Why Hackers Target Accounting Firms and How to Reduce the Risk

Accounting firms hold the keys to their clients' finances - which is exactly why they're such an attractive target for cybercriminals. Here's what makes them vulnerable, and how to close the cyber security gaps.

In May 2025, the Qilin ransomware group listed Melbourne accounting practice MKA Accountants on its darknet leak site. The group published 12 sample documents it claimed were taken from the firm, including financial statements, insurance information and internal correspondence.

MKA Accountants confirmed that it was investigating unauthorised access and had notified clients and relevant authorities, including the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC). Later reports said Qilin claimed to have released more than 185GB of data, although the exact volume was not independently confirmed.

In May 2026, Brisbane accounting firm Kennedy McLaughlin & Associates confirmed unauthorised access to part of its IT environment after the same ransomware group listed it on their darknet leak site. Cyber Daily reported that a dataset containing client financial details and banking information appeared to have been published. The firm said it had notified affected individuals, the ACSC and the OAIC about this incident.

These were not large organisations. They were local accounting practices - the kind of businesses that hold tax and financial records, payroll, and identity document information of many local clients.

Such a set of valuable information is exactly what makes accounting firms attractive targets to cyber criminals.

Why accounting firms are valuable targets

Cybercriminals may target an accounting firm for money, but the greater attraction is often the client information and trusted access the firm holds for every client, going back years. This may include:

  • Tax file numbers
  • Bank account details
  • Financial statements
  • Payroll data such as clients’ employee names, addresses, salaries, bank and superannuation details
  • Identity documents information collected for verification
  • Director ID numbers
  • Trust, company and superannuation fund account details
  • Tax and lodgement access information like practice-management software, online services for agents, myID-linked access and authorisations that allow staff to act for their clients.

Together, these records can provide enough information for identity theft, tax fraud, and various elaborate, targeted scams.

Accounting and professional service firms are regularly affected by reportable data breaches. In 2025, the OAIC received 1,205 data breach notifications. Legal, accounting and management services accounted for 81 notifications, which is approximately 6.7% of the total. This placed the combined sector among the five highest by notification volume.

The information held by accountants for their clients can be used for identity crime, refund fraud and highly convincing scams.

What information attackers want

A stolen TFN isn't just sold once - it's put to work. Cybercriminals have used stolen identities to create fake myGov accounts, link them to real taxpayers' ATO records, then lodge fraudulent tax returns and activity statements, and redirect the refunds.

In the two years leading up to February 2023, the ATO cancelled more than 37,000 fraudulent tax returns and business activity statements with a claimed value of $557.8 million. This affected more than 15,000 taxpayers. Some claims were stopped before payment, and the ATO could not attribute the entire amount of claims to a single fraud method.

In February 2024, the ATO said it was defending its websites, services and infrastructure against an average of 4.7 million attempted cyber attacks each month. The ATO maintains dedicated data breach guidance for tax professionals so firms can report incidents quickly when client identities, tax information, or agent access may have been compromised.

How cyber attacks commonly happen

Three common attack paths show how a cyber incident may unfold:

  1. Phishing and email takeover. An employee receives a convincing email prompting them to enter their username and password on a fake but look-alike Microsoft 365 login page. The attacker gets the access and reads the mailbox for weeks, downloads client records, and uses the trusted address to send invoice-redirection emails to clients.
  2. Ransomware with data theft. An attacker gains access, quietly copies information, and may then encrypt systems before threatening to publish the stolen data. The MKA Accountants and Kennedy McLaughlin & Associates incidents were publicly associated with this type of attack. Paying a ransom does not guarantee that stolen data will be deleted or kept private.
  3. Credential theft against practice software and portals. Stolen logins for practice management systems or lodgement services give cybercriminals the same reach the practice has - across every client at once.

Highly sophisticated hacking is not always required. Many incidents begin with a stolen password, a phishing message, an unpatched system, or access that should have been removed.

