Accountancy practices and bookkeepers sit in an unusual position when it comes to cybersecurity. You hold sensitive financial information for dozens or hundreds of clients — tax records, bank details, payroll data, Companies House credentials — but you’re often a small team without dedicated IT support. Criminals have noticed.
The fraud attempts targeting accountants are specific to the profession: HMRC impersonation at tax return deadlines, fake client invoice requests, payroll redirection scams, and credential theft targeting cloud accounting software. Understanding what the threats actually look like is the first step to protecting against them.
Why Accountancy Practices Are Targeted
You hold valuable credentials: HMRC agent credentials, Xero/Sage/QuickBooks logins, and Companies House access are highly valuable to criminals. With your HMRC credentials, a fraudster can redirect client tax refunds. With your accounting software access, they can view all client financial data and manipulate transactions.
You receive and make large payments: Accountancy practices routinely instruct bank transfers for clients, handle payroll, and pay suppliers. A successful business email compromise attack can misdirect substantial sums in a single transaction.
You have trusted relationships criminals can exploit: Clients trust you. If an email purportedly from your practice asks a client to update their bank details, many will comply without questioning it. Similarly, your relationship with HMRC means attackers impersonating HMRC get more engagement from accountants than from the general public.
The timing pressure at deadlines: January 31st, July 31st, and corporation tax deadlines create stress and time pressure. Criminals deliberately send phishing attacks during these windows, knowing staff are more likely to act quickly without pausing to verify.
The Specific Threats to Watch
HMRC Credential Phishing
HMRC does not proactively contact agents or clients by email asking them to log in, update payment details, or verify identity. Any email asking you to click a link to your HMRC Online Services account should be treated as suspicious.
The attack pattern: you receive an email that looks like an HMRC notification about a client’s tax code or refund. The link goes to a convincing fake HMRC login page that captures your agent credentials. Within hours, those credentials are used to redirect client refunds to criminal bank accounts.
What to do:
- Always navigate to HMRC services by typing the URL directly (www.gov.uk/government/organisations/hm-revenue-customs)
- Enable two-step verification on your HMRC Online Services account — go to your account settings and add an authenticator app or phone number
- Report HMRC phishing to phishing@hmrc.gov.uk
Client Impersonation and Mandate Fraud
A criminal who has been monitoring your email — perhaps after compromising a client’s email account — sends an instruction from the client’s address: “Please update my bank details for future payroll payments / tax refunds / reimbursements.”
Because the email comes from a genuine client address, it bypasses spam filters and looks entirely legitimate.
Defence: Establish a verbal verification policy. Any request to change bank account details — from any client, via any channel — requires a phone call to the client’s registered number to confirm. Hardcode this into your practice procedures so it’s not a judgment call in the moment.
Payroll Redirection
Similar to mandate fraud but targeting payroll specifically. A criminal impersonating an employee (often a senior one) requests a change to their salary payment account just before payroll runs.
The defence is the same: a phone call to the employee’s known number to confirm the request before making any banking change.
Ransomware Targeting Accountancy Data
Ransomware groups specifically know that time-sensitive financial deadlines give them leverage. A practice hit by ransomware in late January will be strongly motivated to pay quickly to restore client data before the self-assessment deadline.
Your most important protection is tested backups. The practice’s client data — whether in your accounting software, in client folders on a server or cloud storage, or in email archives — needs regular, tested backups stored somewhere the ransomware can’t reach. If your backup is on the same server as your data, it gets encrypted too.
Use your cloud accounting software’s built-in backup/export features regularly. Store exports in a separate cloud storage account (one that isn’t connected to your main workstations). Verify you can actually restore from them by doing so periodically.
Securing Your HMRC Agent Account
Enable two-step verification: Go to HMRC Online Services → Your account → Manage two-step verification. Use an authenticator app (Google Authenticator or Authy) rather than SMS if possible — SMS can be intercepted.
Review who has access: If you have staff who have left, remove their access immediately. HMRC agent accounts can have sub-accounts for individual staff members — use them rather than sharing a single login.
Use a strong, unique password: Your HMRC agent login should use a password that exists nowhere else. Use a password manager (Bitwarden is free; 1Password and Dashlane are good paid options) to generate and store it.
Monitor for unexpected activity: Log in to your HMRC agent account periodically and check for any unexpected submissions, refunds, or account changes. HMRC also sends notifications by post for significant account changes.
Securing Your Cloud Accounting Software
Xero, Sage, QuickBooks, and FreeAgent all support multi-factor authentication. Enable it — it means that stolen credentials alone are not sufficient to access your client data.
Audit who has access to each client’s data. Many practices set up broad access during onboarding and never tighten it. In Xero: go to Settings → Users and review the access level for each user.
For client advisory access: use the software’s official advisor invitation system rather than sharing login credentials. This creates an audit trail and lets you revoke access cleanly if needed.
Email: Your Biggest Attack Surface
Most attacks on accountancy practices arrive via email. The highest-impact steps:
Set up DMARC on your domain: This prevents criminals from sending emails that appear to come from your practice’s domain — a common vector for attacking your clients. Your email host or IT contact can do this; it typically takes about 30 minutes. If you have a business email with Google Workspace or Microsoft 365, DMARC setup guides are available in their admin panels.
Train your team to verify suspicious emails: HMRC, banks, ICAEW, and accountancy software providers do not ask you to click links to re-enter credentials. If an email asks you to log in and verify something, go directly to the service’s website in a new browser tab rather than clicking the link.
Enable external email warnings: Microsoft 365 and Google Workspace can tag emails from outside your organisation with a banner. This makes it visually obvious when an email claiming to be from a colleague is actually from an external address.
The GDPR Dimension
Accountancy practices are data processors (and often data controllers) under UK GDPR. A data breach — whether through phishing, ransomware, or accidental disclosure — must be reported to the ICO within 72 hours if it’s likely to result in risk to individuals.
ICAEW and AAT members also have professional obligations around client data protection. A breach that triggers ICO enforcement action can also lead to professional conduct proceedings.
The practical implication: a ransomware attack or credential theft that exposes client financial data isn’t just an operational problem, it’s a reporting requirement. Having a documented incident response plan — who to call, what to preserve, how to notify the ICO — before an incident happens is worth the hour it takes to write.
The ICO provides a self-reporting portal at ico.org.uk/make-a-complaint/. NCSC’s Cyber Incident Response guidance at ncsc.gov.uk is the starting point for managing the incident itself.
Making Tax Digital and Security
MTD has pushed accounting into cloud-based software for most practices. The security benefit of cloud accounting is that reputable providers (Xero, QuickBooks, Sage, FreeAgent) invest heavily in their own security — your client data in their systems is better protected than data on a local server you manage.
The risk shifts to credential security — your login to the software — and to the API integrations. MTD-compatible software talks to HMRC’s API, which means a compromised practice account can interact with HMRC on behalf of all your clients.
Check what third-party apps and integrations have access to your accounting software. In Xero: Settings → Connected Apps shows everything with API access. Remove anything you’re not actively using.
Quick-Win Security Checklist
- Enable two-step verification on HMRC Online Services
- Enable MFA on your cloud accounting software (Xero, QBO, Sage)
- Set a verbal verification policy for bank detail changes
- Test that you can restore from your client data backups
- Set up DMARC on your email domain
- Review and remove old staff access from all systems
- Check connected apps in your accounting software and remove unused ones
- Register for the NCSC’s free Cyber Action Plan at cyberassessment.ncsc.gov.uk
Most of these take under an hour each. A practice that works through this list is substantially more resilient than the average UK accountancy firm.