Court rules: Emails must be end-to-end encrypted!
Even in 2026, email communication remains one of the most popular means of communication. Every day - whether for business or personal use - millions of emails are sent and received worldwide. Find out why even a court in Germany ruled that emails send without end-to-end encryption are not secure!
What happened?
The Higher Regional Court of Schleswig-Holstein dealt with a case involving a building contractor, and its ruling has sparked a new debate about email security. But what exactly happened?
A building contractor sent a final invoice for €15,000 as an attachment in an email using transport layer security (TLS) to a private customer. On its way to the customer, the invoice was intercepted by an attacker, who then manipulated the account number to their own advantage. The customer did not notice the manipulation and transferred the amount to the criminal’s account instead of the contractor’s.
Unfortunately, this type of incident is not an isolated case, and it typically follows the same pattern: An invoice is sent via email without end-to-end encryption, the email is intercepted by unauthorized third parties, and the invoice is tampered with by the criminals - this highlights why companies need end-to-end encrypted email. In addition to this, there are extra steps and measures you can implement to prevent phishing attacks and keep your accounts safe from hackers.
The Higher Regional Court’s Ruling
The court’s ruling is as follows: The transport encryption alone used to send the invoice is not sufficient. Rather, end-to-end encryption is necessary to ensure adequate security. If the company fails to comply with this requirement, the customer is entitled to damages in the amount of the invoice. The court further argued that, given the high invoice amount, end-to-end encryption would have been necessary to prevent tampering by unauthorized third parties. This is because the advantage of end-to-end encryption is that neither the involved email providers can read the emails nor can potential attackers read or tamper with the emails in transit. In its reasoning, the court cites article 32 of the GDPR which mandates a risk-based approach. Specifically, this means that the higher the potential risk to the data subjects, the stricter the protective measures must be. In the case of the aggrieved contractor, the lack of end-to-end encryption was deemed insufficient, which ultimately resulted in the contractor being held liable and required to compensate for the resulting damages.
With Tuta you never have to wonder whether your emails are send securely or a hacker will intercept. Thanks to its quantum-secure cryptography and end-to-end encryption you can make sure that only you and your reader will read your emails. Not even we at Tuta can read your emails. And the good news is that not only is Tuta Mail end-to-end encrypted but also Tuta Calendar and Tuta Drive. Try out Tuta now!
What does this mean for you?
Emails have become a significant part of our daily work lives. But when it comes to their security, the Higher Regional Court’s ruling sends a clear message: To ensure the security of emails, they must be end-to-end encrypted. After all, the IT threat landscape is constantly and rapidly changing. What may be considered secure today can look very different in two or three years time. Nonetheless, the bottom line is this: When it comes to sensitive data, and especially then - such as invoices for large amounts or banking information, etc. - additional security measures should be implemented. This includes using end-to-end encryption. Companies often underestimate the liability risks involved when invoices are deliberately tampered with, resulting in financial loss for the company.
Wrapping up
The Higher Regional Court’s ruling makes one thing clear: Sensitive information must be protected! This also involves developing an adequate security strategy, and end-to-end encryption is a key part of that, as it is the only way to ensure that no one else can read the data. However, the Higher Regional Court’s ruling also highlights another point: Companies - as well as government agencies and local authorities - need an adequate security strategy to be prepared for the threats of today and tomorrow. Is your government agency or local authority ready yet? We at Tuta Mail are happy to help you secure your communications - simply and cost-effectively. Contact us!