{"id":1151,"date":"2023-01-17T07:34:37","date_gmt":"2023-01-17T07:34:37","guid":{"rendered":"https:\/\/www.innov8fs.co.za\/blog\/?p=1151"},"modified":"2026-03-18T11:46:27","modified_gmt":"2026-03-18T11:46:27","slug":"africas-biggest-law-firm-was-just-nailed-for-not-stopping-a-r5-5-million-hack-with-r2000-a-month","status":"publish","type":"post","link":"https:\/\/www.innov8fs.co.za\/blog\/2023\/01\/17\/africas-biggest-law-firm-was-just-nailed-for-not-stopping-a-r5-5-million-hack-with-r2000-a-month\/","title":{"rendered":"Africa\u2019s biggest law firm was just nailed for not stopping a R5.5 million hack \u2013 with R2,000 a month"},"content":{"rendered":"<p><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-1152\" src=\"https:\/\/www.innov8fs.co.za\/blog\/wp-content\/uploads\/2023\/01\/3b77af99fac04b0fa4682df457bb97f8.jpg\" alt=\"\" width=\"1024\" height=\"682\" srcset=\"https:\/\/www.innov8fs.co.za\/blog\/wp-content\/uploads\/2023\/01\/3b77af99fac04b0fa4682df457bb97f8.jpg 1024w, https:\/\/www.innov8fs.co.za\/blog\/wp-content\/uploads\/2023\/01\/3b77af99fac04b0fa4682df457bb97f8-300x200.jpg 300w, https:\/\/www.innov8fs.co.za\/blog\/wp-content\/uploads\/2023\/01\/3b77af99fac04b0fa4682df457bb97f8-768x512.jpg 768w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/p>\n<ul>\n<li><strong>ENSafrica failed in its duty of care when it failed to warn a house buyer about the threat posed by hackers, says a judge.<\/strong><\/li>\n<li><strong>Judith Hawarden lost her millions after hackers changed the bank account number in a PDF emailed by the law firm.<\/strong><\/li>\n<li><strong>Cyber security at ENS could have been beefed up for as little as R2,000 a month, witnesses told the Johannesburg high court.<\/strong><\/li>\n<\/ul>\n<p dir=\"ltr\">Africa\u2019s largest law firm has been ordered to pay R5.5 million to a woman who fell victim to a syndicate that hacked her email during a property purchase.<\/p>\n<div id=\"outstream\" class=\"adblock\" data-adname=\"outstream\" data-adzone=\"\/8900\/24.com\/web\/businessinsider\" data-sizes=\"[[550,309],[632,115],[300,250],[336,280]]\" data-isfluid=\"true\" data-outofpage=\"false\" data-targets=\"{&quot;pagetype&quot;:&quot;article&quot;,&quot;breadcrumb&quot;:&quot;businessinsider\/trending&quot;,&quot;Companies&quot;:&quot;ensafrica&quot;,&quot;Topics&quot;:&quot;online security,judgements&quot;,&quot;Prime&quot;:&quot;n&quot;,&quot;accreditation&quot;:&quot;Business Insider SA&quot;,&quot;artid&quot;:&quot;6e7cc107-a661-4642-b24f-5a8d0a650ec6&quot;,&quot;template_type&quot;:&quot;Article&quot;,&quot;adname&quot;:&quot;outstream&quot;,&quot;posno&quot;:&quot;1&quot;,&quot;pos&quot;:&quot;1&quot;,&quot;Subscribed&quot;:&quot;n&quot;,&quot;PayU&quot;:&quot;n&quot;,&quot;Registered&quot;:&quot;n&quot;,&quot;Suspended&quot;:&quot;n&quot;,&quot;user_type&quot;:&quot;Anonymous&quot;,&quot;is-lifestyle&quot;:&quot;true&quot;,&quot;section&quot;:&quot;businessinsider&quot;,&quot;live&quot;:&quot;false&quot;,&quot;platform&quot;:&quot;desktop&quot;,&quot;pagename&quot;:&quot;https:\/\/www.businessinsider.co.za\/ensafrica-hit-for-bad-online-security-that-cost-a-house-buyer-r55-million-2023-1&quot;,&quot;t_ref&quot;:&quot;m24&quot;}\" data-isrefreshenabled=\"false\" data-google-query-id=\"CO7vo6WLzvwCFVI0cgodboMCQQ\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-1153 aligncenter\" src=\"https:\/\/www.innov8fs.co.za\/blog\/wp-content\/uploads\/2023\/01\/18246687100831226501.png\" alt=\"\" width=\"300\" height=\"250\" \/><\/div>\n<div data-adname=\"outstream\" data-adzone=\"\/8900\/24.com\/web\/businessinsider\" data-sizes=\"[[550,309],[632,115],[300,250],[336,280]]\" data-isfluid=\"true\" data-outofpage=\"false\" data-targets=\"{&quot;pagetype&quot;:&quot;article&quot;,&quot;breadcrumb&quot;:&quot;businessinsider\/trending&quot;,&quot;Companies&quot;:&quot;ensafrica&quot;,&quot;Topics&quot;:&quot;online security,judgements&quot;,&quot;Prime&quot;:&quot;n&quot;,&quot;accreditation&quot;:&quot;Business Insider