California Court Affirms Liability for Wire Fraud in Settlement T

A $475,000 settlement was supposed to end a personal injury dispute. Instead, it became an expensive lesson in spoofed email addresses, changed payment instructions, questionable phone numbers, and the financial danger of trusting a convincing stranger with excellent timing.

In Thomas v. Corbyn Restaurant Development Corp., the California Court of Appeal affirmed a judgment requiring the defendants to pay the agreed settlement even though their counsel had already wired $475,000 to a cybercriminal posing as a representative of the plaintiff’s law firm. The decision established an important California rule: when an imposter fraudulently diverts a wire transfer, the loss may fall on the party that was in the best position to prevent the fraud.

One legal distinction matters immediately. Despite the phrase “liability for wire fraud,” this was not a criminal prosecution under the federal wire fraud statute. The defendants were not found to have committed fraud. The case concerned civil responsibility for a stolen settlement payment and whether sending money to an imposter satisfied the defendants’ contractual obligation to pay the plaintiff. The court concluded that it did not.

The California Wire Fraud Case at a Glance

Brian Thomas filed a personal injury lawsuit against Corbyn Restaurant Development Corp. and two employees after an alleged altercation. Following mediation, the parties agreed to settle the case for $475,000.

The written settlement agreement required the defendants to issue the payment to the “Chambers and Noronha Client Trust Account” for the benefit of Brian Thomas. The parties’ communications also indicated that the money would be delivered by check.

About a week later, an unknown person began impersonating an administrator at the plaintiff’s law firm. The fraudster asked defense counsel to abandon the expected check and transfer the settlement funds electronically instead. That request should have been treated like a fire alarm in a library: unusual, disruptive, and worthy of immediate attention.

Unfortunately, the fraudulent instructions were accepted. The defendants’ side wired the entire settlement to a bank account controlled by the imposter. When the parties eventually discovered the scam, the plaintiff still had not received a dollar of the promised settlement.

How the Settlement Wire Fraud Unfolded

A Nearly Identical Email Address Opened the Door

The authentic email address of the plaintiff’s law firm administrator used the domain “cnlegalgroup.com.” The imposter registered and used a deceptively similar domain containing one additional letter. The username was also slightly altered.

These changes were easy to overlook when reading quickly. That is precisely why domain-spoofing attacks work. Cybercriminals are not always hacking through seven layers of encryption while dramatic music plays in the background. Sometimes they simply buy a similar domain, change one character, and wait for a busy professional to miss it.

The fake emails included legitimate-looking information, including the law firm’s correct physical address and website. However, they also included incorrect telephone and fax numbers. Two identical requests for electronic payment were sent within eight minutes, adding another unusual detail to the conversation.

The Payment Terms Suddenly Changed

The settlement agreement identified a client trust account and named Brian Thomas as the person for whose benefit the funds were being paid. The imposter’s wire instructions instead named “Chambers & Noronha APC” as the recipient, removing both the reference to the client trust account and the plaintiff’s name.

The proposed payment method also changed from check to wire transfer. A change in payment method is not automatically fraudulent, but a sudden request to redirect nearly half a million dollars deserves more than a casual reply. It deserves independent verification using contact information that was already known to be genuine.

The Failed Phone Call Was a Major Warning

Defense counsel attempted to call the telephone number in the suspicious email and discovered that it was inoperable. Rather than stopping the process and locating the plaintiff’s firm through an independent source, the defense team asked the sender for another number.

The fraudster then introduced a supposed “head of finance” named Mark Anderson. Accounting personnel from the defense firm called the new number supplied inside the fraudulent email chain, spoke with the imposter, and completed the wire.

Technically, someone had made a confirmation call. Practically, however, the call confirmed only that the criminal was willing to answer the criminal’s own phone number. That is verification theater, not independent verification.

Why the Plaintiff Never Received the Settlement

After obtaining the money, the scammers apparently tried to delay discovery. A second spoofed email account, this time imitating defense counsel, told the plaintiff’s firm that a settlement check would be sent soon.