What a breach can cost

In 2024-25, the average self-reported financial loss per cybercrime report from a small business was approximately $56,600, which is 14% higher than the previous year.

For an accounting practice, stolen money and ransomware demands are only the beginning. A data breach triggers a stack of obligations that most other small businesses never face. These may include:

  • Privacy Act and Notifiable Data Breaches scheme. Many small accounting practices are TFN recipients and may have Privacy Act obligations for the TFN information they hold, even when annual turnover is $3 million or less. They must notify the OAIC and affected individuals when the breach meets the legal test for an eligible data breach, including that it is likely to cause serious harm.
  • Tax Practitioners Board. Registered tax practitioners must report a significant breach of the Code of Professional Conduct to the TPB within 30 days of when they know, or ought to know, that the breach occurred. A cyber incident may trigger this obligation if it involves a significant breach of duties, such as client confidentiality or causes, or is likely to cause material loss or damage. Whether reporting is required depends on the circumstances.
  • ATO notification. Where client identities, TFNs, tax records or agent access may have been compromised, accounting firms should promptly contact the ATO, so it can assess and apply appropriate protections.
  • Professional standards. Members of professional accounting bodies, such as CPA Australia, may also have confidentiality obligations under APES 110, the Code of Ethics for Professional Accountants. Registered tax practitioners have separate confidentiality obligations under the TPB Code of Professional Conduct. A failure to take reasonable safeguards may also raise professional and ethical issues, depending on the circumstances.
  • Reputational damage and client attrition. Clients trust their accountants with everything. A public data leak can cause lasting damage to client trust and the firm’s reputation.

Controls that reduce the risk

The following controls help reduce the risks discussed above. And most of them are low effort changes.

ControlRisk it reducesEffort
MFA on email, practice software and tax-related accountsAccount takeover after password theftLow
Password manager and strong, unique passwordsPassword reuse and credential-stuffing attacksLow
Protected backup copyLoss of all recoverable copies during ransomwareMedium
Segregation of payment duties and independent verification of changed payment detailsInvoice and payment-redirection fraudLow
Practical staff training on phishing, unexpected MFA prompts and payment changesStaff responding to phishing, unexpected MFA prompts and approving fake payment requestsLow
Automatic security updates on operating systems and practice softwareExploitation of known vulnerabilities in unpatched softwareLow
Regular access reviews and offboarding checklist for staffUnnecessary access and active former-staff accessLow
Regular review of third-party, contractor and connected-app accessUnnecessary access by old providers, contractors or connected appsMedium
Sign-in and administrator alertsUndetected misuse of compromised accountsMedium
Data retention and secure deletionUnnecessary exposure of old client records and identity documentsMedium
Tested incident-response planDelayed containment and missed reporting stepsMedium

Four controls worth a closer look

Review what you keep. Retain records for the periods required by law and professional standards, but securely delete duplicate files, outdated identity documents, and other information, when there is no longer legal, professional, or business-related reasons to keep it. Holding less unnecessary information reduces the potential impact of a breach.

Review connected services. Check which cloud platforms, software integrations, contractors and service providers can access client information. Remove unused and unnecessary connections, confirm who has administrator access, and understand how each provider protects and backs up your data.

Train staff on real warning signs. Make sure employees know how to recognise suspicious login pages, unexpected MFA prompts and urgent payment requests. They should know who to contact and what to do before clicking, approving a prompt or making a payment.

Protect at least one backup copy. Keep one backup offline, immutable or otherwise protected from normal user accounts and devices. Test regularly that important files can be restored from it.

Use our DIY cyber security health check for a structured review of your accounts, payments, backups, devices and business processes.

