The First Applicant, a private company, sought to purchase a motor vehicle from the First Respondent, a car dealership. The Second Applicant, a director of the First Applicant, paid a deposit of R172,502.12 into a bank account, the details of which were provided by the First Respondent's salesperson and business manager via email. The First Respondent denied receiving the deposit, alleging that a cybercriminal had intercepted and altered the email communications, directing the deposit into a fraudulent third-party account. The Third Respondent, a bank, had approved financing and settled the balance of the purchase price. The First Respondent retained possession of the vehicle, refusing to release it until the deposit was paid again. The Applicants brought an urgent application for an interim interdict compelling the First Respondent to release the vehicle pending the outcome of a police investigation.
The application is dismissed with costs, including the costs of Counsel on the 'B' scale.
A purchaser who pays a deposit into a fraudulent bank account following a business email compromise is not entitled to interim or final interdictory relief for the release of the vehicle, as the dispute over liability for the diverted deposit cannot be properly resolved through interdictory proceedings. Ownership of the vehicle must be established to claim vindicatory relief, and a court will not grant an interdict where the final relief sought depends on an uncertain future event such as a criminal investigation.
The court noted that the email compromise probably occurred on the side of the First and Second Respondents, who failed to conduct a credible investigation into their systems. The court also expressed concern about the lack of clear procedural rules for admitting and testing expert evidence in application proceedings involving cybercrime. The court commented that, had the deposit been received, ownership would have passed to the Third Respondent as financier, and the Applicants would have had a right to possess the vehicle.
This case illustrates the legal complexities arising from business email compromise in commercial transactions, particularly where a purchaser acts on compromised payment instructions. The judgment highlights the tension between a purchaser's duty to verify banking details and a seller's duty to secure its email systems. It also confirms that an interdict is an inappropriate procedural vehicle to resolve the substantive dispute over liability for a cyber-fraud loss where ownership has not passed. The case emphasizes the importance of procedural precision in motion proceedings and the need for expert evidence on the origin of email compromise.