For several weeks, the plaintiff’s administrator exchanged messages with the fake defense email account about the supposedly forthcoming check. The deception ended when the fraudulent account stopped responding and the plaintiff’s counsel contacted the actual defense counsel by telephone.

On October 10, 2023, the parties learned that the settlement funds had been diverted. The defendants refused to make another payment, presumably reasoning that they had already released $475,000 and should not have to pay twice.

The plaintiff saw the situation differently: the settlement agreement promised payment to him through his attorneys’ trust account, and neither he nor that account had received the money. He therefore asked the trial court to enforce the settlement under California Code of Civil Procedure section 664.6.

What the California Court of Appeal Decided

The Party Best Positioned to Prevent the Fraud Bears the Risk

Because no published California decision had directly resolved this type of settlement wire fraud, the trial court examined federal cases involving imposters, hacked communications, diverted payments, and fraudulent wiring instructions.

Those decisions generally focused on which party had the best opportunity to detect and prevent the crime. The California Court of Appeal found that approach persuasive and adopted it for California settlement disputes.

The appellate court held that the risk of loss from an imposter’s fraudulent diversion of a wire transfer should be borne by the party in the best position to prevent the fraud. Courts must consider the totality of the circumstances, including whether each party exercised ordinary care. When appropriate, a court may divide the loss according to comparative fault.

This is not a mechanical rule declaring that the sender always loses. The court must examine who received the fraudulent communications, what warning signs appeared, whether instructions changed, whether anyone knew the transaction was being targeted, and what each party reasonably could have done.

The UCC Imposter Rule Provided Guidance

The court drew guidance from the Uniform Commercial Code’s imposter rule. Although that provision directly governs negotiable instruments rather than ordinary wire transfers, other courts have used its ordinary-care and comparative-fault principles when analyzing payments diverted by cybercriminals.

California has adopted the relevant UCC language. It permits a person bearing a loss to recover from another person whose failure to exercise ordinary care substantially contributed to that loss, to the extent of that contribution.

The appellate court also observed that ordinary contract principles could lead to a similar result. When neither party expressly assumed the risk of a mistake caused by an imposter, a court may reasonably place the loss on the party best able to avoid it.

The Red Flags That Controlled the Outcome

The decision rested on a collection of warning signs rather than one spectacular mistake. The important red flags included:

  • The requested payment method changed from a check to a wire transfer.
  • The proposed payee differed from the payee identified in the settlement agreement.
  • The wire instructions removed the plaintiff’s name.
  • The instructions no longer clearly identified a client trust account.
  • The sender’s email address contained subtle spelling changes.
  • The signature block listed a different telephone number.
  • The first telephone number provided was inoperable.
  • A replacement contact and number came from the same suspicious email chain.
  • The supposed finance officer was not independently verified.
  • Duplicate emails were sent within a short period.

Any one of those details might have an innocent explanation. Together, they formed a parade of red flags carrying a banner that read, “Please do not wire $475,000 yet.”

The court also emphasized that the correct phone number for the plaintiff’s law firm appeared in authentic emails and court filings and had reportedly remained unchanged since 1989. Defense counsel could have used a pleading, an earlier verified message, the State Bar’s directory, or another independent source to reach the real firm.

Why Calling the Fraudster Did Not Count as Safe Verification

One of the most valuable lessons from the ruling is that a callback is useful only when the number comes from a trusted source independent of the request being verified.

Calling a telephone number printed in a suspicious email is similar to asking a person wearing a fake badge whether the badge is genuine. The answer is unlikely to improve the investigation.

A secure callback process begins with contact information already established through an earlier, authenticated channel. Appropriate sources may include the signed settlement agreement, filed court documents, an existing contact database, a verified company website, or a professional licensing directory.

The person making the call should also read the material payment details aloud: recipient name, bank name, account number, routing number, payment amount, and reason for any change. The recipient should confirm those details rather than simply saying, “Yes, the instructions are correct.”

