1800 868 620 enquiry@bci.net.au

The Biggest Cyber Risk to Your Accounting Firm Isn’t a Hacker. It’s Someone Pretending to Be You.

For an accounting firm, trust is one of your greatest assets. Clients trust your advice, your financial reports, your payment instructions and, importantly, that every email coming from your business is genuine. That trust can take years to build—and unfortunately, criminals understand exactly how valuable it is. A recent study examined the domains of 275 Australian accounting firms to answer one simple question:

Could someone impersonate your business by sending emails that appear to come from your domain?

The findings were alarming. Around 76% of the firms examined had not fully configured the protections designed to prevent fraudulent emails from being sent in their name. What is particularly surprising is that this was not necessarily because the firms had ignored cybersecurity or failed to invest in technology. In many cases, they had already completed most of the required work. The missing piece was often the final configuration that tells other email providers to reject messages pretending to come from the firm’s domain. That seemingly small oversight creates a significant opportunity for scammers and, for an accounting firm, impersonation can be just as damaging as someone directly hacking into its systems.

Why Accounting Firms Are Attractive Targets

Accounting firms regularly handle highly sensitive and commercially valuable information. Clients expect to receive emails requesting financial statements, tax documents, payroll information, payment instructions, banking details and access to accounting platforms. These are ordinary interactions between an accountant and their client, which means they do not always raise immediate suspicion. That familiarity is exactly what scammers rely on. A criminal does not necessarily need to break into the accounting firm’s systems. They may simply need to create an email that looks as though it has come from the firm, a partner, a director or a trusted staff member. An employee might receive an urgent email that appears to come from a partner asking for an immediate bank transfer. A client may be told that the firm’s bank account details have changed shortly before paying an invoice. A supplier could receive updated payment instructions, or a business owner might be asked to upload confidential financial records through what appears to be a secure client portal. In some cases, the fraudulent email may even refer to a real transaction, staff member or upcoming deadline, making the request appear more credible. The scam works because the recipient already trusts the name appearing in front of them.

Impersonation Is Becoming More Convincing

As artificial intelligence continues to evolve, these fraudulent communications are becoming increasingly difficult to identify. Poor spelling, unusual wording and obvious formatting errors were once common warning signs. Today, scam emails can be professionally written, carefully structured and almost indistinguishable from genuine business communication. Branding can be copied, email signatures can be replicated and publicly available information from websites and LinkedIn profiles can be used to identify staff, clients and business relationships. Scammers can also imitate the tone, language and communication style of legitimate businesses, meaning an email may sound exactly like the partner, manager or adviser the recipient regularly speaks with. For accounting firms, this creates a serious risk. A convincing fraudulent email may not only result in financial loss—it can also damage the relationship between the firm and the client who believed the communication was genuine. The immediate consequences may include lost funds, exposed financial records or compromised login details, but the longer-term consequences can be even more damaging.

The Damage Goes Beyond the Initial Scam

Clients may begin questioning whether they can trust future payment instructions. Staff may become reluctant to send confidential documents electronically. Referral partners may reconsider recommending the firm. Management may also be forced to spend significant time investigating the incident, contacting affected clients and repairing the reputational damage. Even when the firm’s internal systems were never breached, clients may still associate the fraudulent email with the firm’s name. That is why email impersonation is not simply a technical problem. It is a business continuity issue, a client relationship issue and a potential threat to the value of the firm itself. For a professional services business, reputation, client loyalty and goodwill can represent a substantial part of its overall value. Anything that weakens confidence in the firm can therefore have broader commercial consequences.

Many Firms Are Almost Fully Protected

The study does not suggest that accounting firms are failing to take cybersecurity seriously. If anything, it shows that many firms are almost there. They have invested in the right email systems, security software and IT support but have stopped just short of fully protecting one of their most valuable assets—their identity. The final step is often ensuring the firm’s email authentication settings are properly configured and enforced. These settings include SPF, DKIM and DMARC. While the terminology may sound technical, their purpose is relatively straightforward: they help email providers confirm whether a message was genuinely authorised by the domain it claims to represent. Without the correct settings, a fraudulent email may still reach a client’s inbox appearing to have come from the firm. With the appropriate protections in place, suspicious emails can be rejected or quarantined before they reach the recipient.

Trust Cannot Simply Be Reinstalled

Technology can always be upgraded. Trust cannot. For professional services businesses, reputation is everything. Protecting your identity should therefore be considered just as important as protecting your computers, servers and accounting systems. The bottom line is that email impersonation is not merely an IT issue. It is a business risk, a client trust issue and, ultimately, a reputational risk. The fact that 76% of the accounting firms examined remained exposed should be a wake-up call—not because the solution is necessarily expensive or complex, but because it may come down to one final configuration step. Cybersecurity is no longer only about stopping someone from entering your systems. It is also about stopping someone from borrowing your identity and using the trust attached to your name. For many firms, resolving this may not require a major technology project. Depending on the firm’s existing setup, the necessary changes can often be reviewed and implemented relatively quickly by an experienced IT provider. A few configuration changes today could prevent someone from impersonating your business tomorrow. If you have not recently reviewed your email authentication settings, including SPF, DKIM and DMARC, now may be a good time to ask your IT provider one direct question:

“Can someone send an email pretending to be our firm today?”

You may also want to ask whether your settings are simply recording suspicious activity or actively instructing email providers to reject fraudulent messages. Having the technology in place is not always the same as having it fully enforced.

If the answer is yes—or your provider cannot confidently confirm that impersonated emails will be blocked—it is worth addressing before someone else takes advantage of the gap.

Your clients already trust your name. Make sure nobody else can use it.

 

 

 

If you want to know more feel free to reach out. Contact us for personalised assistance and expert guidance.

Regards,
Tony Arena