Home Insights Security
Security

Tax-time scams: how accounting firms get targeted

Adam Dodds
Adam Dodds
22 July 2026 · 7 min read
Tax-time scams: how accounting firms get targeted

Tax time is your busiest season, and it is the scammers’ busiest season too. For an accounting firm, the mix of high volumes, tight deadlines and lots of money moving around is exactly the environment criminals look for. Here are the scams that spike at this time of year, and the practical steps that stop them.

Why accounting firms are such a prime target

Accountants sit on top of everything a criminal wants: client bank details, tax file numbers, refunds heading out the door, and the trust of dozens or hundreds of clients. Compromise one firm and you potentially get a path to many people’s money and personal information at once.

On top of that, tax season is genuinely hectic. When your team is processing returns at speed and juggling client requests, a well-timed fake email is far more likely to slip through. Scammers know this, so they lean in hard from July onwards.

The scams that spike at tax time

Payment and refund redirection

This is the big one. A criminal gets into (or convincingly spoofs) an email account, watches for a payment or refund, and sends a message that quietly changes the bank details. The classic version is a “we’ve updated our banking details, please use these for the refund” email. The money lands in the scammer’s account, and by the time anyone notices, it is gone. This kind of attack, often called business email compromise, is one of the most costly for Australian businesses.

ATO impersonation

Fake messages pretending to be the Australian Taxation Office flood inboxes and phones around tax time, aimed at both your staff and your clients. They promise a surprise refund or threaten a fake debt to pressure people into clicking a link or handing over details.

It helps everyone to know what the ATO will never do. The ATO will not send an email or text with a link asking you to log in to its online services. It will not demand immediate payment, threaten you with arrest, or ask you to pay a debt with gift cards, vouchers or cryptocurrency. And it will never ask you to pay a fee to release a refund. Anything doing those things is a scam.

Someone pretending to be you

A particularly nasty version turns the trust in your firm against your clients: the attacker emails your clients while posing as your firm, often about a refund or an outstanding payment. Because it looks like it came from their trusted accountant, people act on it. This is why protecting your own email (and being able to prove your messages are genuinely from you) matters so much.

Fake login pages

Many attacks start with a fake Microsoft 365 or myGov sign-in page. An email nudges a staff member to “verify your account” or “view a secure document,” they enter their password on a page that looks real, and the criminal now has the keys to a mailbox full of client data. From there, the redirection scams above become easy.

Malware hidden in “tax documents”

An attachment dressed up as an invoice, a BAS, or a client’s tax file can carry malware, including ransomware that locks up your systems at the worst possible time of year. A moment’s hesitation before opening an unexpected attachment saves a great deal of pain.

How to protect your firm

A few years ago the answer to all of this was “turn on multi-factor authentication.” It is still worth having, but on its own it is no longer enough: attackers now use fake login pages that capture your live sign-in session and sail straight past a basic code or approval prompt. Modern protection is layered, aligned to a recognised standard, and, for most firms, already sitting unused in the Microsoft 365 licences you pay for.

  • Align to the Essential Eight. The Essential Eight is the set of eight strategies the Australian Signals Directorate recommends every business start with. Reaching the first maturity level shuts off the majority of the techniques these scammers rely on, and gives you a clear, government-backed checklist instead of guesswork. It is the backbone of the IT security work we do.
  • Switch on the tools you already own. If you are on Microsoft 365 Business Premium (and most firms should be), you are already paying for enterprise-grade security that is often left switched off. The most powerful piece is conditional access with device compliance: you set rules so client data can only be opened from devices your firm manages and that meet your security standard. Even if a criminal steals a password and clears a login prompt, their own unknown laptop is simply refused entry. That is the control that answers today’s session-stealing attacks in a way a code on its own cannot, and getting Business Premium set up to actually do it is the heart of our Microsoft 365 optimisation service.
  • Keep multi-factor authentication on, as one layer. It still belongs in the mix, ideally using app-based or phishing-resistant methods rather than SMS codes. Just do not treat it as the finish line.
  • Verify every money change out loud. No technology replaces this habit. Any request to change bank details, from a client, a supplier or a colleague, should be confirmed by phone on a number you already have on file, never by replying to the email. This one rule defeats refund and invoice redirection outright.
  • Train your team and lock down your email. Regular, plain-English security awareness training helps staff spot phishing and impersonation before they click, while modern anti-phishing and anti-spoofing protection filters out many of these messages before anyone sees them, and stops criminals sending email that appears to come from your firm.
  • Back up and plan for the worst. Tested backups mean a ransomware attack is a bad day, not a lost season, and knowing who to call beforehand keeps a scare from becoming a crisis.
  • Prove it with SMB1001. Once the controls are in place, SMB1001 lets you certify your firm against a recognised Australian cyber security standard, so you can show clients, referrers and insurers that you take their data seriously. For an accounting firm, that is fast becoming a competitive advantage as much as a security one.

This is the kind of layered protection we build for accounting and finance firms as part of our accounting IT services, and it lines up with the phishing defences in our guide to building a human firewall.

Help your clients spot it too

A quick heads-up to clients at the start of tax season pays for itself. Share the simple rules: the ATO will never send a link to log in or ask for payment by gift card or crypto; treat any “our bank details have changed” message with suspicion and confirm it by phone; and if a refund or bill arrives out of the blue, check directly through official channels rather than clicking. If something looks off, they can report it to the ATO and to Scamwatch (scamwatch.gov.au).

The bottom line

Tax-time scams work by catching busy people at their busiest, and the defence has moved on from “just turn on MFA.” You beat them by aligning to the Essential Eight, switching on the security already built into Microsoft 365 Business Premium so that only your trusted, managed devices can reach client data, keeping the firm habit of verifying money changes by phone, and backing it with a trained team. Certifying the result with SMB1001 then proves to your clients that you have done it. Get those right and you have closed the doors the criminals rely on.

If you would like a hand making sure your firm is protected before the season really ramps up, our team is happy to take a look, in plain English and with no obligation. See our accounting IT services or get in touch for a quick chat.

Adam Dodds
Adam Dodds

Adam leads the Itopia team in Brisbane, helping professional-services firms get secure, productive and confident with their technology, in plain English.

Keep reading

Related insights

Security
7 min read

Passkeys explained: the beginning of the end for passwords

Read more →
Security
5 min read

Before you switch on Copilot: the data-governance checklist

Read more →
Security
3 min read

Top 10 cyber security companies in Brisbane 2025

Read more →

Want IT advice tailored to your business?

Talk to a local Brisbane technician, no jargon, no obligation.

Get a Quote Call 07 3063 2211