Business Email Compromise Losses: Fraudsters as the Effective Cause Where a Confidentiality Clause Does Not Assume Responsibility for Payment Fraud
1) Introduction
Logix Aero Ireland Ltd v Siam Aero Repair Company Ltd [2026] EWCA Civ 510 is a Court of Appeal decision about
contractual causation in the context of “man-in-the-middle” email interception fraud (business email compromise).
The appellant buyer (Logix) was deceived into paying US$824,900 to a Vietnamese account controlled by fraudsters,
instead of paying the respondent seller (Siam Aero) in Thailand, during negotiations and execution of aircraft engine sale documents.
The only claim pursued on appeal was a damages claim said to arise from breach of a binding confidentiality clause
contained in an otherwise largely non-binding Letter of Understanding (the “LOI”).
The High Court struck the claim out under CPR 3.4(2)(a) as disclosing no reasonable grounds, holding that—even if there was an arguable
breach—the breach did not cause the loss because the fraudsters’ intervention broke the chain of causation.
The appeal (permission limited to causation) argued that the High Court wrongly distinguished
London Joint Stock Bank Limited v Macmillan and Arthur [1918] AC 777.
2) Summary of the Judgment
The Court of Appeal (Phillips LJ, with Peter Jackson LJ and Cockerill LJ agreeing) dismissed the appeal.
It held that, on the undisputed email record:
-
even assuming Siam Aero breached the confidentiality clause by sending documents/information to the fraudsters,
that breach was not an effective (dominant) cause of Logix’s loss;
-
the fraudsters’ intervention was the independent and effective cause of the mistaken payment,
such that the breach was at most part of the opportunity for the fraud, not the legal cause of the loss;
-
Macmillan did not assist Logix: it is not a general rule that fraud/forgery never breaks the chain of causation;
it turns on a specific duty (there, a customer’s duty to its bank when drawing cheques) directed at preventing the very fraud that occurred.
Because the appeal failed on causation, the Court did not need to determine the respondent’s other grounds for upholding the strike-out.
3) Analysis
3.1 Precedents cited (and how they shaped the outcome)
(a) Strike-out / summary judgment threshold
-
Begum v Marcan (UK) Limited [2021] EWCA Civ 326 and
Altimo Holdings v Kyrgyz Mobil Tel Ltd [2011] UKPC 7, [2012] 1 WLR 1804:
the Court accepted that the strike-out and summary judgment tests converged in this context: whether the claim was
“bound to fail”. This matters because the email chain was fully documented and essentially undisputed,
making causation suitable for determination at the interlocutory stage.
(b) Intervening acts and “breaking the chain of causation”
-
Galoo v Bright Grahame Murray [1994] 1 WLR 1360:
critical authority for the distinction between (i) a breach that causes the loss and (ii) a breach that merely gives the
opportunity for loss. The Court of Appeal applied this framework to hold that Siam Aero’s assumed breach was not the effective cause;
it was one step in a fraud whose operative cause was the fraudsters’ deception and Logix’s mistaken payment.
-
Monarch Steamship Co. Ltd. v. Karlshamns Oljefabriker (A/B) [1949] A.C. 196 and
Quinn v Burch Bros. (Builders) Ltd [1966] 2 QB 370:
used (via Galoo) to support the “effective/dominant cause” inquiry and the need to distinguish cause from occasion.
-
Armstead v Royal & Sun Alliance Insurance Co Ltd [2024] UKSC 6, [2025] AC 406:
cited for conceptual clarity—separating factual (“but for”) causation from “legal causation” where a later, significant cause combines with
the earlier breach. Although a tort case, it provided a modern articulation of the “new intervening cause” question that the Court treated as
analytically helpful in contract.
(c) Scope of duty and remoteness as neighbouring controls
-
Transfield Shipping Inc v Mercator Shipping Inc (The Achilleas) [2008] UKHL 48, [2009] 1 AC 61:
cited to frame the idea that, even where “but for” causation exists, the defendant may not have assumed responsibility for the type of loss.
Although the Court decided the appeal on “effective cause”, it observed that scope-of-duty and remoteness would also have been problematic for Logix.
-
Hadley v Baxendale (1854) 9 Ex. 341:
referenced as the classic remoteness test (loss arising “in the usual course of things”).
(d) Concurrent effective causes
-
Heskell v Continental Express Ltd [1950] 1 All ER 1033:
authority that there can be more than one effective cause and that an earlier breach may remain causative even if a later event contributes.
Logix relied on a “necessary stage” type of argument; the Court rejected this on the facts, treating the fraud as destroying the causative potency
of the assumed breach.
-
County Ltd. v Girozentrale Securities [1996] 3 All ER 834:
used to underline that one does not discard a causative breach merely because another factor is also effective, or even more effective.
Nonetheless, the Court held that this was a case where the fraud displaced (rather than merely competed with) the assumed breach.