Five actions to take this week

  1. Turn on MFA for every supported business account, beginning with email, administrator, financial and tax-related accounts. Where available, use phishing-resistant methods like passkeys or security keys.
  2. Give staff two clear rules:
    1. Never approve an MFA prompt they did not request. An unexpected prompt may mean someone is trying to access the account.
    2. Never change payment details based on an email alone. Confirm the request by calling a trusted phone number already held by the firm.
  3. Enable automatic security updates where supported. Keep computers, servers, browsers, practice software, remote access tools and internet-facing devices protected against known vulnerabilities.
  4. Review your user list. Check every account and access role. Promptly disable accounts belonging to former staff. Treat any unknown or suspicious account as urgent.
  5. Print your incident contacts. Include the ATO's data breach guidance for tax professionals, the OAIC, the TPB, ReportCyber and the Australian Cyber Security Hotline 1300 CYBER1 (1300 292 371). You should also include your IT or incident-response provider; cyber insurer and policy number; legal or privacy adviser; authorised decision-maker.

Cybercriminals target accounting firms because the information and access they hold can be highly valuable. The good news is that you can strengthen your defences with basic, consistent controls to make many common attack paths much harder for cybercriminals to execute.

Sources used

  • ASD, Annual Cyber Threat Report 2024-25
  • OAIC, Data breach notifications increase to all-time high in 2025
  • OAIC, Quick reference guide for responding to data breaches
  • OAIC, The Privacy (Tax File Number) Rule 2015 and the protection of TFN information
  • ATO, Agent checklist for client-to-agent linking process
  • ATO, Accessing Online services for agents
  • ATO, Data breach guidance for tax professionals
  • Australian Government, Privacy (Tax File Number) Rule 2015
  • TPB, Breach reporting obligations;
  • TPB, Protect your practice from cyber-attacks
  • TPB, Debunking myths about breach reporting
  • iTnews, ATO attackers filed $557 million in false claims
  • Cyber Daily, MKA Accountants confirms Qilin ransomware attack
  • Cyber Daily, Kennedy McLaughlin confirms cyber incident
  • ABC, Outgoing ATO boss says getting rid of work-related tax deductions would be a 'big step'
Share
Share

Frequently Asked Questions

Why would hackers target a small accounting firm instead of a big company

A small accounting firm may hold the same kinds of valuable client information as a big company, including TFNs, payroll records, bank details, and identity documents. At the same time, smaller firms may have fewer dedicated IT and security resources. This combination can make them attractive to cybercriminals.

Does the Privacy Act apply to my accounting practice if turnover is under $3 million?

Under the Privacy (Tax File Number) Rule 2015, many accounting practices with annual turnover of $3 million or less still have Privacy Act obligations because they receive and hold TFN information. If a breach is likely to cause serious harm, the practice may need to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. Other Privacy Act exceptions may also apply. Obtain legal or privacy advice for your circumstances.

What is the single most effective protection for an accounting firm?

Multi-factor authentication (MFA) is one of the most important protections for administrator, email, practice management software, and tax-related accounts. It adds another layer of protection if a password is stolen or phished.

What should an accounting firm do immediately after discovering a data breach?

Where safe and appropriate, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it, and seek qualified IT or incident-response support. Contact the ATO promptly if client tax information or agent access may be affected. The firm should then assess its notification obligations. These may include notifying the OAIC and affected individuals under the Notifiable Data Breaches scheme; the TPB where a significant Code of Professional Conduct breach may have occurred; professional associations; insurers; and other affected parties.

More To Explore

Latitude Financial Data Breach: Lessons for Small Businesses

Latitude Financial Data Breach: Lessons for Small Businesses

The 2023 Latitude Financial breach exposed approximately 14 million records, including information dating back to 2005. Here is what Australian businesses can learn about data retention, third-party access, stolen credentials and breach response.
What The Medibank Breach Teaches Small Businesses

What The Medibank Breach Teaches Small Businesses

The 2022 Medibank data breach made headlines, but the weaknesses that contributed to it are not unique to large companies. Here are the practical lessons small businesses can take from the incident.
The DIY Cyber Security Health Check for Small Business

The DIY Cyber Security Health Check for Small Business

A practical, jargon-free cyber security checklist you can complete this afternoon to see where your business is exposed - no IT department required.