A recent District Court of NSW decision confirms that a business which pays a fraudster relying on compromised email instructions can still be liable to pay the full amount owed to the intended recipient. Consistently with other recent cases, it underscores a simple but critical control: before any payment is made, a payor should independently verify a request to change bank account details through a trusted channel.
In MJ Concepts Kotara Pty Ltd v Pandora Jewellery Pty Ltd (No 2) [2026] NSWDC 262, the District Court of NSW considered which of two innocent businesses should bear a loss caused by a business email compromise (BEC) scam.
Under an Asset Sale Agreement (ASA), Pandora agreed to buy back the assets of a jewellery store operated by MJC (one of its franchisees) for $467,378. Payment was due within five business days after completion.
Completion occurred on 5 March 2024. After MJC issued an invoice setting out its nominated bank account for payment, a fraudster used a compromised MJC email account to send Pandora false bank details. Pandora transferred the full purchase price to the fraudster's account, and from there, most of the funds were quickly dissipated and unrecoverable.
The Court considered four key questions in deciding who should bear the loss:
The ASA allowed Pandora to pay by electronic transfer into a bank account "nominated in writing" by MJC. MJC did this by issuing tax invoices that specified its NAB "MJ Concepts Kotara" account, and those invoices were passed on to Pandora's finance team.
On 7 March 2024, Pandora's finance manager emailed its Global Business Services team instructing it to pay $467,378 to the bank account shown on MJC's invoice. The Court held that MJC had validly nominated that NAB account and Pandora had accepted that nomination.
At 2.16 am on 8 March 2024 (after the nomination), unknown third parties gained access to an MJC employee's email account and sent an email from her address attaching a fake "NAB" letter that nominated different account details for an account belonging to an unrelated entity.
Pandora argued that MJC was bound by this email because it came from an MJC employee's account and that employee appeared to have authority to provide bank details.
The Court rejected that argument. It found that the employee did not send or authorise the email and that no one in MJC's business did. The email was therefore "in substance a forgery by digital means" and had no legal effect. Any authority held by the account owner applied to her genuine communications, not to messages sent by an impersonator.
The unusual timing, wording and attachment should also have prompted Pandora to verify changed bank details with MJC through a known contact method before making payment. The Court's reasoning was consistent with Mobius Group Pty Ltd v Inoteq Pty Ltd [2024] WADC 114, where the District Court of Western Australia also found that a payer is better placed to prevent the loss by properly checking the payment instructions.
Pandora argued that MJC failed to take reasonable steps to prevent or limit its loss because it did not promptly act on later emails on 8 March confirming that payment had been "processed" to a "new" MJ Concepts Kotara account. Pandora said those emails should have alerted MJC that payment was being directed to different account details.
The Court held that MJC's claim was properly an action in debt, so the usual duty to mitigate loss does not apply. It went on to find that, even if mitigation principles were relevant, MJC had not acted unreasonably: key emails about payment were either not received or seen by MJC personnel or not read in a way that exposed the fraud. MJC followed up on 14 March once it realised the money had not arrived in its NAB account. By that time, most of the funds had been removed from the fraudulent account.
Pandora also argued that MJC's failure to respond to the 8 March payment confirmation emails effectively represented to Pandora that Pandora had complied with its payment obligations under the ASA.
The Court rejected that argument. The emails did not ask MJC to verify or approve changed bank details, and MJC was unaware that payment had been sent to a third party. In light of the circumstances of the fraudulent 2.16am email and attachment, Pandora could not reasonably treat MJC's silence as assurance that the ASA had been complied with.
The Court found that MJC's NAB account was the only account validly nominated by MJC, and that the fraudulent email had no legal effect. Pandora remained liable to pay MJC under the ASA.
MJC was awarded $467,378, plus interest at 5% per year from 13 March 2024 and costs.
A business should never rely on being able to, after an unauthorised payment, freeze or recover transferred funds before they are moved on and untraceable. Preventative (rather than reactionary) steps are the best protection and mitigation.
The MJC decision highlights the growing risk of BEC scams across diverse sectors and the need for robust payment controls. Practical steps for businesses include:
1. Consider cyber‑fraud risk in contracts
Consider and negotiate clauses that allocate the risk of third‑party fraud — for example, provisions dealing expressly with losses arising from compromise of either party's systems and how those losses are to be shared or indemnified.
2. Set clear, enforced payment procedures
Specify who can provide or change bank details, how changes must be communicated, and who must approve them. Require staff to treat any change in bank details as high‑risk and to seek guidance or verify through a separate, trusted channel using known contact information.
3. Train payment and finance teams
Staff should pause and escalate instructions that:
Set a clear process/checklist for large payments.
4. Verify before paying
Never rely solely on email replies or contact details in a change request. Before releasing funds, phone a known contact on a number already on file and confirm the account name, BSB and account number.
For further advice on this topic, please contact Eva Lin at Jackson McDonald.
This article was written by, Emma Cohen, Associate, Disputes.