Skip to section content

Dubai & DIFC / Insights

Corporate & Commercial Law

Your Email Was Hacked and the Bank Paid: Who Bears the Unauthorised Transfer?

By Advocate Sharan Jain September 21, 2026

Your Email Was Hacked and the Bank Paid: Who Bears the Unauthorised Transfer?

A DIFC bank hacked-email payment dispute does not end with the bank saying the instruction came from your usual address. The questions include whether it was authorised, what the banking contract says and what warning signs were available before payment. The customer does not automatically bear the loss merely because its mailbox was compromised.

Act promptly to contain the incident and ask the bank about stopping or recalling the payment. At the same time, preserve the evidence needed for the liability dispute. This guide concerns forged instructions considered in DIFC litigation. It does not promise reimbursement or apply the same analysis to a transfer that you personally authorised after being deceived.

IssueEvidence to preserveQuestion it answers
AuthorityMandate, signatory rules and original instructionDid the customer actually approve this payment?
AuthenticityEmail headers, mailbox logs and attachmentsHow was the purported instruction created and sent?
Bank checksUsual process and transaction recordsWhat was different before payment?
Risk allocationExecuted indemnity and facility termsWhat conduct and risk does the clause address?
LossAccount entries, recovered funds and expense proofWhat remains lost, charged or owed?

What makes a DIFC bank hacked-email payment different from an authorised scam?

Begin with who gave the instruction. In a forged-instruction case, the customer says it never approved the transfer. A different case arises where the customer genuinely instructs the bank but does so because a fraudster deceived it. Do not describe both simply as fraud and assume that one judgment answers both.

In Aegis Resources DMCC v Union Bank of India (DIFC Branch) [2020] DIFC CFI 004, the Court addressed fraudulent instructions sent through a hacked customer email system. Its July 2021 reasons placed the loss on the bank on the facts established. That was a DIFC decision concerning the bank's DIFC branch, not a general rule for every bank or every fraud.

Give your adviser a precise account of what the authorised signatory did. Did the person sign anything, approve a portal request, speak to the bank or discover the transfer only afterwards? Preserve the answers even if they complicate the proposed claim. A forged signature and a genuine signature obtained through deception require different factual explanations.

If staff recall an approval call, identify the caller, number used and person who answered. Do not assume that the appearance of a familiar number proves identity. Equally, do not assume that every genuine internal approval was compromised. The objective is to identify the actual authorisation path before choosing a legal theory.

Does the usual email address settle the bank's defence?

No single feature should replace examination of the whole record. Compare the disputed transaction with the established payment process. Was there normally an accompanying call, a second communication or supporting trade documents? Was the beneficiary new? Did the purpose fit the customer's known business and the facility's agreed use?

Aegis considered departures from the established process, unusual transaction content and the absence of information connecting payments to the facility. The Court assessed what should have prompted inquiry at the time. It did not require the bank to have the benefit of the later forensic investigation.

Prepare a comparison using several genuine transactions close in time. Include an inconvenient comparator if it shows that an allegedly unusual feature had happened before. A reliable analysis explains the normal range of activity, rather than selecting one ideal payment as the only possible standard.

Ask the bank to identify the checks it actually performed on each disputed payment. Keep a distinction between a written procedure, a witness's description of usual practice and the record of what happened on this occasion. They may support each other, but they are not interchangeable.

Common mistake. Building the entire claim around the fact that the beneficiary was new. Explain the combined warning signs and what the bank could see before payment, without relying on hindsight.

What if I signed an email or fax indemnity?

Obtain the executed version and read it with the account and facility terms. A document headed fax instructions may contain wider language about electronic communications. Conversely, a broad heading does not answer whether a specific protection covers the particular event or the bank's own conduct.

Aegis examined the protective provisions individually. Their effect could not be reduced to the slogan that all fraud risk belonged to the customer. The Court's treatment depended on the wording and its findings about the bank's conduct. The result is not a rule that every email indemnity is invalid.

Annotate the clause by separating its trigger, protected conduct, conditions and exceptions. Does it concern inconsistency between oral instructions and later confirmation, transmission errors, apparent authority or negligence? Ask the bank which provision it relies on and why it says that provision applies to these facts.

Keep amendments and onboarding records. If the bank supplies a later standard form, ask whether that was the version incorporated into your relationship at the relevant date. Avoid arguing solely from current website terms when the transfer occurred under an earlier signed facility.

These three questions help organise the first legal review.

Actual authority

Identify what the customer genuinely instructed or approved. Keep the instruction question separate from the appearance of a familiar address or signature.

Contractual protection

Read the executed protection clause and its conditions. Do not assume that a document's title resolves its scope or legal effect.

Available warning signs

Compare the disputed payment with normal practice and the facility. Focus on information available before payment rather than later discoveries alone.

Will the customer be blamed for weak email security?

Expect the issue to be investigated rather than assuming either that it is irrelevant or that it defeats the claim. Preserve the security configuration, service-provider engagement, incident reports and relevant training records from the time of the incident. A current improved system does not prove what was in place earlier.

Aegis rejected contributory negligence on the evidence before it. Its assessment concerned the customer and security arrangements at the relevant historical time. Do not use that finding as present-day approval for any particular security setup, or as an assurance that a customer can ignore known security risks.

Ask a suitable technical professional to distinguish established facts from hypotheses about the compromise. Which account was accessed, which settings changed and which logs support the sequence? Preserve the original data before relying on a narrative report. If a log was unavailable, say so instead of treating absence of evidence as proof that access never happened.

