How Does Business Email Compromise (BEC) Affect You and Your Business Legally?

News, Uncategorized

Authors: Olivia Johnston, Anna Lloid

Olivia and Anna are associate lawyers at Dunn & Black, P.S.

We often hear about the increased importance of internet security, such as double authentication and frequently changing passwords. Organizations have implemented significant safety measures and systems to ensure their information is protected from outside threats, but nonetheless, it is still something to monitor internally. While the mandatory company training materials on this topic can seem theoretical, the FBI has reported over 21,389 instances of business email compromise (“BEC”) in 2023 alone, with adjusted losses over $2.9 billion.[1] The FBI describes BEC as “a sophisticated scam targeting both businesses and individuals performing transfers of funds.”

The scenario is usually as follows: emails are exchanged back and forth, often between two parties who have previously communicated about a wire transaction. This is particularly important for law firms—transferring of settlement funds, retainer fees, etc. During one of those email exchanges, one party inadvertently clicks on a phishing email and exposes their security, or a virus will download to a computer. These actions enable hackers to fly under the radar until an invoice or wiring instructions are sent out. Hackers then respond to the paying party with new payment instructions. Unless the paying party notices the warning signs, payment is sent to the improper receiver and the money is never seen again.

Some of the biggest companies have fallen victim to this scheme. Facebook and Google lost approximately $121 million and Toyota at around $37 million. However, it happens more frequently to small businesses and individuals. Unfortunately, the methods hackers use are becoming more creative and are evolving faster than the law can catch up. But that does not mean small businesses and individuals can’t take preventative measures to protect themselves in this ever-evolving scheme.

Litigation has commenced across the United States, mainly on contract theories to solve these complex issues of liability.  Overall, courts appear to construe liability against the party responsible for misdirecting the payments. This is often referred to as “The Imposter Rule,” a phrase coined in the banking industry. “Under the ‘imposter rule,’ the party who was in the best position to prevent the forgery by exercising reasonable care suffers the loss.See, e.g.,  Section 3–404(d) of the Uniform Commercial Code; Arrow Truck Sales, Inc. v. Top Quality Truck & Equip., Inc., No. 8:14-CV-2052-T-30TGW, 2015 WL 4936272, at *5 (M.D. Fla. Aug. 18, 2015).

In Arrow Truck Sales, Inc., companies Arrow Truck Sales and Top Quality Truck & Equipment exchanged emails over a period of five years where they negotiated the sale of twelve trucks totaling $570,000. The parties previously used email as a mode of communication to send wiring instructions upon sale. Consequently, when Arrow Truck Sales received “updated” instructions from an almost identical email address at Top Quality, the “updated” instructions were followed. Unfortunately, this was the product of a hacker, and the $570,000 was wired to a fraudulent account. Because Top Quality never received the money, the trucks were never delivered, which triggered the buyers to bring a lawsuit.

The Arrow Truck Sales court utilized the “Imposter Rule” to determine that the buyers ultimately bore the responsibility. In short, the court analyzed the following factors:

  • Was the new wire instruction completely different from all previous wire instructions?
  • Is the wire transfer through a different bank, location, or to a new beneficiary?
  • Did the paying party take reasonable measures, such as calling, to ensure the wiring instructions were legitimate?

The last factor is likely weighed the heaviest. Thus, if there was a reasonable opportunity for the paying party to confirm the legitimacy of the information, they should make sure to do this.

Bottom line—this is an issue everyone needs to be aware of. To prevent this type of harm from occurring and being subject to liability, we recommend the following:

  1. While email is not the best mechanism to transfer funds, if you choose to do so, ensure all email addresses and information are identical. Even the smallest change in the email address can transfer the funds to the wrong individual.
  2. When receiving an email, be suspicious of the following:
    1. The phrase “kindly send.” For reasons unknown, scammers use this frequently.
    2. Incorrect spelling and grammar.
    3. Differences in writing style from previous communications.
    4. Fake physical addresses. Always look up the address to determine if it is legitimate.
  3. Frequently change passwords.
  4. Enlist a two factor authentication system.
  5. When in doubt, always call the receiving party before transferring and confirm the account information.
  6. If you have been a victim of this crime, notify the FBI’s Internet Crime Complaint Center. Internet Crime Complaint Center(IC3) | File a Complaint.

It is unfortunate to have to implement these measures, but it is the best way to ensure you are protected against hackers. Should you have any questions or need for legal advice, please contact Dunn & Black.

[1] 2023_IC3Report.pdf

Related Cases

No Results Found

The page you requested could not be found. Try refining your search, or use the navigation above to locate the post.