TL;DR:

  • Accountancy practices are specifically targeted by criminals for their access to client bank accounts, payroll systems, and HMRC credentials
  • Mandate fraud — changing payment details mid-transaction — is the highest-volume threat for practices handling client supplier payments
  • MTD (Making Tax Digital) and cloud accounting platforms create new attack surfaces that require specific security settings to be hardened

An accountancy practice with 150 business clients has something criminals want: access to those clients’ bank accounts, payroll systems, VAT records, and HMRC credentials. A successful attack on a small practice doesn’t just harm the practice — it creates liability to every client whose data was compromised, and potentially enables direct financial fraud against those clients’ suppliers and employees.

The ICO’s enforcement record includes numerous accountancy practices fined for data breaches, and Action Fraud receives thousands of reports annually from businesses that lost money through fraud enabled by compromised accountancy credentials. This is a high-risk sector that is frequently under-protected.

The Specific Threats to Accountants and Bookkeepers

Mandate fraud targeting client payments: This is the highest-frequency financial fraud affecting practices that handle client payment runs. The pattern: a criminal impersonates a supplier and contacts your practice (or your client) claiming their bank details have changed. If the practice updates payment details without verifying directly with the supplier by phone, the next payment goes to the criminal’s account. Practices handling supplier payments, payroll, or any client disbursements are at risk on every transaction.

Credential theft for HMRC systems: Your HMRC agent credentials give access to your clients’ tax affairs — VAT, PAYE, corporation tax. Criminals who obtain these credentials can submit fraudulent VAT repayment claims, alter PAYE records, or access sensitive financial information that enables identity fraud. Phishing emails impersonating HMRC are consistently among the most convincing seen in the UK — the brand authority of HMRC makes recipients less likely to question the email.

Cloud accounting platform compromise: Xero, QuickBooks, FreeAgent and Sage are the dominant platforms for UK small business accounting. Access to a client’s cloud accounting credentials gives a criminal visibility into every transaction, the ability to raise fraudulent invoices, and, in platforms with payment integrations, potential to redirect funds. Practices that use the same credentials across multiple client accounts amplify this risk.

Ransomware targeting practice files: Practices hold years of client records — tax returns, management accounts, payroll histories. Ransomware that encrypts these files creates both a recovery crisis and a data breach notification obligation under UK GDPR. Practices using local file servers are particularly vulnerable; cloud-only practices with proper access controls are somewhat less exposed, but not immune.

ICAEW and HMRC Guidance

The Institute of Chartered Accountants in England and Wales (ICAEW) has published specific cybersecurity guidance for member practices, and HMRC maintains guidance on protecting agent credentials. Both emphasise multi-factor authentication and the dangers of mandate fraud.

HMRC’s agent services accounts now support MFA — enable it immediately if you haven’t. HMRC will not request credential changes by email; any such email is a phishing attempt.

Practical Security Steps for Practices

Multi-Factor Authentication on Everything

This is the single most impactful control. Enable MFA on:

  • HMRC Agent Services Account and older HMRC online services logins
  • Xero, QuickBooks, FreeAgent, Sage — all cloud accounting platforms
  • Practice management software (Iris, TaxCalc, CCH, etc.)
  • Practice email accounts — Microsoft 365 or Google Workspace
  • Companies House WebFiling and CHS portal
  • NEST, Peoples Pension, and any other pension provider portals

Most of these platforms support MFA and it costs nothing to enable. An account protected by MFA is dramatically harder to compromise even if the password is stolen.

Mandate Fraud Controls

Establish a written procedure for any change to payment details:

  1. Receive request for bank detail change (email, letter, or phone call from unknown number)
  2. Do not use contact details in the request
  3. Call the supplier or client back on a number you already have on file or find independently
  4. Verbally confirm the change
  5. Document the verification and by whom

This procedure sounds obvious. It isn’t always followed under time pressure. Make it mandatory and ensure all staff know they should not override it regardless of the apparent urgency of the request.

Cloud Accounting Security Settings

For every client cloud accounting platform you have access to:

  • Review who else has admin access — remove former employees or accountants who no longer work on the account
  • Check whether bank feeds are connected, and whether those connections have been authorised by the client recently
  • Review user roles: practice staff should have the minimum access level needed for their work
  • Enable audit trails — Xero, QuickBooks, and FreeAgent all log who accessed what and when; this is invaluable after an incident

For your own practice Xero or accounting platform subscription (not client accounts), apply the same controls and audit the access list quarterly.

HMRC Credential Protection

  • Never share HMRC agent credentials with clients
  • Never share them between practice staff — each user should have their own HMRC login linked to the agent account
  • Enable MFA on the agent services account
  • Review which client tax accounts are linked to your agent account annually; remove clients who are no longer served by your practice
  • If you receive a call claiming to be from HMRC asking for credentials, hang up. HMRC does not call to ask for login details.

Email Security

Business email compromise — where criminals impersonate your practice or your clients to redirect payments — is straightforward to set up and hard to detect without proper email authentication.

Set up DMARC on your practice domain. This prevents criminals from sending emails that appear to come from your domain to your clients. Your IT provider or email host can do this; it typically takes under an hour.

Enable external email banners in Microsoft 365 or Google Workspace — a visual indicator that an email came from outside your organisation helps staff spot impersonation attempts.

Making Tax Digital Specific Risks

MTD for Income Tax Self Assessment (ITSA) is rolling out from April 2026 for larger self-employed businesses and landlords. The new bridging software and MTD-compatible platforms create additional attack surface:

  • Vet any new MTD software you adopt — ensure it is listed on HMRC’s approved software list
  • Be cautious about browser extensions or plugins claiming to “simplify” MTD submissions — these can intercept your HMRC credentials
  • Train clients who are submitting their own MTD records on the phishing risks specific to digital tax submissions

Incident Response: What to Do If You’re Compromised

If you suspect your practice has been compromised:

  1. Isolate affected devices from the network immediately
  2. Contact your practice insurance (cyber liability cover, or professional indemnity if that includes cyber) — check before an incident what’s covered
  3. Notify HMRC if agent credentials may have been compromised: HMRC has a dedicated agent credentials compromise line
  4. Report to Action Fraud: 0300 123 2040 or actionfraud.police.uk
  5. Notify the ICO within 72 hours if personal data belonging to clients was accessed
  6. Notify affected clients promptly — they need to review their bank accounts and tax records

The ICO takes a significantly more lenient view of breaches when the affected organisation had demonstrable security controls in place and responded promptly. Document your security measures and your incident response — both matter if a breach occurs.

Quick Checklist

  • MFA enabled on HMRC agent account
  • MFA enabled on all cloud accounting platforms
  • MFA enabled on practice email
  • Written mandate fraud verification procedure in place and communicated to all staff
  • DMARC configured on practice email domain
  • Access audit completed for all client cloud accounting accounts
  • Cyber liability insurance checked for coverage scope

Accountancy practices typically hold more sensitive data per employee than almost any other business type. The security investment required to protect it is modest compared to the regulatory, financial, and reputational consequence of a breach.