-
Stacey v Autosleeper Group Ltd [2014] EWCA Civ 1551 and
Borealis v AB Geogas Trading SA [2010] EWHC 2789 (Comm), [2011] 1 Lloyd's LR 482:
cited for the “destroying causative potency / obliterating wrongdoing” formulation. The Court treated this as descriptive of what happened here:
the fraud scheme both preceded and drove the assumed breach and then culminated in payment without Siam Aero’s involvement.
(e) The central authority debated: forged intervention and causation
-
London Joint Stock Bank Limited v Macmillan and Arthur [1918] AC 777 (and its foundation case Young v Grote (1827) 4 Bing. 253):
Logix argued Macmillan stood for a broad principle that criminal intervention does not break causation where the defendant’s act created the opportunity.
The Court of Appeal rejected that reading, emphasising that Macmillan is anchored in a
specific contractual duty in the banker–customer relationship: the customer must draw cheques with reasonable precautions to prevent
the very kind of alteration that occurred. In that setting, the fraud was “a very natural consequence” of the breach, within the scope of duty,
and not too remote.
3.2 Legal reasoning
(a) The Court accepted “but for” causation but rejected legal responsibility
The Court proceeded on the basis (undisputed on appeal) that “but for” causation was satisfied:
if Siam Aero had not sent the relevant documents/information, the fraud would not have played out in the same way.
However, satisfying “but for” causation did not determine whether the breach was an effective cause in law.
(b) Why the fraud broke the chain on these facts
The Court’s key factual/legal synthesis was that the fraudsters’ intervention:
-
began before the assumed confidentiality breach (the fraudsters had already inserted themselves into the correspondence);
-
was the cause of the assumed breach (Siam Aero sent materials to the fraudsters because it was deceived as to the recipient);
-
remained the operative driver of events, with the decisive final step—Logix’s payment to the wrong account—occurring
without Siam Aero’s involvement.
On that basis, Siam Aero’s assumed breach was characterised as part of the “opportunity” landscape, not the legal cause of the loss.
The fraud did not merely join as a concurrent cause; it displaced the breach’s causative potency.
(c) Why Macmillan was properly distinguished
The Court treated Macmillan as a case where the contractual duty was directed at preventing the very fraud that materialised.
By contrast, the LOI confidentiality clause here was “primarily concerned” with preventing commercial harm from information leakage
(e.g., competitors gaining advantage), not with allocating the risk of sophisticated payment redirection fraud.
In short: Macmillan did not create a general rule that criminal acts never break the chain. Rather, it illustrates that where the defendant has
assumed a duty specifically to guard against the intervening fraud, the fraud may be treated as a natural consequence, within scope and not remote.
That contractual architecture was absent here.
3.3 Impact
-
Confidentiality clauses and payment-fraud losses: the decision signals that a standard confidentiality clause (even if binding in an
otherwise non-binding LOI) will not readily be construed as transferring the risk of business email compromise payment loss to the party whose
documents were intercepted—particularly where the fraudster’s deception is the dominant cause.
-
Limits of Macmillan in modern fraud: the Court of Appeal has clarified that Macmillan is not a broad “fraud never breaks causation”
authority; it depends on a specific duty to prevent the particular intervention.
-
Interlocutory disposal in fraud-related contract claims: where the documentary record is complete and the causation question is
legally determinative, courts may be prepared to strike out/summarily dispose of claims even in fact-sensitive fraud scenarios.
-
Drafting and risk allocation: commercial parties seeking protection against payment redirection fraud may need express contractual
mechanisms (verification procedures, change-of-bank-details protocols, warranties, indemnities, allocation of cyber-fraud risk), rather than relying
on confidentiality wording.
4) Complex concepts simplified
-
“But for” causation: a factual test—would the loss have happened “but for” the breach? The Court treated this as satisfied (at least
arguable) but insufficient.
-
Effective/dominant cause (legal causation): a legal attribution question—should the breach be treated in law as responsible for the loss,
or did something else (here, intentional fraud) supersede it?
-
Breaking the chain of causation: where an intervening event is so independent and significant that the law treats it as the real cause,
meaning the earlier breach no longer grounds damages for that loss.
-
Scope of duty (assumption of responsibility): asks what types of loss the contract-breaker should be taken to have accepted responsibility for.
Even if there is causation in fact, the claimed loss may fall outside that scope.
-
Remoteness: whether the loss was sufficiently foreseeable/within contemplation under Hadley v Baxendale (1854) 9 Ex. 341.
5) Conclusion
[2026] EWCA Civ 510 confirms that, in contract, meeting “but for” causation does not answer whether a defendant is legally responsible for a loss
where a third-party fraud intervenes. In business email compromise scenarios, a confidentiality breach (even if arguable) may be treated as merely providing
occasion for the fraud, with the fraudsters’ deception breaking the chain—unless the contract is properly construed as imposing a duty aimed at preventing
that very fraud. The decision also narrows the practical reach of London Joint Stock Bank Limited v Macmillan and Arthur [1918] AC 777 to its
duty-specific context, rather than as a general causation override whenever criminality intervenes.