Fraudsters in the Inbox: The Limits of Contractual Causation in Logix Aero v Siam Aero
min readIntroduction
Authorised Push Payment (APP) fraud or email interpretation fraud has, sadly, become a tale as old as time and increasingly common. In short, a fraudster hacks or otherwise makes unauthorised access to an unknowing victim’s IT system, intervening in email traffic about a high value transaction, and changes the payment details on an invoice, request for funds, and/or purchase order to a bank account controlled by the fraudster. The victim, unaware, authorises a payment to the wrong account. Invariably, the fraudster uses a newly registered/created domain name and an email account bearing a remarkable similarity to the parties’ real email address in the hope the fraud remains undetected as long as possible. Unless the error is spotted immediately (it rarely is) the stolen funds, now in the control of the fraudster, disappear within seconds to multiple bank accounts across multiple jurisdictions in smaller and smaller denominations in an attempt to thwart tracing and recovery efforts. The fraudster’s real identity often remains a mystery. That leaves many victims at the mercy of pursuing alternative claims against other third parties to recover their losses. In recent years the most widely reported cases have been claims against the victim’s own bank (on Quincecare grounds) or against the recipient bank with mixed success. Logix is an ingenious (albeit unsuccessful) attempt to claim against the co-victim of fraud on breach of confidence grounds.
Context
The UK Annual Fraud Report 2026 [1] reports that “APP fraud” remains rife, although, that term (as defined in the report) is an umbrella term for a wide variety of different subcategories of fraud; the most prevalent subcategories being (1) online fraud (purchase fraud/investment scams/romance fraud etc) representing 66% of all cases, (2) telecommunications scams (impersonation of banks, police etc over the phone) representing 17% of all cases and, of course, (3) invoice/mandate frauds via email representing only circa 1% of all cases. The total number of reported APP cases (personal and corporate) as a whole has risen from 154,614 (2020) to 248,070 (2025), a +60% increase in only 5 years. In 2025, it is estimated that within those c250,000 cases there was a total of 519,433 fraudulent payments identified with a combined value of £576.4m. In better news, ~ 60% (£354.3m) of that was successfully recovered and returned to victims.
Of all those circa 250,000 cases, as above, invoice/mandate fraud accounted for only 1% in volume. The total amount of invoice/mandate cases has actually diminished in the last 5 years from 4,721 (2020) to 2,305 (2025) and down from a value of £68.8m (2020) to £41.3m (2025). In 2025, £20m/41.3m lost was returned to victims.
Yet despite all this it only takes one unwitting victim and high value case to make the headlines.
Facts
Logix was your classic APP scam. Unknown fraudsters managed to insert themselves in the middle of email correspondence between the appellant (Logix, an Irish entity) and the respondent (Siam Aero, a Thai entity). This correspondence revolved around the purchase by Logix of two aircraft engines from Siam Aero on English law governed contracts. The fraudsters created fake email addresses for both Logix and Siam Aero that differed only subtly from the genuine addresses (".co" instead of ".com"). Neither party noticed the changes and unwittingly corresponded through the fraudsters from a very early stage. The fraudsters then altered the payment details on the purchase orders and invoices to an account in Vietnam controlled by them. As a result, Logix paid the balance of the purchase price of US$824,900 to the fraudsters' account rather than to Siam Aero's account in Thailand. By the time Siam Aero raised the alarm, only a few days later, the funds had already disappeared. Post-event investigations could not determine that either party’s IT system had been compromised nor who was responsible for the leak. That said it was undisputed that Logix did not make any attempt to independently verify the bank details directly (by phone etc) before authorising the payment.
Logix sought to recover its loss on a number of bases all of which failed; its claim was struck out at first instance as having no realistic prospect of success. The sole issue on this appeal was the judge’s finding on causation in respect of a claim in damages against Siam Aero for breach of confidentiality clause in a Letter of Understanding i.e. that by (inadvertently) sending documents and information to the fraudsters Siam Aero had caused Logix’s loss. The judge found this “highly artificial” but accepted that it was at least arguable there could have been a breach of the clause but, even if there was, it was not causative of the loss. The loss was caused by the fraudsters' intervening actions which broke the chain of causation. Logix appealed.
Causation
It is well-known that the voluntary act of third party intervening between the breach of contract and the loss suffered will usually break the chain of causation.
However, Logix argued that the case of London Joint Stock Bank Limited v Macmillan and Arthur [1918] AC 777 (“Macmillan”) was authority for the proposition that the intervention of a third-party fraudster does not break the chain of causation and that the contract breaker remains liable, subject only to the issue of remoteness of loss. The appeal court firmly rejected this submission and distinguished Macmillan on its own facts (a case about a doctored cheque presented by the victim to its own bank and a case where a special contractual “duty to prevent” arose so the chain of causation did not break).
Application in Logix
In the present case, the court found that Logix’s loss was not caused by the assumed breach of contract by Siam Aero, but by the fraudsters. The breach of contract was not an “effective” cause of the loss. The intervention of the fraudsters occurred before any assumed breached of contract by Siam Aero, meaning the fraud was in fact the cause of this assumed breach as well as an intervening and independent cause. Furthermore, Siam Aero's assumed breach constituted only one element of a broader fraudulent scheme, the success of which also depended upon Logix being deceived into making payment to an incorrect account.
Further, the confidentiality clause did not impose a special duty to protect the other party from being deceived by fraudsters to bring the case within the facts of Macmillan. Rather, it was focused on protecting the parties from commercial documents and information being passed on to competitors. Therefore, there was a break in the chain of causation and the Court of Appeal thought that the judge at first instance was right to find so.
Interestingly, albeit obiter, the appellate court also commented that it would have been open to the first instance judge to strike out on the basis that the loss suffered by Logix was (1) outside the scope of the duty assumed by Siam Aero and (2) that Logix’s loss would have been too remote. Further, had the case proceeded to trial, there were significant obstacles including how exactly Siam Aero could be in breach of confidence for disclosing its own confidential details (bank details) to a third party?
Commentary
Logix is sadly another case in a long line of APP fraud cases where the victim comes up short. It was a novel claim based on the breach of a confidential clause in a non-binding Letter of Understanding against a co-victim. It had the whiff of last chance saloon (all other pleaded bases had failed) so the result to uphold the first instance decision is hardly surprising.
Above all else, Logix is perhaps a salutary lesson for companies to be alert to fraud and ensure that they have robust anti-fraud policies and adequate fraud prevention training in place. Had Logix’s employees spotted the red flags or, at a minimum, followed best practice to independently verify the seller’s bank details directly over the phone the fraud would likely have been prevented. The financial crime team at Charles Russell Speechlys can assist in drafting such policies and delivering the comprehensive training needed to guard against similar incidents.