SA&quot;,&quot;artid&quot;:&quot;6e7cc107-a661-4642-b24f-5a8d0a650ec6&quot;,&quot;template_type&quot;:&quot;Article&quot;,&quot;adname&quot;:&quot;outstream&quot;,&quot;posno&quot;:&quot;1&quot;,&quot;pos&quot;:&quot;1&quot;,&quot;Subscribed&quot;:&quot;n&quot;,&quot;PayU&quot;:&quot;n&quot;,&quot;Registered&quot;:&quot;n&quot;,&quot;Suspended&quot;:&quot;n&quot;,&quot;user_type&quot;:&quot;Anonymous&quot;,&quot;is-lifestyle&quot;:&quot;true&quot;,&quot;section&quot;:&quot;businessinsider&quot;,&quot;live&quot;:&quot;false&quot;,&quot;platform&quot;:&quot;desktop&quot;,&quot;pagename&quot;:&quot;https:\/\/www.businessinsider.co.za\/ensafrica-hit-for-bad-online-security-that-cost-a-house-buyer-r55-million-2023-1&quot;,&quot;t_ref&quot;:&quot;m24&quot;}\" data-isrefreshenabled=\"false\" data-google-query-id=\"CO7vo6WLzvwCFVI0cgodboMCQQ\">\n<p dir=\"ltr\">The hackers changed the bank account number in a PDF emailed to Judith Hawarden by ENSafrica, which was handling the conveyancing of a Johannesburg house she was buying from its client.<\/p>\n<p dir=\"ltr\">Instead of landing in the law firm\u2019s trust account, Hawarden\u2019s money ended up in the account of one of the hackers, and swiftly disappeared.<\/p>\n<p dir=\"ltr\">After the discovery of the fraud, ENSafrica wrote to Hawarden demanding the money a second time, and she sued the bank for failing in its duty of care by negligently failing to warn her about the dangers of hacking or taking precautions to prevent it.<\/p>\n<p dir=\"ltr\">Three-and-a-half years later, the Johannesburg high court ruled in favour of Hawarden on Monday, ordering the firm to pay her R5.5 million plus interest and the costs and fees of two expert witnesses.<\/p>\n<p dir=\"ltr\">Judge Phanuel Mudau said even one of ENSAfrica\u2019s own experts admitted in court that the firm could have done much more to avoid the fraud, and it could have cost as little as R2,000 a month to implement a technical solution.<\/p>\n<p dir=\"ltr\">\u201cBut for the negligent transmission of its account details and failure to warn Hawarden upfront of the inherent danger of business email compromise, she would not have suffered the loss,\u201d he said.<\/p>\n<p dir=\"ltr\">\u201c[ENS] was an expert conveyancer and was facilitating and managing the transaction. The risk of loss to Hawarden was highly foreseeable by ENS.\u201d<\/p>\n<p dir=\"ltr\">Mudau dismissed the law firm\u2019s argument that a ruling in Hawarden\u2019s favour would expose all conveyancers to claims of the same kind by third parties with whom they have no relationship.<\/p>\n<p dir=\"ltr\">\u201cENS owed at least a general duty of care to \u2026 Hawarden,\u201d he said. \u201c[This] arose from the moment it accepted the brief to act as conveyancer in the transaction. [She] depended on [ENS] to act professionally.\u201d<\/p>\n<p dir=\"ltr\">Even though evidence in court showed that in 2019 it was a \u201cnear-universal\u201d practice for conveyancers to send their banking details by email, \u201cit does not absolve [ENS] of its unsafe behaviour\u201d.<\/p>\n<p dir=\"ltr\">The firm obviously knew better, said Mudau, because its trust account investment mandate &#8211; sent to Hawarden after she made the R5.5 million payment but before the fraud was detected &#8211; \u201ccontained several warnings about business email compromise and precautions to be taken against it\u201d.<\/p>\n<p dir=\"ltr\">Mudau also made a punitive costs award against ENSafrica for including in its court files numerous documents from Hawarden\u2019s laptop that had no relevance to the case, and for breaching agreements not to take copies of these documents when it had access to her computer during the discovery process. He said this was \u201cegregious\u201d behaviour.<\/p>\n<p dir=\"ltr\">Hawarden\u2019s ordeal began when she divorced in 2019 and her husband \u00a0gave her R6 million towards the purchase of a home as part of the settlement.<\/p>\n<p dir=\"ltr\">After deciding on a house in Forest Town, she paid a R500,000 deposit to Pam Golding Properties in May. Three months later, the hackers began to intercept her emails with ENS conveyancing secretary Eftyhia Maninakis, one of which had a PDF attachment with the firm\u2019s bank account details.