In May 2025, the Qilin ransomware group listed Melbourne accounting practice MKA Accountants on its darknet leak site. The group published 12 sample documents it claimed were taken from the firm, including financial statements, insurance information and internal correspondence.
MKA Accountants confirmed that it was investigating unauthorised access and had notified clients and relevant authorities, including the Australian Cyber Security Centre (ACSC) and the Office of the Australian Information Commissioner (OAIC). Later reports said Qilin claimed to have released more than 185GB of data, although the exact volume was not independently confirmed.
In May 2026, Brisbane accounting firm Kennedy McLaughlin & Associates confirmed unauthorised access to part of its IT environment after the same ransomware group listed it on their darknet leak site. Cyber Daily reported that a dataset containing client financial details and banking information appeared to have been published. The firm said it had notified affected individuals, the ACSC and the OAIC about this incident.
These were not large organisations. They were local accounting practices - the kind of businesses that hold tax and financial records, payroll, and identity document information of many local clients.
Such a set of valuable information is exactly what makes accounting firms attractive targets to cyber criminals.
Cybercriminals may target an accounting firm for money, but the greater attraction is often the client information and trusted access the firm holds for every client, going back years. This may include:
Together, these records can provide enough information for identity theft, tax fraud, and various elaborate, targeted scams.
Accounting and professional service firms are regularly affected by reportable data breaches. In 2025, the OAIC received 1,205 data breach notifications. Legal, accounting and management services accounted for 81 notifications, which is approximately 6.7% of the total. This placed the combined sector among the five highest by notification volume.
The information held by accountants for their clients can be used for identity crime, refund fraud and highly convincing scams.
A stolen TFN isn't just sold once - it's put to work. Cybercriminals have used stolen identities to create fake myGov accounts, link them to real taxpayers' ATO records, then lodge fraudulent tax returns and activity statements, and redirect the refunds.
In the two years leading up to February 2023, the ATO cancelled more than 37,000 fraudulent tax returns and business activity statements with a claimed value of $557.8 million. This affected more than 15,000 taxpayers. Some claims were stopped before payment, and the ATO could not attribute the entire amount of claims to a single fraud method.
In February 2024, the ATO said it was defending its websites, services and infrastructure against an average of 4.7 million attempted cyber attacks each month. The ATO maintains dedicated data breach guidance for tax professionals so firms can report incidents quickly when client identities, tax information, or agent access may have been compromised.
Three common attack paths show how a cyber incident may unfold:
Highly sophisticated hacking is not always required. Many incidents begin with a stolen password, a phishing message, an unpatched system, or access that should have been removed.
In 2024-25, the average self-reported financial loss per cybercrime report from a small business was approximately $56,600, which is 14% higher than the previous year.
For an accounting practice, stolen money and ransomware demands are only the beginning. A data breach triggers a stack of obligations that most other small businesses never face. These may include:
The following controls help reduce the risks discussed above. And most of them are low effort changes.
| Control | Risk it reduces | Effort |
|---|---|---|
| MFA on email, practice software and tax-related accounts | Account takeover after password theft | Low |
| Password manager and strong, unique passwords | Password reuse and credential-stuffing attacks | Low |
| Protected backup copy | Loss of all recoverable copies during ransomware | Medium |
| Segregation of payment duties and independent verification of changed payment details | Invoice and payment-redirection fraud | Low |
| Practical staff training on phishing, unexpected MFA prompts and payment changes | Staff responding to phishing, unexpected MFA prompts and approving fake payment requests | Low |
| Automatic security updates on operating systems and practice software | Exploitation of known vulnerabilities in unpatched software | Low |
| Regular access reviews and offboarding checklist for staff | Unnecessary access and active former-staff access | Low |
| Regular review of third-party, contractor and connected-app access | Unnecessary access by old providers, contractors or connected apps | Medium |
| Sign-in and administrator alerts | Undetected misuse of compromised accounts | Medium |
| Data retention and secure deletion | Unnecessary exposure of old client records and identity documents | Medium |
| Tested incident-response plan | Delayed containment and missed reporting steps | Medium |
Review what you keep. Retain records for the periods required by law and professional standards, but securely delete duplicate files, outdated identity documents, and other information, when there is no longer legal, professional, or business-related reasons to keep it. Holding less unnecessary information reduces the potential impact of a breach.
Review connected services. Check which cloud platforms, software integrations, contractors and service providers can access client information. Remove unused and unnecessary connections, confirm who has administrator access, and understand how each provider protects and backs up your data.
Train staff on real warning signs. Make sure employees know how to recognise suspicious login pages, unexpected MFA prompts and urgent payment requests. They should know who to contact and what to do before clicking, approving a prompt or making a payment.
Protect at least one backup copy. Keep one backup offline, immutable or otherwise protected from normal user accounts and devices. Test regularly that important files can be restored from it.
Use our DIY cyber security health check for a structured review of your accounts, payments, backups, devices and business processes.
Cybercriminals target accounting firms because the information and access they hold can be highly valuable. The good news is that you can strengthen your defences with basic, consistent controls to make many common attack paths much harder for cybercriminals to execute.
A small accounting firm may hold the same kinds of valuable client information as a big company, including TFNs, payroll records, bank details, and identity documents. At the same time, smaller firms may have fewer dedicated IT and security resources. This combination can make them attractive to cybercriminals.
Under the Privacy (Tax File Number) Rule 2015, many accounting practices with annual turnover of $3 million or less still have Privacy Act obligations because they receive and hold TFN information. If a breach is likely to cause serious harm, the practice may need to notify the OAIC and affected individuals under the Notifiable Data Breaches scheme. Other Privacy Act exceptions may also apply. Obtain legal or privacy advice for your circumstances.
Multi-factor authentication (MFA) is one of the most important protections for administrator, email, practice management software, and tax-related accounts. It adds another layer of protection if a password is stolen or phished.
Where safe and appropriate, disconnect an affected computer from Wi-Fi or the network without wiping or resetting it, and seek qualified IT or incident-response support. Contact the ATO promptly if client tax information or agent access may be affected. The firm should then assess its notification obligations. These may include notifying the OAIC and affected individuals under the Notifiable Data Breaches scheme; the TPB where a significant Code of Professional Conduct breach may have occurred; professional associations; insurers; and other affected parties.


