yes.
EFT Payment Scam
In the case, two companies had agreed to split the costs to repair a sidewalk after a natural gas line was installed. Shortly after the repairs were completed, Jane Group emailed Heritage Gas seeking payment of its share. Heritage Gas responded, requesting an invoice for the repairs, and indicated it could pay by electronic funds transfer (“EFT”) or via cheque. So far, so good.
Then, Heritage Gas received what it assumed was a response from Jane Group, providing banking information and instructions to send payment via EFT. Unfortunately, this email was actually from an online hacker who had intercepted previous communications. The hacker, representing themselves as the Jane Group president, provided information for a fraudulent bank account, and asked for the money to be deposited that same day.
Heritage Gas emailed Jane Group again indicating it needed an invoice before it could make a payment. In response, (and from a different email address) Jane Group provided an invoice, which indicated payment should be made by cheque to a mailing address.
Unfortunately, upon receipt of the invoice, Heritage Gas followed the earlier EFT instructions that had been sent, depositing the payment into the fraudulent bank account provided by the hacker.
Decision
Having not received payment, Jane Group sued for recovery from Heritage Gas. Counsel for Jane Group argued that there were several “red flags” in the email from the hacker (spacing and typographical errors) which should have triggered a follow-up by Heritage Gas, not to mention the discrepancy in the direction to pay via EFT or cheque.
On the other hand, counsel for Heritage Gas argued that the loss of money was due to Jane Group’s “carelessness” and lack of cybersecurity.
In the end, Adjudicator Darling found that both parties were innocent victims of the hacker and ruled that as neither party had exhibited blameworthy conduct, the case must be decided in favour of the Claimant, Jane Group.
Key Takeaway
As we move towards an increasingly digital world, this case serves as a reminder to keep an eye out for fraudulent activity. Take extra steps to make sure your electronic funds transfers are secure. Watch out for email red flags (typos, suspicious links, misspellings, a sense of urgency) and confirm payment details via an additional method – otherwise you might end up on the hook and have to pay twice!
This update is intended for general information only. If you have questions about the above, please contact the authors.
Click here to subscribe to Stewart McKelvey Thought Leadership.
Archive
Vasu Sivapalan and Meg Collins On May 5, 2017, An Act Respecting the Opening of Sealed Adoption Records (“Act”) received royal assent, leading to significant changes for birth parents and adoptees across the province. As…
Read MoreJennifer Taylor Recent amendments to the Nova Scotia Insurance Act are designed “to protect the financial interests of an innocent person when the person’s property is damaged by another person with whom that person shares…
Read MoreBrian G. Johnston, QC Cannabis legalization is coming. The legislation is expected to pass by July with legalization becoming effective by September. Employers should take notice because: 1. There is already a lot of cannabis…
Read MoreJanet Clark and Sean Seviour A recent decision from the Supreme Court of Canada clarifies determination of what is “reasonably foreseeable”: Rankin (Rankin’s Garage & Sales) v J.J., 2018 SCC 19. The case involved two…
Read MoreJennifer Taylor & Michelle Chai A recent Supreme Court decision tackled two issues that have proven complex in Nova Scotia law: summary judgment and limitation periods. The Plaintiff in Cameron v Nova Scotia Association of…
Read MoreBrian G. Johnston, QC The Arbitrator in Lower Churchill Transmission Construction Employers’ Association and IBEW, Local 1620 dismissed a grievance on April 30, 2018 concluding: The Employer did not place the Grievor in employment at…
Read MoreRick Dunlop and Richard Jordan Employers, and benefit providers on their behalf, make policy decisions as to what drugs or benefits (including monetary limits) will be covered by benefit plans. The Board of Trustees in…
Read MoreErin Best The decision of Justice Handrigan in Ryan v. Curlew is the first motor vehicle accident personal injury decision to come out of the Newfoundland and Labrador courts in quite some time. The case…
Read MoreRob Aske The arrival of spring should bring thoughts of renewal… to your privacy practices. Breach reporting under PIPEDA Canada’s federal privacy law known by the acronym PIPEDA (Personal Information Protection and Electronic Documents Act)…
Read MoreChad Sullivan Overview An Indigenous law professor filed a human rights complaint against the University of British Columbia claiming the university discriminated against her in failing to consider her less traditional scholarly work as akin…
Read More