Approval email spoofing liability.

APPROVAL EMAIL SPOOFING LIABILITY

Introduction

Approval email spoofing liability arises when a person creates, manipulates, or sends an email that falsely appears to have been issued by an authorized manager, officer, employer, government official, or other decision-maker. Such a fraudulent email may be used to obtain approval for payment, employment action, procurement, salary adjustment, contractual activity, access to confidential information, or another organizational decision.

Email spoofing creates important legal questions concerning fraud, unauthorized electronic communication, identity misuse, employment misconduct, electronic evidence, and the liability of persons who rely upon or fail to verify the disputed communication.

Meaning of Approval Email Spoofing

Approval email spoofing occurs when an electronic communication is deliberately presented as if it originated from an authorized person when that person did not actually send or approve it.

For example, an employee may receive an email apparently sent by the HR Director approving a salary increase. The employee processes the approval, but subsequent investigation reveals that the HR Director never sent the email. The organization must then determine who created the email, whether there was an intention to deceive, whether the recipient acted reasonably, and whether any loss resulted.

Essential Elements of Liability

The following factors are generally important in determining liability:

False Representation: The email falsely represents that an authorized person issued an approval.

Intent to Deceive: There should ordinarily be evidence that the communication was deliberately created or used for a fraudulent or unauthorized purpose.

Impersonation: The sender may falsely use another person's name, email address, designation, signature, or organizational identity.

Reliance: Another person or department may rely upon the email and take action.

Loss or Legal Consequence: The spoofed approval may result in financial loss, unauthorized employment action, disclosure of information, or another legal consequence.

Causation: There must be an appropriate connection between the fraudulent communication and the resulting loss or action.

Civil Liability

A person responsible for a fraudulent approval email may face civil liability where the conduct causes financial or other legally recognizable loss.

Possible remedies may include:

Recovery of financial losses;

Damages where legally available;

Restitution;

Injunctions;

Cancellation of unauthorized transactions; and

Recovery of amounts obtained through fraudulent conduct.

Civil liability depends upon the applicable law and the evidence establishing fraud, misrepresentation, authorization, reliance, and loss.

Criminal Liability

Where approval email spoofing involves dishonest or fraudulent conduct, unauthorized access, identity misuse, forgery, or electronic manipulation, criminal laws may become applicable.

In Pakistan, depending upon the facts, provisions of the Prevention of Electronic Crimes Act, 2016 (PECA) and relevant provisions of the Pakistan Penal Code, 1860 may become relevant.

The precise offence depends upon the conduct involved, such as unauthorized access, electronic fraud, forgery, cheating, identity-related misuse, or unauthorized use of information.

Employment and Disciplinary Liability

If an employee deliberately creates or uses a forged approval email, the conduct may constitute serious workplace misconduct.

Possible disciplinary consequences include:

Warning;

Suspension;

Demotion where legally permissible;

Recovery of financial loss;

Termination of employment; and

Referral to law-enforcement authorities where criminal conduct is suspected.

However, disciplinary action should ordinarily be based upon reliable evidence and a fair inquiry.

Liability of an Employee Who Relies Upon a Spoofed Email

A different issue arises when an employee receives and relies upon a fraudulent email without knowing that it is false.

Mere reliance does not automatically establish misconduct.

Relevant factors include:

Whether the email appeared genuine;

Whether the apparent sender had authority;

Whether the employee followed normal organizational procedures;

Whether there were obvious warning signs;

Whether independent verification was required;

Whether the employee personally benefited; and

Whether the employee intentionally ignored security procedures.

An employee who follows established procedures and reasonably believes the communication to be genuine may have a substantially different legal position from an employee who knowingly participates in the fraudulent transaction.

Employer's Responsibility

Employers should maintain adequate safeguards against approval-email fraud.

Important safeguards include:

Multi-factor authentication;

Strong password and access-control policies;

SPF, DKIM and DMARC email authentication;

Clear approval-authority matrices;

Segregation of duties;

Independent confirmation of high-value approvals;

Email and server-log preservation;

Cybersecurity training;

Phishing-awareness programs; and

Prompt investigation of suspicious communications.

For particularly sensitive approvals, organizations should use an independent communication channel rather than relying exclusively upon the appearance of an email.

Electronic Evidence

In an approval-email spoofing dispute, the visible email alone may not establish who actually sent the communication.