<\/p>\n<p dir=\"ltr\">She made the R5.5 million payment on August 22 from the Rosebank branch of Standard Bank. \u201cThe beneficiary bank, namely FNB, was unable to retrieve the misappropriated funds,\u201d said Mudau.<\/p>\n<p dir=\"ltr\">ENS\u2019s letter the following month requesting a replacement payment contained a warning urging Hawarden to telephonically verify the firm\u2019s banking details before making the payment, and it emerged in court that this had been added in response to the August fraud.<\/p>\n<p dir=\"ltr\">Anton van &#8216;t Wout, an expert in digital forensics who testified on Hawarden\u2019s behalf, gave a demonstration in court which Mudau said \u201cshowed the ease with which an email and PDF attachments could be spoofed and altered, the inherent insecurity of email, and alternative, safer ways of communicating sensitive information, including used a secure portal in conjunction with two-factor authentication\u201d.<\/p>\n<p dir=\"ltr\">Attorney Mark Heyink, who specialises in IT law and organisational security safeguards, told the court that ENS\u2019s witness statements revealed \u201cinadequate awareness\u201d among its staff of business email compromise.<\/p>\n<p dir=\"ltr\">When she testified, Maninakis said she did not know PDFs could be manipulated until Hawarden\u2019s loss occurred, and Mudau said this showed her training and awareness of the dangers of hacking were \u201chopelessly inadequate\u201d. ENS conveyancer Arshaad Carrim said he could not recall receiving training in cyber security.<\/p>\n<p dir=\"ltr\">\u201cViewed objectively, [Hawarden] cannot be faulted for placing her trust in [ENS], which she knew was a very large and reputable law firm,\u201d said Mudau. \u201cOn her version, which I accept and cannot fault, she did not think she needed to seek advice as she was dealing with a law firm whose reputation went before it.<\/p>\n<p dir=\"ltr\">\u201cHer case established clearly that sending bank details by email is inherently dangerous, and so must either be avoided in favour of, for example, a secure portal, or must be accompanied by other precautionary measures like telephonic confirmation or appropriate warnings which are securely communicated. Secure portals were available in 2019 and would have averted the fraud.<\/p>\n<p dir=\"ltr\">\u201cENS is best placed to understand and prevent business email compromise. Individuals in society are generally not as well-placed to respond to the ever-evolving threat of cyber crime, which is sophisticated and technical in nature.\u201d<\/p>\n<p dir=\"ltr\">In October 2021, the\u00a0Mail &amp; Guardian\u00a0reported that Bukelwa Kwinana,\u00a0Robert Asamoah and Thembani Maswanganyi\u00a0appeared in the Johannesburg specialised commercial crimes court in connection with the Hawarden fraud. They faced charges of fraud, forgery, uttering and contravention of the Prevention of Organised Crime Act.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>ENSafrica failed in its duty of care when it failed to warn a house buyer about the threat posed by hackers, says a judge. Judith&hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[],"class_list":["post-1151","post","type-post","status-publish","format-standard","hentry","category-innov8ions"],"_links":{"self":[{"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/posts\/1151","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/comments?post=1151"}],"version-history":[{"count":1,"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/posts\/1151\/revisions"}],"predecessor-version":[{"id":1154,"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/posts\/1151\/revisions\/1154"}],"wp:attachment":[{"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/media?parent=1151"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/categories?post=1151"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.innov8fs.co.za\/blog\/wp-json\/wp\/v2\/tags?post=1151"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}