Phishing in the Workplace: When a Simple Click Leads to Dismissal (and Damages)
In an era where cybercrime has become as sophisticated as a high-end financial engineering operation, the line between being a “scam victim” and a “negligent employee” has become perilously thin. A recent analysis published in the Baker McKenzie newsletter (March 2026) highlights a Supreme Court trend that is shaking the foundations of disciplinary liability: employees who fall for phishing scams can now be legally dismissed, even if the company failed to provide specific cybersecurity training.
The Case: The “CEO Email” and the Ghost Wire Transfer
The legal saga, which culminated in Ordinance No. 3263 of February 13, 2026, by the Italian Court of Cassation, involved an experienced accounting professional. The employee received an email, ostensibly from the company’s President, requesting an urgent international wire transfer to a UK-based account for “urgent overseas expenses.”
Without triggering internal verification procedures or seeking verbal confirmation, the employee executed the transaction. Only after the damage was done did it emerge as a Business Email Compromise (BEC) attack.
Why “Lack of Training” is No Longer a Valid Defense
The legal turning point in this ruling lies in the employee’s defense. She argued that because the company had not provided specific cybersecurity courses, the error should be considered a simple, blameless oversight.
The Court of Cassation firmly rejected this argument, establishing three core principles:
- Qualified Diligence: For roles involving significant responsibility (Administration, Finance, HR), a standard level of care is insufficient. An “elevated” professional diligence is required (pursuant to Art. 2104 of the Civil Code).
- Obvious Red Flags: The Court noted that the email’s tone, the lack of supporting documentation, and the unusual nature of the request were “alarm signals” that an experienced professional should have caught, regardless of formal training.
- Breach of the Fiduciary Bond: The severity of the negligence, combined with the scale of the financial loss, was deemed to make the continuation of the employment relationship impossible, justifying dismissal for just cause.
Beyond Dismissal: Liability for Damages
The real “sting” of this 2026 legal orientation is the cumulative nature of the penalty. In addition to upholding the job loss, the judges found the company’s request for reimbursement of the lost funds to be well-founded.
“The cunning of the fraudster does not eliminate the minimum duty of prudence expected from the employee.”
In short, the employee not only loses their income but can also be ordered to personally compensate the employer for damages resulting from their imprudent conduct.
This jurisprudential shift sends a clear message: cybersecurity is no longer just an IT department issue; it is a contractual duty of care for every employee. For companies, while training remains a pillar of GDPR compliance (Art. 32), its absence is no longer a “passport to impunity” for gross negligence.
