Why attackers love accountancy firms

If you wanted to steal money by email, where would you start?
You'd want somewhere money already moves by email. Where payment requests are routine. Where clients are used to being asked for transfers, bank details get updated without ceremony, and nobody blinks at an invoice.
You'd start with an accountancy firm.
The Perfect Target
This isn't a hypothetical. According to ICO data highlighted by the ICAEW, around 100 UK accountants report data breaches caused by cyber attacks every single quarter. And those are just the incidents serious enough to legally require reporting - the real number is higher.
The reasons are obvious once you think like an attacker. An accountancy practice holds bank details, payroll data, tax records and identity documents for hundreds of clients in one place. It sits in the middle of a constant flow of payment instructions. And critically, its emails carry authority - when an accountant asks a client to pay something, the client pays it.
That last part is what makes the sector special. Most businesses are targets because of what they have. Accountancy firms are targets because of what their emails can do.
The Fraud That Doesn't Need a Hack
Here's the uncomfortable truth about most attacks on practices: nothing gets "hacked" in the Hollywood sense. Nobody breaks through a firewall.
Instead, an attacker gets into one inbox - usually through a phishing email or a remote access tool with no multi-factor authentication - and then simply joins the conversation. They watch how the firm writes. They wait for a live payment thread. Then they send a request that looks exactly like business as usual: an invoice, a change of bank details, an urgent transfer.
The numbers show how well it works. Fake invoice fraud is now the single most common fraud type experienced by UK businesses - 11% were hit in a year, with a further 7% experiencing mandate fraud, where bank details get switched to divert payments. UK Finance figures put losses to invoice and mandate scams at £49 million in 2024 and 78% of that money came out of business accounts, not personal ones.
And the gateway is almost always the same. The Government's Cyber Security Breaches Survey found phishing was experienced by 38% of UK businesses last year, and was rated the most disruptive attack type by 69% of those it hit.
We've seen this play out first-hand. A practice we'd recently taken on had been told they needed MFA on their remote access software - it was one of the first things we flagged. Before the controls were in place, an attacker got into the tool, walked straight onto a machine, and sent an email from the firm's own accounts inbox asking the owner to transfer money. No malware. No clever code. Just a missing security layer that takes minutes to switch on.
Your Client Finds Out First
Now the part that really stings.
When a compromised practice starts sending fraudulent payment requests, who spots it? Almost never the firm. It's the client, calling to say "this doesn't sound like you" or "it's odd for you to ask me for this."
Sit with that for a moment. Your client protected themselves from you. They caught your breach before you did.
For most businesses, a breach costs money and time. For an accountancy practice, it costs the thing the entire practice is built on: the assumption that what comes from you can be trusted. Money and time can be recovered. That assumption recovers much more slowly - which is exactly why so many breached firms never publicly explain what happened.
The Defences Are Boring. That's the Good News.
None of this requires an enterprise security budget. The attacks succeed because basic layers are missing - which means basic layers stop them.
MFA everywhere, no exceptions. Every email account, every cloud app, every remote access tool. Including the partners - especially the partners, who tend to have the most access and the laxest rules.
External email banners. A simple flag on every message from outside the organisation. Costs nothing to switch on in Microsoft 365. Makes imposters visibly foreign.
Staff trained to second-guess the routine. Any change of bank details, any urgent payment request - verified by phone, on a known number, never by replying to the email. Every member of staff, including during the January rush, when attackers know everyone is too busy to check.
Monitoring that notices when something's off. Sign-ins from odd locations, forwarding rules nobody set up, behaviour that doesn't fit the pattern. The earlier it's seen, the smaller the story.
The firms that put these in place before an incident never have to send the awkward email to their client list. The pattern, in our experience, really is that consistent.
Find Out Where Your Practice Stands
If you run a practice and you're not certain which of those layers are actually in place, our free Business IT Health Check will tell you. It takes less than 5 minutes, it's written in plain English, and there's no hard sell at the end. Just an honest picture of where you stand, before someone else finds out for you.

