AT A GLANCE
Case
Intengo Imoto (Pty) Ltd v Zoutpansberg Motor Wholesalers CC 2025(6) SA 143 (SCA)
Bottom line
EFT payment is only good once it lands in the creditor's correct account — the paying party carries the risk of interception.
A problem that we are regularly contacted about or hear about relates to payments made by parties into the incorrect bank account. The most common scenario is that a consumer/ purchaser receives an email attached to an invoice from a supplier/ seller for payment little knowing that the email has been sent by a hacker posing as the supplier/ creditor. Payment is then made by the consumer/ purchaser in good faith into that account reflected on the invoice. On many occasions, eye- watering payments are paid. When the actual supplier/ creditor advises that the payment has not been received, it descends into a blame game as to where and how the hacking emanated. The consumer/ purchaser insists that its payment is good and that it was the supplier/ creditor's fault, which had supposedly enabled the hacker to pose as the supplier/ creditor. The supplier/ creditor denies this in a heartbeat, and it goes downhill from there. IT specialists are called in to try trace where the problem emanated and whose server is somehow to blame. This is all fertile grounds for disputes and the destroying of business relationships.
The Supreme Court of Appeal made a definitive ruling as far back June 2025 in the matter of Intengo Imoto (Pty) Ltd v Zoutpansberg Motor Wholesalers CC 2025(6) SA 143 (SCA) and yet we find that much uncertainty in relation to liability arising from hacking still persists.
As a result, we deemed it necessary to prepare this short memorandum on this judgement to inform clients yet again of the importance thereof and setting out squarely where liability in relation to hacking starts and ends.
The facts
Intengo Imoto (Pty) Ltd, trading as Northcliff Nissan, sold two vehicles to Zoutpansberg Motor Wholesalers CC, trading as Hyundai Louis Trichardt, for R145,000 each. Intengo's invoices specified its FNB account for payment by electronic funds transfer (EFT). A cybercriminal intercepted the email correspondence between the parties and altered the banking details on the invoice. Hyundai paid into the fraudulent account, genuinely believing it was paying Intengo. Intengo never received the funds and sued Hyundai for the purchase price. Hyundai's defence was that it had already paid.
The legal question
When a party (eg, the consumer/ purchaser) pays into the wrong account because hackers intercepted and altered the invoice, has that party discharged its payment obligation to the other party (eg, the supplier/ seller).
What the SCA decided
The short answer is- No. The Supreme Court of Appeal confirmed that an EFT payment obligation is only discharged once the funds actually reach the creditor's correct account. Because Hyundai had not verified the banking details before paying, it had not performed its obligation under the sale agreement, regardless of its bona fide belief that it was paying the seller. Hyundai remained liable for the full purchase price.
The “golden thread” running through the authorities
The Court described this outcome as part of a consistent line of authority, holding that a consumer/ purchaser must verify the banking details of the supplier/ seller on an invoice before paying. Failure to do so does not extinguish the underlying debt. It simply means the purchaser has paid the wrong party and still owes the original debt to the supplier/ seller.
On the burden of proof
The SCA also confirmed upon whom the onus of proof lay in such instances. Where a debtor (consumer/ purchaser) asserts that it has already paid, it is the debtor who bears the onus of proving, on a balance of probabilities, that valid payment was made to the creditor (supplier/ seller). Payment into the incorrect account is however not proof thereof.
Why this matters for you
- If you send or receive payment instructions by email in the ordinary course of business, this case confirms that the risk of interception falls on the party making payment, not the party awaiting it.
- A genuine, good-faith payment into a fraudulent account does not discharge your obligation to pay. You may find yourself liable to double payment. Once to the hacker, which is may be unrecoverable depending on your bank, and again to the actual creditor.
- Courts expect simple, practical precautions before paying telephonically verify banking details with a known contact at the counterparty (never using a number taken from the email itself).
- This decision sits alongside the SCA's related judgment in ENS Africa v Hawarden, which confirmed that creditors generally owe no legal duty to protect debtors from this type of fraud, reinforcing that the responsibility to verify sits squarely with the paying party.
Our recommendation
Before making any payment based on banking details received by email, verify those details telephonically through an independently sourced number, not one taken from the email or attached invoice. request a bank account letter verification from the supplier/seller and treat any last-minute change to previously confirmed account details as a red flag.
Should you have any queries regarding this update, please do not hesitate to contact our offices.
Director | Maurice Phillips | Wisenberg
BA LLB (UCT) | Arbitrator | Association of Arbitrators (Southern Africa)
antony@mpw.co.za
|
+27 21 419 7115
|
+27 83 300 4364
Disclaimer: This article is the personal opinion/view of the author(s) and does not necessarily present the views of the firm. The content is provided for information only and should not be seen as an exact or complete exposition of the law. Accordingly, no reliance should be placed on the content for any reason whatsoever, and no action should be taken on the basis thereof unless its application and accuracy have been confirmed by a legal advisor. The firm and author(s) cannot be held liable for any prejudice or damage resulting from action taken based on this content without further written confirmation by the author(s).