Ask a practice owner to name their firm's biggest asset and you will usually hear about the client base, the team or the recurring fee income. Very few will say "our agent services account". Yet that single set of credentials sits in front of the tax affairs of hundreds or even thousands of taxpayers, and it can be used to file returns, claim repayments and redirect money. Criminals worked this out some time ago.
While the profession has spent 2026 absorbed by quarterly updates, Companies House reform and the next wave of Making Tax Digital, the threat landscape has quietly become the most under-managed risk in UK practice. The Cyber Security Breaches Survey 2025/2026 found phishing to be by far the most common attack type, reported by 38 per cent of all UK businesses and present in 88 per cent of businesses that identified a breach. The Information Commissioner's Office receives data breach reports from roughly 100 UK accountants every quarter attributable to cyber attacks. Accountancy is not collateral damage in someone else's crime wave. It is a chosen target.
Firms often picture a faceless hacker brute-forcing a password. The reality reported by practitioners is far more patient and far more convincing.
A typical pattern runs like this. The firm receives a phone call from a prospective client, using the name of a genuine local business, explaining that they are struggling with HMRC and some late filings. A follow-up email arrives with what appears to be a PDF of an HMRC letter. It is not a PDF. It is a disguised link that silently installs remote access software, and in some reported cases the intruders then disable or hijack the firm's antivirus. They sit quietly for weeks, watching, learning the naming conventions, the client list and the working rhythm of the practice.
Then they act. Fraudulent VAT returns with large repayment claims. Self Assessment returns claiming Construction Industry Scheme refunds. Bank details switched to accounts the criminals control. In several reported cases the firm only discovered the breach when a partner noticed unfamiliar bank details against a client record. One practitioner described the aftermath as the worst experience of their working life, and said they genuinely considered walking away from the business they had spent years building.
That is the real cost. Not just the money, which HMRC may eventually recover, but the client notifications, the ICO report, the professional body report, the insurance claim, the rebuilt machines, the lost weeks and the quiet erosion of trust that follows.
Three things have changed the risk profile for practices this year.
There is also a hard truth about the agent services account itself. Multi-factor authentication on the agent gateway has long been a source of frustration for practitioners, who report that it is inconsistently enforced and does not always challenge a login from a familiar device or location. Firms cannot control HMRC's roadmap. They can control everything that sits in front of that login.
You do not need an enterprise security budget. You need a short list of controls applied consistently.
Most compromises are visible before they become expensive, if someone knows what to look for. Treat the following as an alarm rather than an annoyance:
Build a simple weekly habit of reviewing submissions and repayment positions across your client base. In the January and quarterly peaks, make it more frequent. If you are ever locked out of a government account, check daily until access is restored, because the criminals will be doing exactly that, and change the password the moment you get back in.
A breach is a project management problem under extreme time pressure. Decide the running order now, while you are calm, and write it down on one page:
Firms that handle the first 48 hours well tend to keep their clients. Firms that improvise rarely do.
Here is the commercial upside. Your clients are being targeted by the same criminals, usually with fewer defences and no in-house expertise. A practice that has genuinely tightened its own controls has earned the right to raise the subject, and it is a natural extension of the advisory conversations that quarterly reporting has already opened up.
Talk to clients about verifying changes to supplier bank details, about invoice redirection fraud, about who in their business can authorise a payment, and about the repayment scams that circulate every January. Some firms are packaging this as a paid resilience review. Others simply use it as a differentiator at the renewal conversation. Either way it positions you as the adviser who protects the business, not just the one who files the return.
None of this is glamorous, and none of it will feel urgent until the day it is the only thing that matters.
The profession has spent 2026 proving it can absorb enormous regulatory change. Cyber resilience deserves the same seriousness. Every quarterly update, every digital link and every client portal login has expanded the surface area of your practice, and criminals are watching that expansion closely.
Firms that keep client data in one controlled, well governed system rather than scattered across spreadsheets, inboxes and shared drives are structurally harder to attack and far faster to recover. Centralised client records, controlled access, secure document exchange and a clear audit trail of what was filed and when are not just efficiency features. They are the foundations of a defensible practice.
If you want to see how a single integrated platform can reduce both your admin burden and your risk exposure, book a TaxCalc demonstration and see how firms are filing faster while keeping client data under proper control.