Email hijacking and business email compromise: Why accountancy firms remain a prime target for cyber criminals
As cyber criminals become increasingly sophisticated, email hijacking remains one of the most effective and financially damaging attacks facing accountancy firms today. While the tactics used by attackers continue to evolve, the objective remains the same: gain access to a trusted email account, monitor communications, and exploit opportunities to steal money, sensitive information or both.
The threat is far from theoretical. According to the UK Government’s Cyber Security Breaches Survey 2025/26, 43% of UK businesses experienced a cyber security breach or attack during the previous 12 months, with phishing continuing to be the most common form of attack. Email remains one of the most effective routes into an organisation, particularly where staff are handling large volumes of financial and client-related communications.
For accountancy firms, the consequences can be particularly severe. A successful email hijacking attack can expose confidential client information, disrupt business operations, compromise payroll and tax data, and result in significant financial losses. In addition to regulatory and legal considerations, firms may also face serious reputational damage and a loss of client trust.
How do cyber criminals benefit from email hijacking?
Unlike ransomware attacks that immediately announce their presence, email hijacking attacks can be slow, deliberate and difficult to detect.
Once attackers gain access to an account, they may spend weeks or even months monitoring communications. Their objective is to identify opportunities to intercept payments, redirect funds, steal sensitive tax information or impersonate trusted individuals.
Many of these attacks ultimately become Business Email Compromise (BEC) incidents. By posing as a partner, finance manager, payroll specialist or client, cyber criminals can alter bank details, request urgent payments or obtain confidential financial information.
The longer an attacker remains undetected, the more intelligence they can gather and the greater the potential damage. Even a short window of access to email can provide attackers with sufficient information to launch further attacks against your organisation or your clients.
Why are accountancy firms such attractive targets?
Accountancy firms hold some of the most valuable information available to cyber criminals.
Many firms routinely process and store:
- Payroll information
- Tax records
- Client bank account details
- Financial statements
- VAT and corporation tax information
- Personal and commercially sensitive client data
- Access to cloud accounting and payroll platforms
Rather than targeting hundreds of individual businesses, cyber criminals can potentially access the financial information of multiple organisations through a single compromised accountancy practice. This concentration of sensitive data makes accountants an attractive target for attackers seeking financial gain, identity theft, fraud or extortion.
Recent examples from the accountancy sector
Recent incidents demonstrate the growing cyber threat facing accountancy firms.
One of the most significant examples involved the Optionis Group, now part of Caroola, which suffered a major ransomware attack that reportedly impacted thousands of clients and resulted in large volumes of sensitive data being exposed. The incident affected several accountancy and contractor services brands and highlighted the significant consequences that cyber incidents can have across an interconnected client base.
In another example, ransomware group Rhysida claimed responsibility for an attack against UK-based accountancy firm Sibbalds Chartered Accountants in 2025, demonstrating that small and mid-sized firms remain firmly within attackers' sights.
These incidents reinforce an important reality: cyber criminals are not solely targeting large enterprises. Firms of all sizes are at risk.
How do email hijacking attacks work in 2026?
While weak passwords remain a problem, modern attackers have expanded their toolkit considerably.
Today, email accounts are commonly compromised through:
- Phishing emails designed to steal usernames and passwords. This now includes AI-generated phishing campaigns that create highly convincing and personalised messages.
- Multi-factor authentication (MFA) fatigue attacks that pressure users into approving login requests.
- Session hijacking techniques that steal authenticated browser sessions and bypass MFA protections.
- Data breaches exposing credentials from third-party services.
Once access is obtained, attackers frequently create hidden forwarding rules, divert emails to private folders, or silently monitor conversations from within the compromised mailbox. Their objective is to remain invisible while gathering intelligence and identifying opportunities for fraud.
For accountancy firms, this often means monitoring communications relating to payroll processing, supplier payments, tax submissions, client bank details and financial approvals. Armed with this information, cyber criminals can impersonate trusted contacts, redirect payments, alter banking information or use stolen data in wider fraud and extortion schemes. Cyber criminals are also increasingly leveraging AI-powered social engineering techniques to create highly convincing emails, messages and even voice communications designed to bypass traditional security awareness measures.
What could happen if an accountancy firm is compromised?
The impact can extend far beyond a single mailbox.
Attackers may gain access to client financial records, tax returns, payroll data, employee information and commercially sensitive documents. In some cases, firms may discover that fraudulent payments have already been processed before the compromise is detected.
Payroll diversion fraud is an increasing concern. Criminals with access to payroll systems may alter bank details or create fictitious employees in an attempt to redirect funds. Equally, compromised email accounts can be used to send convincing payment requests to clients or suppliers.
In addition to direct financial losses, firms may face operational disruption, client notification requirements, data protection obligations and lasting reputational damage.
How can accountancy firms protect themselves?
No organisation can eliminate cyber risk entirely, but a layered approach significantly reduces the likelihood and impact of an attack.
Accountancy firms should ensure they:
- Enforce multi-factor authentication on all accounts.
- Monitor mailbox forwarding rules and suspicious login activity.
- Configure advanced security settings that are available in your email platform Disable legacy authentication methods.
- Enable mailbox auditing and security alerting.
- Conduct regular phishing awareness training.
- Monitor for compromised credentials on the dark web.
- Secure payroll and accounting platforms with strong access controls.
Ensure your email filtering configuration is set up to remove as much malicious and unwanted inbound email as possible Ensure you have defined Incident Response plans that include a suitable IR expert you can call upon.
Achieve Cyber Essentials certification or equivalent security standards.
Most importantly, cyber security should not be viewed solely as an IT responsibility. Everyone within the firm plays a role in protecting client data and maintaining the firm's security posture.
Staying one step ahead
The most damaging email hijacking attacks are often the ones that go unnoticed.
Modern cyber criminals are patient, organised and increasingly supported by automation and artificial intelligence. For accountancy firms handling sensitive financial information, tax records and payroll data, strong security controls, continuous monitoring and informed employees remain the most effective defences.
Cyber security is no longer simply an IT issue. It is a business-critical risk and a professional responsibility. Protecting client data, financial information and organisational reputation requires ongoing vigilance and a commitment to cyber resilience at every level of the firm.
Need help protecting your practice?
As a trusted cyber risk management partner to ICAS, Mitigo helps accountancy firms identify vulnerabilities, strengthen cyber resilience and protect the sensitive financial information entrusted to them by clients.
Whether you need support with Cyber Essentials certification, cyber security assessments, staff awareness training, managed security services or incident response planning, our team understands the unique risks facing the accountancy profession.
ICAS members receive 10% off a range of Mitigo cyber security services, designed specifically to help accountancy firms improve their cyber resilience and meet their professional obligations.
To discuss your firm's cyber security requirements or arrange a no-obligation consultation, contact Mitigo today.
Email: icas@mitigogroup.com
Phone: 0330 223 1869
Website: www.mitigogroup.com
This blog is one of a series of articles from our commercial partners, Mitigo. The views expressed are those of the author and not necessarily those of ICAS.
Categories:
- Practice
- Sponsored
- Member Rewards