Containment and preservation need coordination. Ask the technical team to record the changes it makes while securing the system, so that necessary remedial work does not leave everyone guessing about the previous state. This is evidence preparation, not a substitute for an incident-response professional's security advice.

Can I recover business losses as well as the transfer?

Separate the unauthorised debit or borrowing from consequential loss. If the payment used a credit facility, the immediate dispute may concern an alleged debt owed to the bank rather than repayment of cash previously deposited by the customer. Reconcile the account entries and any money recovered before stating the remedy sought.

The 23 August 2021 final order in Aegis declared that the customer need not repay the outstanding balance attributable to the disputed sums and provided for damages and interest. The reasons rejected an unsupported lost-trading-profit calculation while accepting particular management-time and travel losses. Success on the transfer did not establish every additional loss claimed.

For your file, list each loss separately with its amount, date, supporting document and alleged causal link. Distinguish money paid, income allegedly missed and liabilities still disputed. Do not count a recovered sum as still missing or claim the same expense under two headings.

A management-time claim needs more than a senior employee's frustration. Record what work the person was diverted from, what incident-related tasks were performed and how the calculation was made. For alleged lost trading, identify the actual opportunity and the evidence that the unavailable funds caused it to be lost. A margin applied to a headline transfer amount does not supply those missing facts.

Should I complain to the bank, the regulator or the Court?

These routes have different purposes. Start by giving the bank a clear incident report and asking for its response and recovery steps. Keep the complaint reference, chronology and supporting records. Do not confuse an acknowledgment of the complaint with acceptance of legal liability.

The DFSA complaints guidance describes the regulator's remit and encourages dealing directly with the firm. Whether a regulatory complaint falls within that remit needs separate consideration. A complaint is not itself a civil judgment requiring the bank to pay the amount you demand.

Ask your adviser about the proper civil forum, governing law and relevant deadlines independently of the complaint process. This article does not determine jurisdiction merely from the presence of the word Dubai in an account address. Nor should ongoing complaint correspondence be assumed to stop a separate legal deadline.

If court proceedings follow, RDC 28.1-28.2 includes electronic communications and metadata within its document framework. Preserve original emails and logs as well as readable copies. This does not create an unrestricted right to inspect the bank's systems or unrelated customer information.

What should the first evidence pack contain?

Organise a concise pack before writing a lengthy accusation. Begin with the disputed payment, the authority position and the contract. Put technical and financial records behind that summary with stable references. A reviewer should be able to locate the original document supporting each factual statement.

  1. Identify each disputed payment and the exact account entries.
  2. Preserve the original instruction, attachments, headers and available logs.
  3. Collect the executed mandate, facility terms and relevant indemnity.
  4. Compare genuine payments and the established confirmation process.
  5. Record when the fraud was discovered and each request to stop or recall funds.
  6. Reconcile recoveries, disputed borrowing, expenses and any claimed further loss.
  7. Obtain advice on current law, forum and deadlines before making admissions or settling.

Keep the work divided into three practical files so that urgent recovery activity does not obscure the liability evidence.

Incident record

Preserve what was sent, when the compromise was discovered and what containment occurred. Mark technical conclusions that remain provisional or unsupported.

Banking record

Collect the mandate, agreed payment process and transaction history. Ask what checks were actually performed on each disputed instruction before execution.

Loss record

Track account adjustments, recoveries and separate expense claims. Tie each alleged business loss to evidence rather than multiplying the missing amount by a margin.

Selected official sources were checked on 29 September 2026. The later-history search located the final August 2021 order but did not certify the complete docket or all later treatment. Aegis is used here for its fact-specific forged-instruction analysis, not as a comprehensive statement of current law on every payment scam.

Key takeaway. Preserve the authority question, the banking process and the loss calculation separately. A familiar email address is evidence to investigate, not a complete answer to who bears the loss.

Frequently Asked Questions

Does my hacked mailbox automatically make me liable? No. The contract, authority, bank conduct and facts require examination. Aegis placed the loss on the bank on its particular evidence.

Does Aegis guarantee a refund for an authorised scam payment? No. Its facts concerned forged instructions. A genuine customer instruction induced by deception needs a separate current-law assessment.

Is an email indemnity always unenforceable? No. Review the executed wording, its conditions and the conduct it addresses.

Does every new beneficiary require the bank to refuse payment? That is not the proposition advanced here. Examine the combined circumstances and the bank's obligations, without hindsight.

Can the bank investigate my security arrangements? They may be relevant to its defence. Preserve the historical evidence and obtain advice on any requested disclosure.

Can I claim lost profits without supporting transactions? Aegis rejected an unsupported trading-loss calculation. Identify the actual opportunity, causation and evidence for your own claim.

Will a DFSA complaint itself recover the money? It is not a civil money judgment. Assess the complaint route and any civil remedy separately.

Should I delete the fraudulent messages after reporting them? Preserve originals and coordinate secure handling with the incident-response team. Screenshots alone may omit useful technical evidence.

This article is for general informational purposes only and does not constitute legal advice. Consult a qualified advocate for advice on your specific situation.

References

Matters before the DIFC Courts are conducted by the firm, with counsel from its panel of DIFC-registered advocates engaged for the hearing. The firm acts as counsel in arbitrations seated in the DIFC and the wider UAE, and conducts the Indian proceedings that follow, including enforcement of UAE awards and judgments in India. This section is legal information, not legal advice.

All Dubai and DIFC guides