The Court Did Not Automatically Find Professional Negligence

The trial court stated that it was not necessarily finding that a lawyer or party had committed negligence. Everyone involved, other than the criminal, was a victim of a sophisticated scam.

Nevertheless, determining who was “negligent” was not the only issue. The central question was which side had the better opportunity to prevent the loss. A party can therefore bear the financial risk even when the court stops short of making a formal professional-negligence finding.

That distinction has major consequences. Businesses and law firms cannot assume that avoiding a malpractice label means avoiding the bill. A court may enforce the original payment obligation because money sent to an unauthorized stranger is not payment to the contractual recipient.

Why the Plaintiff’s Side Was Not Assigned Comparative Fault

The defendants argued that the scammer must have gained information through a compromise of the plaintiff’s computer system. The appellate court rejected that theory because the evidence did not establish that either party’s system had been breached.

The court noted that a criminal might learn about a settlement through several methods. A fraudster could obtain information from exposed documents, public conversations, compromised third parties, social engineering, or other sources. The use of look-alike email domains did not prove that the plaintiff’s network had been hacked.

The defendants also argued that the plaintiff’s lawyers waited too long before calling about the missing check. The court found that this conduct occurred after the defendants had already wired the money to the wrong account. There was no evidence that the delay contributed to the original transfer.

Because the defense side received the fraudulent instructions and encountered the meaningful warning signs before payment, substantial evidence supported assigning it 100% of the loss.

What the Ruling Means for California Businesses and Law Firms

A Settlement Is Not Paid Until the Right Recipient Is Paid

A payment obligation is not necessarily discharged merely because money has left the sender’s bank account. The payment must reach the person or account authorized by the agreement.

In this case, enforcing the settlement meant that the defendants remained responsible for the full $475,000. From their perspective, the practical cost could approach twice the original settlement amount, subject to any recovery from banks, insurers, cyber policies, responsible professionals, or the fraudster.

Changed Instructions Require a Mandatory Stop

Every organization that sends significant payments should have a rule requiring additional verification whenever payment instructions change. The rule should apply regardless of the sender’s apparent identity, urgency, seniority, or ability to sprinkle “please handle today” throughout an email.

Employees should not be allowed to bypass the procedure because a transaction is near a deadline. Urgency is not a reason to weaken controls; urgency is one of the reasons the controls exist.

Responsibility Cannot Be Delegated Without a Process

Delegating a confirmation call to accounting staff is not inherently improper. The risk arises when the staff member is given no independently verified contact information, no checklist, and no authority to stop the transaction.

Law firms, insurers, escrow companies, corporate legal departments, and settlement administrators should document who verifies instructions, which information must be confirmed, and who grants final approval.

A Safer Settlement Payment Protocol

  1. Record payment terms in the settlement agreement. Identify the method, recipient, account type, and required documentation.
  2. Verify contact details at the beginning. Establish trusted telephone numbers before payment discussions begin.
  3. Treat every change as suspicious. A new account, payee, bank, email address, or payment method should pause the transaction.
  4. Use an independent communication channel. Do not reply to the questionable email or call a number contained in it.
  5. Require two-person approval. High-value wires should be reviewed by at least two trained people.
  6. Confirm every material detail. Read back the recipient, routing number, account number, bank, and amount.
  7. Document the verification. Record who confirmed the instructions, when the call occurred, and which trusted number was used.
  8. Use multifactor authentication. Protect email, financial platforms, document systems, and administrator accounts.
  9. Train lawyers and support staff together. Criminals target the entire workflow, not merely the person whose name appears on the pleading.
  10. Prepare an incident-response plan. Employees must know how to contact the bank, cyber insurer, law enforcement, and affected parties immediately.

Official cybersecurity guidance consistently recommends verifying unusual financial requests through a separately obtained contact method. The State Bar of California also warns that attorneys are frequent targets of phishing, trust-account scams, identity theft, and wire fraud.

