Phishing attacks and employee liability.

Phishing Attacks and Employee Liability

Phishing attacks are fraudulent attempts to obtain confidential information—such as passwords, banking credentials, authentication codes, customer information, or corporate data—by impersonating a trusted person or organisation. In an employment context, phishing may occur through deceptive emails, messages, fake login pages, malicious attachments, or fraudulent requests appearing to come from senior management.

Employee liability arises when an employee's conduct in relation to a phishing incident causes loss or damage to the employer, customers, or third parties. The legal position generally depends on the employee's contractual duties, the degree of negligence, applicable employment and data-protection law, and whether the employee acted within the scope of employment.

1. Employee's duty to exercise reasonable care

Employees are ordinarily expected to follow reasonable workplace security procedures. If an organisation has clear policies requiring employees to verify suspicious emails, protect passwords, use multi-factor authentication, or report suspected phishing, deliberate or seriously negligent non-compliance may constitute misconduct.

However, falling victim to a sophisticated phishing attack does not automatically make an employee personally liable. Liability normally requires examination of the employee's actual conduct and the circumstances surrounding the incident.

2. Negligence and breach of workplace policies

An employer may consider disciplinary action where an employee:

  • knowingly ignores established cybersecurity procedures;
  • discloses credentials despite clear warnings;
  • downloads prohibited attachments or software;
  • deliberately bypasses security controls;
  • fails to report a suspected compromise;
  • repeatedly violates information-security policies; or
  • intentionally assists a fraudulent transaction.

The employer should distinguish ordinary human error from reckless or intentional misconduct. A proportionate disciplinary process should consider the employee's training, the sophistication of the attack, the security controls available, workload, previous warnings, and whether the employee promptly reported the incident.

3. Personal financial liability of employees

Whether an employee must personally reimburse an employer for losses caused by phishing depends on the applicable law and employment contract. Courts generally do not treat every workplace mistake as creating unlimited personal financial liability.

Factors that may be relevant include:

  • whether the employee acted negligently or deliberately;
  • whether the loss was reasonably foreseeable;
  • whether the employer provided adequate cybersecurity training;
  • whether the employer maintained appropriate technical safeguards;
  • whether the employee acted within the scope of employment;
  • whether the employer itself contributed to the loss; and
  • whether contractual deductions or recovery are legally permissible.

4. Data protection and confidentiality

Phishing can result in unauthorised disclosure of personal data. Where employee actions expose customer or employee information, the organisation may have statutory obligations concerning data security and breach management.

The fact that an employee caused a security incident does not necessarily transfer the organisation's statutory responsibilities to the employee. Data-protection obligations may continue to rest upon the organisation as the relevant controller, processor, or other regulated entity.

5. Vicarious liability of employers

An important distinction exists between employee liability and employer liability. An employer can potentially be responsible for wrongful acts committed by an employee in the course of employment, even where the employer did not personally commit the wrongdoing.

Therefore, where an employee is deceived by a phishing attack while performing legitimate employment duties, questions may arise about the employer's own cybersecurity controls and about whether the employee's actions occurred within the scope of employment.

6. Internal disciplinary proceedings

If an employee's conduct warrants disciplinary action, the employer should ordinarily follow applicable employment rules and principles of natural justice. The employee should have an opportunity to understand the allegation and respond to it.

A phishing incident should therefore be investigated by examining:

  1. the original phishing message;
  2. the employee's actions;
  3. applicable cybersecurity policies;
  4. training provided to the employee;
  5. available warnings or security controls;
  6. the extent of resulting loss;
  7. whether the employee promptly reported the incident; and
  8. whether similar incidents were treated consistently.

Important Case Laws

1. Lloyd v. Grace, Smith & Co. [1912] AC 716

The House of Lords considered an employee's fraud committed while acting in the course of employment. The case established an important principle of vicarious liability: an employer can be liable for an employee's wrongful conduct where the employee was acting within the scope of the authority entrusted to them.

Relevance to phishing: If an employee is authorised to handle financial or customer transactions and fraudulent conduct occurs through misuse of that position, questions of employer vicarious liability may arise.