Relevant evidence may include:

Complete email headers;

Server logs;

IP information;

SPF/DKIM/DMARC authentication results;

Microsoft 365 or Google Workspace audit records;

Device logs;

Login records;

Metadata;

Attachment information;

Timestamp information; and

Digital forensic examination.

Therefore, an investigation should examine the technical origin and integrity of the electronic communication.

CASE LAWS

1. Trimex International FZE Ltd. v. Vedanta Aluminium Ltd., (2010) 3 SCC 1

The Supreme Court of India recognized the legal significance of electronic communications in determining contractual arrangements.

Relevance: The case demonstrates that email communications can have legal consequences. Therefore, where an email purports to constitute an official approval, the authenticity and authority of that communication become important legal issues.

2. Shakti Bhog Foods Ltd. v. Kola Shipping Ltd., (2009) 2 SCC 134

The Supreme Court of India considered electronic communications in the context of commercial dealings.

Relevance: Electronic communications can form part of the evidentiary record of a transaction. In a spoofing dispute, the authenticity and reliability of the communication therefore become significant.

3. Anvar P.V. v. P.K. Basheer, (2014) 10 SCC 473

The Supreme Court of India laid down important principles concerning the admissibility of electronic records under the Indian Evidence Act.

Relevance: In an email-spoofing case, a party cannot necessarily establish authorship merely by producing a printout or screenshot. The applicable requirements concerning electronic evidence must be satisfied.

4. Arjun Panditrao Khotkar v. Kailash Kushanrao Gorantyal, (2020) 7 SCC 1

The Supreme Court further clarified the evidentiary requirements relating to electronic records.

Relevance: The case is important where liability depends upon disputed electronic communications. The provenance and integrity of an email may need to be established through legally admissible electronic evidence.

5. State (NCT of Delhi) v. Navjot Sandhu, (2005) 11 SCC 600

The Supreme Court considered the evidentiary significance of computer-generated and electronic records.

Relevance: The case demonstrates the importance of examining electronic records in determining whether alleged electronic activity can be connected with the accused person.

6. Tomaso Bruno v. State of Uttar Pradesh, (2015) 7 SCC 178

The Supreme Court emphasized the importance of scientific and electronic evidence where such evidence is capable of assisting in the determination of facts.

Relevance: In an email-spoofing investigation, server records, electronic logs, and forensic material may assist in determining the origin and authenticity of the disputed communication.

7. P.R. Transport Agency v. Union of India, 2006 SCC OnLine All 1265

The Allahabad High Court considered the legal significance of electronic communication in contractual dealings.

Relevance: The case illustrates the legal recognition of email communications and supports the importance of examining whether an electronic communication was genuinely authorized.

Principles for Determining Liability

A court, disciplinary authority, or investigating body may consider the following sequence:

AUTHENTICITY → AUTHORITY → INTENTION → RELIANCE → LOSS → CAUSATION → ELECTRONIC EVIDENCE → DUE PROCESS

The existence of a suspicious email alone does not necessarily prove who created it. Technical evidence and surrounding circumstances must be considered.

Preventive Measures

Organizations should establish a formal electronic-approval verification system.

The following measures are particularly useful:

Authentication of official email accounts;

Multi-factor authentication;

SPF, DKIM and DMARC implementation;

Independent confirmation of high-value approvals;

Clear delegation of approval authority;

Preservation of email logs;

Regular cybersecurity audits;

Employee training against phishing and spoofing;

Immediate investigation of suspicious approvals; and

Fair disciplinary procedures based on reliable evidence.

Conclusion

Approval email spoofing liability concerns the unauthorized creation or use of electronic communications that falsely appear to originate from an authorized person. Such conduct may result in civil, criminal, employment, disciplinary, and regulatory consequences depending upon the facts and applicable law.

The principal considerations are authenticity, authority, intention, reliance, causation, financial or organizational loss, and the admissibility and reliability of electronic evidence.

A person who deliberately fabricates an approval email to obtain an unauthorized benefit may be held responsible under applicable law. On the other hand, an employee who innocently relies upon a sophisticated spoofed communication should not automatically be treated as a participant in the fraud. The employee's conduct, applicable organizational procedures, reasonable reliance, and available evidence must be examined.

Therefore, effective prevention requires both technical cybersecurity controls and legally sound approval procedures. Organizations should authenticate electronic approvals, independently verify sensitive transactions, preserve forensic evidence, and conduct fair investigations before imposing liability.

LEAVE A COMMENT