Practice-Based Experience: What a Secure Settlement Workflow Looks Like

The most revealing experience in settlement fraud prevention occurs during an ordinary workday, not during a dramatic cybersecurity emergency. Imagine that a legal assistant receives an email at 3:42 p.m. on Friday. The message appears to come from opposing counsel and explains that the firm’s banking information has changed. The settlement deadline is Monday, the client is impatient, and accounting wants to close the file.

In an unsafe workflow, the assistant forwards the message to accounting. Accounting calls the number in the new instructions, speaks with a polite “finance manager,” and releases the money. Everyone feels efficient until Tuesday, when the real lawyer asks why the settlement has not arrived.

In a secure workflow, the same email triggers a payment-change alert. The assistant compares the sender’s address with the verified address in the case-management system and notices an extra letter. She does not reply. Instead, she calls opposing counsel using the number stored when the case began.

Opposing counsel confirms that no change was requested. The wire is stopped, the suspicious domain is blocked, and both firms preserve the messages for investigation. The entire save may come from one five-minute telephone call. That call is not glamorous, but neither is paying a settlement twice.

Another common experience involves excessive trust in internal hierarchy. An accounting employee may receive instructions that appear to come from a partner, executive, claims manager, or client. Because the message sounds authoritative, the employee worries that asking questions will seem slow or disrespectful.

A strong organization reverses that pressure. Employees are praised for stopping unusual payments. Leadership repeatedly states that no one will be criticized for independently confirming a financial request. Fraud prevention becomes part of professional performance rather than an obstacle to it.

Organizations also learn that cybersecurity tools cannot replace payment discipline. Spam filters, domain monitoring, multifactor authentication, and endpoint protection are valuable, but a scam can succeed without penetrating the sender’s network. A criminal may use publicly available information and a newly registered look-alike domain to create a believable conversation.

The safest teams therefore combine technical defenses with human controls. They maintain verified contact directories, use two-person approval, prohibit last-minute changes through email alone, and conduct periodic simulations. During training, employees examine real-looking domains character by character. They practice responding to urgent requests without clicking links or using embedded phone numbers.

Experience also shows why incident response must begin immediately. Once a fraudulent wire is discovered, the sender should contact its financial institution without delay and request a recall or freeze. The organization should preserve emails, headers, call records, wire confirmations, and account information. It should notify its insurer and report the incident through appropriate law-enforcement channels.

Recovery is never guaranteed, and delays allow money to move through additional accounts. A written response plan prevents the first hour from disappearing into confusion, internal blame, and meetings about who should schedule the next meeting.

The enduring lesson from Thomas is operational rather than technological: verification must be independent, routine, and resistant to urgency. The safest payment procedure is the one employees follow even when the email looks authentic, the deadline is approaching, and everyone desperately wants the matter closed.

Conclusion

Thomas v. Corbyn Restaurant Development Corp. changed the California landscape for settlement wire fraud by adopting a fact-sensitive rule that assigns loss to the party best positioned to prevent it. The defendants remained obligated to pay the $475,000 settlement because the agreed recipient never received the funds and multiple warning signs appeared before the fraudulent transfer.

The published opinion was filed on May 27, 2025. The judgment was affirmed in full, the remittitur issued on August 5, 2025, and the California appellate docket lists the case as complete and final.

The ruling does not make every sender automatically responsible for every fraudulent wire. It requires courts to examine ordinary care, comparative fault, security practices, warning signs, and each party’s opportunity to stop the transaction. Still, its practical message is wonderfully uncomplicated: before sending a large wire, independently call the person who is actually supposed to receive it.

Note: This article provides general educational information and does not constitute legal advice. Organizations facing a fraudulent transfer or disputed settlement payment should consult qualified counsel and contact their financial institution promptly.

This site uses cookies to offer you a better browsing experience. By browsing this website, you agree to our use of cookies.