2. Lister v Hesley Hall Ltd [2001] UKHL 22

The House of Lords developed the modern approach to determining whether an employer is vicariously liable by examining whether there is a sufficiently close connection between the employee's duties and the wrongful act.

Relevance: In cybersecurity disputes, the connection between the employee's assigned responsibilities and the conduct causing the security incident can be significant.

3. Mohamud v WM Morrison Supermarkets plc [2016] UKSC 11

The UK Supreme Court considered an employee's wrongful conduct and explained the close-connection approach to vicarious liability.

Relevance: The case illustrates that employment-related liability cannot be determined merely by asking whether the employer expressly authorised the particular wrongful act. The relationship between the employee's duties and the conduct must be examined.

4. Various Claimants v WM Morrison Supermarkets plc [2020] UKSC 12

This case concerned a deliberate disclosure of personal information by an employee. The Supreme Court held that the employer was not vicariously liable because the employee's disclosure of the data was not sufficiently connected with the field of activities entrusted to him at the relevant time.

Relevance to phishing: It demonstrates that an employer does not automatically become liable for every data-security incident involving an employee. The circumstances and connection with employment must be examined.

5. Barclays Bank plc v Various Claimants [2020] UKSC 13

The Supreme Court considered whether an organisation could be vicariously liable for the actions of an individual who was not an employee in the traditional sense.

The Court emphasised the distinction between an employment relationship and an independent contractor relationship.

Relevance: Cybersecurity incidents frequently involve contractors, consultants, outsourced IT personnel, and other non-employees. Their legal status can affect allocation of liability.

6. Dubai Aluminium Co Ltd v Salaam [2002] UKHL 48

The House of Lords considered vicarious liability and the relationship between an employee's wrongful conduct and the activities entrusted to that employee.

The decision is important for understanding the scope of employment-related liability where an employee misuses authority obtained through employment.

Relevance: Where an employee has access to sensitive systems or financial information, the scope of the employee's authorised activities may become important in determining responsibility for resulting losses.

7. Google LLC v Vidal-Hall [2015] EWCA Civ 311

The Court of Appeal considered claims concerning misuse of personal information and privacy under UK data-protection law.

Relevance: Phishing attacks can involve the unauthorised acquisition or disclosure of personal information. The case illustrates the broader legal significance of misuse of personal data beyond purely contractual employment disputes.

8. WM Morrison Supermarkets plc v Various Claimants [2018] EWCA Civ 2339

The Court of Appeal considered employer responsibility for an employee's deliberate disclosure of personal data.

Although the Supreme Court subsequently reversed the finding of vicarious liability, the litigation is useful for understanding the competing approaches to employer responsibility for employee-caused data breaches.

Relevance: It demonstrates why the circumstances of the employee's conduct, rather than simply the existence of an employment relationship, are important in cybersecurity liability disputes.

Key Legal Principles

IssueGeneral legal principle
Employee clicks phishing linkNot automatically personal liability
Employee ignores security policyMay support disciplinary action
Deliberate disclosure of credentialsPotentially serious misconduct
Employee promptly reports phishingRelevant mitigating circumstance
Employer has inadequate security controlsMay affect allocation of responsibility
Customer data is exposedOrganisation may retain statutory obligations
Employee commits fraud during employmentVicarious liability may arise depending on circumstances
Independent contractor causes breachLegal position may differ from employee liability
Salary deduction for lossesMust comply with applicable employment law
Intentional employee misconductPotentially stronger basis for disciplinary/legal action

Conclusion

Phishing attacks create a shared cybersecurity and legal risk, rather than automatically making the employee financially responsible for every resulting loss. The central questions are usually what the employee did, what security obligations applied, what training and safeguards were provided, whether the conduct was negligent or intentional, and what legal relationship existed between the employee and organisation.

Employers should therefore investigate phishing incidents objectively and distinguish genuine human error from reckless, repeated, or deliberate misconduct. At the same time, employees handling sensitive information are expected to comply with reasonable security procedures and report suspected attacks promptly.

LEAVE A COMMENT