Cybercrime

Business E-Mail Compromise

Who is liable – and when does a GDPR reporting obligation apply?

ATB.LAW Attorneys at Law in Vienna specializes in cybercrime, IT law, data protection, and crypto-asset law, assisting companies with Business Email Compromise (BEC) incidents from initial assessment to judicial enforcement or defense of claims.

Business Email Compromise (BEC)

Table of Contents

What is Business Email Compromise (BEC)?

Business Email Compromise is a fraud scheme in which perpetrators compromise a business email account or forge a trusted sender identity to trick employees into making wire transfers to fraudulent accounts or changing bank details. If an actual mailbox is taken over, this is referred to as Email Account Compromise (EAC).

Do I have to pay a second time after making a payment to a fake account?

Short answer: As a rule, yes. A payment to a fraudster posing as a creditor generally does not discharge the original debt.

The Supreme Court (OGH January 14, 2025, 8 Ob 121/24p) ruled in a case of email spoofing that a fraudulently inserted account change was not attributable to the genuine creditor and that the debtor's payment to the fraudulent account did not release them from their payment obligation. German jurisprudence arrives at the same principle: the Higher Regional Court of Karlsruhe (July 27, 2023, 19 U 83/22) and the Higher Regional Court of Schleswig-Holstein (December 18, 2024, 12 U 9/24) both denied any discharging effect of payment made to the manipulated account.

Exception: If the payer's own IT sphere was compromised or recognizable warning signs were ignored, contributory negligence can shift liability (OLG Linz; LG Koblenz, 8 O 271/22).

Is the management personally liable?

Short answer: Yes, in the event of a gross breach of the duty of care.

According to Section 25 of the GmbHG (Limited Liability Company Act), managing directors must apply the diligence of a prudent businessman – which includes risk-appropriate IT security. If payment approval processes or multi-factor authentication are completely lacking despite a known risk situation, internal liability towards the company may be considered. The burden of proof for compliance with the duty of care lies with the managing director (Section 25 (3) GmbHG).

When is there a GDPR reporting obligation after a BEC incident?

Short answer: Whenever there is a likely risk to the rights and freedoms of data subjects – notification within 72 hours to the supervisory authority.

A compromised mailbox regularly contains personal data and thus constitutes a data breach. Controllers must report the incident to the data protection authority without undue delay, where feasible within 72 hours (Art. 33 GDPR), unless a risk can be ruled out; in the event of a high risk, the data subjects must also be notified (Art. 34 GDPR). In its Guidelines 01/2021, the EDPB addressed a practical case of a hacked employee mailbox with mass phishing mailouts, confirming both notification and the notification of data subjects as appropriate. A decision not to notify must also be documented (Art. 33(5) GDPR).

Can affected customers or employees claim damages themselves?

Short answer: Yes, pursuant to Article 82 GDPR – provided there is a GDPR violation with concrete, causal damage.

The mere fact of a successful hacker attack does not in itself constitute a violation of Article 32 GDPR (Higher Labor Court of Hesse, Feb 10, 2026, 12 SLa 709/25). However, if security measures are inadequate, even a temporary loss of control over the data is sufficient as a compensable non-material damage. The amounts awarded in German case law in simple cases of loss of control generally range in the low to mid-three-digit bracket, and significantly higher for more severe violations.

Brief conclusion

BEC/EAC incidents trigger four parallel legal levels: the allocation of civil law risk between contracting parties, the internal liability of management pursuant to Section 25 GmbHG (Limited Liability Company Act), the GDPR notification obligation pursuant to Articles 33/34 GDPR, and individual claims for damages pursuant to Article 82 GDPR. Case law in Austria and Germany regularly assigns the risk of loss to the sphere in which the compromise took place—while the original claim remains in effect. A prompt, documented initial response is crucial.

Why ATB.LAW for Business Email Compromise?

ATB.LAW Attorneys at Law (Vienna) specializes in cybercrime, crypto-asset law, data protection, and IT law, supporting companies in BEC/EAC incidents with GDPR notifications, the enforcement or defense of civil law claims, management liability issues, and criminal complaints.

Contact: office@atb.law


FAQ:

What is the difference between BEC and EAC?


BEC generally refers to fraud using forged or compromised business email communication; EAC specifically refers to the takeover of a real email account by attackers.


Do I have to pay a second time after a BEC payment?

Generally yes, since payment to a fraudster does not settle the original claim – unless the payer's own sphere was compromised.


How much time do I have for the GDPR notification?


Without delay, if possible within 72 hours of becoming aware of the incident.

Is the management personally liable for a BEC loss?


In the event of a gross breach of the duty of IT care pursuant to Section 25 GmbHG, internal liability is possible.

Can those affected file individual lawsuits?


Yes, pursuant to Article 82 of the GDPR in the event of a proven GDPR violation and causal damage.

More articles

ATB.LAW Cybercrime Lawyer

Cybercrime in Austria

Legal situation, figures, and action steps
Picture of Roman Taudes
Roman Taudes
Cyberattack reporting obligations NIS GDPR MAR

Reporting obligations in the event of cyber attacks

What the TeamViewer case means for Austrian companies
Picture of Roman Taudes
Roman Taudes
cPanel/WHM leads to ransomware attacks on websites - ATB.LAW supports victims

cPanel ransomware attack

Critical vulnerability CVE-2026-41940 puts websites at risk
Picture of Roman Taudes
Roman Taudes