Email invoice fraud, also known as Business Email Compromise (BEC), costs companies significant sums of money every year. When a debtor pays a counterfeit invoice after the creditor's mailbox has been hacked, the question immediately arises whether that debtor should pay his debt again to the real creditor. A ruling by the French-speaking Enterprise Court in Brussels on May 2, 2024, shows that the court can rule for shared liability (50/50) when both parties have acted negligently and failed to respect internal procedures.
The facts
In the case before the court, an Italian IT company (ITA) and a Luxembourg IT company (LUX) worked together in a consortium. LUX acted as leader of the consortium, received the funds and had to pay ITA for its performance. After a cyber attack, a hacker gained access to the mailbox of an ITA employee.
The hacker intercepted email traffic and sent fraudulent messages to LUX. Under the pretext of a banking audit, LUX was asked to pay outstanding invoices to a new, Spanish bank account number. To this end, the hacker delivered a document with a forged, poorly spelled signature. Without further verification, LUX made two payments totaling 618,220.10 euros. When ITA did not receive the money and raised the alarm, the fraud came to light. ITA then demanded payment of the invoices on.
Enterprise court decision
The legal discussion revolved around two central articles of law from the (old) Civil Code:
- Article 1239 old CC: This article states that a payment is dischargeable when made to the true creditor. If one does not do this, then the principle “he who pays badly, pays twice” applies.
- Article 1240 old CC:This article is an exception to the main rule and states that a payment is valid (discharging) if it was made in good faith to a person in possession of the claim (the so-called “sham creditor”).
LUX invoked its good faith (Article 1240 Old Civil Code), but the court rejected this argument. LUX had not exercised sufficient vigilance: the signature on the document was visibly forged, the hacker suddenly communicated in Italian instead of English, and LUX ignored its own internal procedures by not thoroughly checking the document.
However, the court ruled that the creditor (ITA) had also committed grave (extra-contractual) misconduct (Art. 1382 old CC, now Art. 5.5 CC). Despite its status as an IT company, ITA had ignored numerous warnings, such as suspicious login attempts from Nigeria and unusual e-mail rules.
Because both parties had committed gross negligence that enabled the fraud, the court decided on shared liability. LUX was ordered to still pay half of the amount (€309,110.05) to ITA.
Legal analysis and interpretation
The ruling illustrates an interesting interplay in case law between the trust doctrine (the theory of sham representation) and extra-contractual liability law.
On the one hand, the application of Article 1240 Old Civil Code (now codified under Article 5.198 CC) requires a “legitimate mistake” on the part of the payer. Caselaw is strict here: a professional player (especially in the IT sector) is expected to exercise a high degree of care when changing bank information. Any anomaly - such as a spelling error in a signature or a sudden change of language - deprives the payer of the opportunity to invoke the excusability of his error.
On the other hand, extra-contractual liability law (Article 1382 old Civil Code, now Article 6.5 Civil Code) provides an important corrective mechanism. Even if the debtor makes an error of judgement, he can claim damages (or apply set-off) if the creditor himself has been careless with the security of his IT systems. Here, failure to adequately respond to ‘impossible travel activity’ or ‘risky sign-in alerts’ in a Microsoft Office 365 environment explicitly qualifies as a breach of the general standard of care.
This evolution shows that judges are increasingly looking to the effective cyber hygiene behavior of both parties to equitably allocate the financial risk in BEC fraud cases.
What this specifically means
For businesses, both as debtor and creditor, this case law has significant practical implications:
- For the payer (debtor): You cannot blindly rely on an e-mail message communicating a new account number. Even if the message comes from your vendor's real e-mail address, you carry a significant risk. Strict adherence to internal procedures (such as a telephone verification requirement via an already known, reliable phone number) is crucial.
- For the supplier (creditor): You are not automatically protected when you fall victim to a hack. If your IT infrastructure is poorly secured (e.g., lack of Multi-Factor Authentication) or if you ignore alerts (security alerts), you risk losing a large portion of your claim permanently.
Frequently asked questions (FAQ)
Do I have to pay an invoice again if I have been scammed by a hacker?
Yes, as a general rule, you are not freed from your debt when you pay to a scammer instead of your actual creditor. Exceptions exist only if you acted in good faith and without any negligence (the sham creditor theory), or if the hacker was able to strike in part because of a serious mistake on the part of your supplier.
What is Business Email Compromise (BEC)?
BEC, or invoice fraud via e-mail, is a scam in which a cybercriminal hacks into a company's e-mail account. The scammer intercepts invoices and modifies bank account numbers, causing unsuspecting customers to send their payments to the fraudster's account instead of to the legitimate supplier.
How can my company prevent invoice fraud?
Implement strict, multi-layered security procedures. Always verify changes to bank information through an alternative channel, such as a phone call to your regular contact person. In addition, on your own side, ensure good cyber hygiene, including active monitoring of suspicious login attempts, to avoid co-liability.
Conclusion
The rising trend of invoice fraud and Business Email Compromise is forcing businesses in Belgium to be extremely vigilant. If you pay to the wrong account number, there is a real chance that you will have to pay the invoice a second time. If you are hacked as a creditor, you run the risk of being partly responsible for the damage if you were negligent in terms of cyber security. Careful analysis of the conduct of all parties involved is crucial to correctly answering the liability question.



