Cause and effect: Court of Appeal confirms fraudsters’ intervention can break the chain of causation

As business email compromise fraud continues to evolve in scale and sophistication, the Court of Appeal’s decision in Logix Aero Ireland Ltd v Siam Aero Repair Company Ltd [2026] EWCA Civ 510 provides guidance on where legal responsibility begins and ends. The Court concluded that the actions of sophisticated fraudsters constituted an intervening event, breaking the chain of causation between the alleged contractual breach and the loss suffered.

The judgment offers a reminder that, even in disputes arising from complex cyber-enabled frauds, courts will continue to apply conventional principles of causation and contractual risk allocation. 

Background

During negotiations as part of a transaction, unknown fraudsters succeeded in infiltrating the parties’ email communications. Using deceptive email domains and manipulated correspondence, they inserted themselves between the buyer, Logix Aero Ireland Ltd (Logix), and the seller, Siam Aero Repair Company Ltd (Siam Aero). Genuine communications were intercepted, altered and retransmitted, enabling the fraudsters to replace authentic payment details with information for an account under their control. 

As a result, Logix transferred the purchase monies to a bank account controlled by the fraudsters rather than to the seller’s. By the time the deception was uncovered, the funds had been dissipated. 

Logix pursued a number of claims against Siam Aero. By the time of the appeal, the only surviving claim was an allegation that Siam Aero had breached a confidentiality provision contained in a Letter of Understanding. The essence of the claim was that Siam Aero had disclosed confidential information and documents to the fraudsters, albeit unknowingly, and that this breach ultimately caused Logix’s loss. 

The High Court struck out the claim. It accepted that Siam Aero had an arguable case to answer on whether its communications with the fraudsters breached the confidentiality clause. However, it held that any such breach did not legally cause Logix’s loss. The fraudsters caused the loss through their own independent actions, which broke the chain of causation between Siam Aero’s actions and Logix’s loss. The Court of Appeal agreed. 

Breaking the chain of causation 

The central issue was whether Siam Aero could be held liable for damages notwithstanding the intervention of third-party fraudsters between its assumed breach of contract and the loss. 

The Court of Appeal concluded that the fraudsters’ conduct was the true cause of the loss. Their intervention involved multiple deliberate and independent acts, including intercepting communications, manipulating transaction documents, altering banking information and inducing Logix to transfer funds to an account controlled by them. The loss ultimately resulted from those fraudulent acts rather than from Siam Aero’s alleged disclosure of information. 

It was noted that the fraudsters had already placed themselves within the communications chain before the alleged breach occurred. In that sense, the fraudsters’ intervention was not merely a consequence of the breach but the effective cause of Logix’s loss.  

Providing an opportunity is not the same as causing a loss

One of the most significant aspects of the judgment is its treatment of the relationship between opportunity and causation.

The court accepted that the alleged disclosure may have been one of the events which enabled the fraud to succeed. However, it rejected that creating an opportunity for fraud is necessarily equivalent to causing the resulting loss. 

That distinction is particularly important in cases involving cyber-enabled fraud. Businesses routinely exchange information and documents electronically. If every inadvertent disclosure that assisted a subsequent fraud were treated as the legal cause of resulting losses, the scope of contractual liability could become extremely wide. The Court of Appeal’s decision draws a clear boundary by requiring claimants to establish a more direct causal connection. The courts can be slow to impose liability where a party’s conduct is merely part of the background to a fraud, rather than its legal cause.

Scope of duty remains critical

The judgment also reaffirms that, as a matter of the scope of the duty, loss caused by the intervention of a third party may not be regarded as the type or kind of loss in respect of which the contract breaker had assumed responsibility. 

The confidentiality clause in issue was directed towards preventing the disclosure or misuse of commercially sensitive information. It did not impose a special duty to protect the other party from being deceived by fraudsters. 

This aspect of the decision will be particularly relevant when parties seek to rely upon confidentiality provisions, data-protection obligations or information security clauses as a basis for recovering fraud losses. The precise purpose of the contractual obligation will remain central to the analysis. 

Practical implications

The decision has a number of practical implications for businesses. In an age of increasing cybercrime, it is crucial to ensure that transactions are underpinned by robust verification processes (such as always confirming bank details by telephone). Moreover, businesses should have clear anti-fraud policies, together with fraud prevention training, to ensure they are doing all that they can to prevent costly mistakes. There may be warning signs for employees to spot when a potential fraud is brewing.  

When negotiating contracts, it is worth businesses giving proper thought to the allocation of cybercrime-related risk. Logix Aero v Siam Aero suggests that ordinary confidentiality clauses are unlikely to offer protection against losses caused by fraud. It may therefore be worth including express provisions to deal with the verification of payments, cybercrime risks or other protections against fraud. 

Subcribe to news and views

Related page