The successful appeal (Edward Nathan Sonnenberg Inc v Hawarden 2024 (5) SA 9 (SCA)) to the Johannesburg High Court – which initially held a law firm liable for a R 5,5 million cybercrime loss – has brought temporary relief to legal practitioners. However, this ruling does not eliminate the ever-present threat of cybercrime targeting conveyancers and their clients. The reality remains: fraudsters continue to exploit vulnerabilities in electronic payments, leaving victims financially devastated. 

The problem: How business e-mail compromise (BEC) works

Most cybercrime in property transactions occurs through BEC. Here is how it typically unfolds:   

  • A conveyancer e-mails the client with legitimate trust account details for the property purchase payment.  
  • Fraudsters intercept the e-mail and alter the banking details to their own.  
  • The client, unaware of the manipulation, initiates the payment.  
  • Despite the recipient name and account number not matching, the bank processes the transaction, allowing the funds to land in the criminal’s account.  

The result? Millions lost, reputations damaged, and legal battles ensue – all because banks currently do not verify payee name-account alignment.

The solution: A simple but powerful banking safeguard

To prevent 95% of these fraud cases, banks must implement the following policy:  

Online transfers must be blocked if the recipient’s name and account number do not match. A warning must pop up, prompting the payer to double-check details and alerting them to potential fraud – even if just one letter is incorrect or a nickname is used.

Why this works
  • Instant fraud detection: If a fraudster changes account details but not the conveyancer’s name, the bank’s system will flag the mismatch and halt the transaction.  
  • Minimal disruption, maximum protection: This adds only a small verification step for users but massively reduces fraud risk.  
  • Global precedent: Many leading banks worldwide already use name-checking systems (eg, the United Kingdom’s ‘Confirmation of Payee’), drastically cutting BEC fraud.  
Call to action 

This is not just a suggestion – it is a necessary security upgrade. Banks, regulators, and legal bodies must collaborate to enforce this change before more victims suffer preventable losses. Conveyancers are presently incurring prohibitive cybercrime insurance, cyber security and safeguards costs, and the sooner the banks implement the above safeguard, conveyancers and members of the public will save costs and prevent them from being victims of cybercrime.

The question is no longer if this should be implemented – but why it has not been done already?  

‘Nevertheless, the safeguards and cyber security measures put in place by conveyancers and the recipients of electronic payments remain essential protection mechanisms and should not be discarded. The judgment is a helpful reminder that the responsibility to guard against cyber fraud is mutual.  Purchasers and any persons making electronic payments should also educate themselves about the risk of cyber fraud and take care when making electronic payments’ (Daniel Breier (www.financialinstitutionslegalsnapshot.com, accessed 1-7-2025)).

Fazel Bulbulia BProc (UKZN) is a legal practitioner, conveyancer, and notary public at Mohamed Hassim Attorneys in Durban.

This article was first published in De Rebus in 2025 (Aug) DR 18.

 

The post Business e-mail compromise: A critical solution to protect attorneys, conveyancers, and the public appeared first on De Rebus.