News

Accountancy firms: your client data is a magnet for hackers

Tax Manager · Fiduciary Lausanne

Accountancy firms: your client data is a magnet for hackers

An accountancy firm is not merely an administrative service provider. It is a digital safe where bank accounts, identity documents, salaries, tax returns, contracts, balance sheets and sensitive correspondence all come together. For a Swiss SME, the accountancy firm is often the hub of the company’s financial operations. For a cybercriminal, this concentration of information represents a highly valuable target.

Recent events serve as a stark reminder of this. According to Clubic, on 20 August the Everest ransomware group claimed responsibility for hacking the firm Experts Entreprendre, stating that it held 1.13 TB of data spread across more than 2.6 million files, including annual accounts, tax returns, payslips, contracts and clients’ identity documents. Although the example cited relates to France, the message applies equally to Switzerland: trust firms and the accounting departments of SMEs can no longer treat cybersecurity as a purely IT matter.

The fiduciary firm: the gateway to an entire client portfolio

What sets an accountancy firm apart is the variety of data it handles. A client file contains more than just a few journal entries. It may include the identities of directors, bank details, accounts payable and receivable, payroll documents, tax information, commercial contracts, statements and, at times, highly personal supporting documents. In an SME, these elements provide an insight into how the business receives and makes payments, recruits staff, finances its investments and meets its obligations.

This wealth of documentation changes the nature of the risk. A breach of an email system or an accounting portal does not grant access to a single isolated document, but potentially to an entire chain of transactions. The attacker can exploit the data to orchestrate payment fraud, impersonate a company, mimic a genuine exchange with a client, or exert pressure by threatening to disclose information.

For a Swiss trust company, the problem therefore goes beyond confidentiality. An attack can disrupt bookkeeping, delay the preparation of VAT returns, halt payroll processing, prevent access to documents required for closing the accounts, or undermine the relationship of trust with clients. In small organisations, where knowledge of client files is concentrated in the hands of just a few people, the unavailability of a workstation or software can quickly disrupt the entire operation.

Fake bank transfers and phishing: the risk stems from everyday habits

The most effective attacks do not always begin with a spectacular technical breach. They often exploit everyday actions: opening an attachment, clicking on a link, confirming an IBAN change, replying quickly to an urgent client, or using a password already known elsewhere. Clubic cites data from Cybermalveillance.gouv.fr, which shows that reported cases of fraudulent transfer orders rose by 29 per cent in 2024, whilst requests for assistance relating to this type of fraud increased by 93 per cent over the same period. According to Trustpair, also cited by Clubic, fewer than one in two companies were verifying their suppliers’ bank details via an automated process in 2024.

In a trust-based context, the scenario is easy to imagine. A hacker takes control of a firm’s email address, mimics the usual signature, attaches a credible invoice or requests an update to payment details. The client recognises the tone, the logo and the relationship, and complies. Supplier impersonation fraud works precisely because it resembles a routine administrative task.

The timing is also a factor in vulnerability. The end of the month, holidays, financial year-ends, tax deadlines or pay periods create pressure. Approvals are processed more quickly, stand-ins are less familiar with suppliers, and informal checks are bypassed. For an SME manager, this means that cybersecurity is not just an IT expense: it is a matter of internal control, just like dual authorisation for bank transactions or the segregation of duties.

Accounting portals: the convenience of the cloud demands robust security measures

The digitalisation of accountancy firms has brought significant benefits: online document sharing, remote access, automated data entry and real-time collaboration with clients. But a portal accessible via the internet also becomes a gateway that needs to be monitored. If a weak, reused or stolen password grants access, an attacker can gain access to multiple files from a single compromised account.

Clubic reports that, according to the CESIN barometer, 55 per cent of French companies targeted by a cyberattack in 2025 were hit by phishing, spear phishing or smishing. The same survey indicates that 40 per cent of French companies suffered a significant cyberattack in 2025, compared with 65 per cent in 2019, with fewer but more serious incidents: 81 per cent of organisations affected by a significant attack in 2025 experienced a direct impact on their business. A third of companies attribute more than half of their incidents to a service provider or supplier.

These figures should not be applied automatically to the Swiss market, but they illustrate a key point for fiduciaries: risk circulates within the ecosystem. A firm relies on its software, its hosting provider, its digital signature tools, its email system, its IT service providers and, in some cases, solutions used by its clients. Security therefore does not stop at the office perimeter. It includes the rights granted to staff, service providers’ access, procedures for when an employee leaves, administrator accounts and the way in which backups are isolated.

Cyber insurance and data protection: requirements are rising

Cybersecurity also has a contractual and insurance-related dimension. According to Clubic, insurers are tightening their conditions before agreeing to a cyber insurance policy. In particular, they require multi-factor authentication, backups disconnected from the network, an advanced detection tool and phishing awareness campaigns. Some firms deemed insufficiently prepared may be refused cover.

For an SME or a trust firm, this has a very practical implication: a cyber insurance policy does not replace basic security measures. On the contrary, it often presupposes them. In the event of a claim, the question will not merely be whether the business was insured, but also whether it had complied with the requirements set out in the policy. Managers must therefore treat these terms and conditions as an operational checklist, not merely as an administrative appendix.

Data protection adds another layer of responsibility. Clubic reports that the CNIL recorded 6,167 personal data breaches in 2025, up 9.5 per cent on 2024, and that half of these resulted from hacking. In the same year, the CNIL imposed 83 fines totalling 487 million euros across all sectors. Whilst these figures relate to the French authority, they serve as a reminder of the stakes involved: when a firm holds clients’ personal and financial data, a data breach can trigger obligations regarding analysis, disclosure and documentation.

In Switzerland, too, companies must take the security of personal data and data processing governance seriously. The specifics depend on the situation, the types of data, contracts and, in some cases, cross-border relationships. A fiduciary firm working with clients, employees or service providers outside Switzerland would be well advised to clarify in advance which rules apply, who must be informed and within what timeframes. This point warrants a case-by-case legal review.

Simple measures, but ones that need to be formalised before an incident occurs

The difficulty is not always knowing what to do, but doing it systematically. Many firms already have antivirus software, a firewall or an IT service provider. This is not enough if staff members confirm a change to an IBAN via email, if passwords are shared, if access rights are too broad, or if backups remain connected to the same environment as production data.

Certain measures must become standard management practices. Any request to change bank details should be confirmed via an independent channel, for example by calling a number already known to the firm rather than the one provided in the suspicious message. Access to accounting software should be restricted according to each employee’s actual role. Multi-factor authentication should protect email systems, business portals and administrative accounts. Passwords should be unique and managed using a suitable tool rather than stored in shared documents.

Backups deserve particular attention. Clubic recommends the so-called 3-2-1 rule: keep three copies of the data, on two different media, including one offline copy. The reasoning is simple: if ransomware encrypts the main server and the connected backups, an isolated copy can enable a restart without having to start from scratch. However, restoration must be tested regularly. A backup that has never been restored remains a promise, not a guarantee.

Training is the other key pillar. Phishing attacks are evolving and can take less obvious forms, such as messages mimicking a system error to trick the user into carrying out a dangerous action. Clubic describes, in particular, the ClickFix method, where a fake error message tricks the victim into pasting malicious code into a system tool. In a practice, explaining these mechanisms using concrete examples is better than a long set of rules that nobody reads.

Finally, the incident response plan should be drawn up before a crisis arises. Who cuts off access? Who contacts the IT provider? Who speaks to clients? Who checks compliance with obligations towards the authorities, the insurer or partners? Which files must be prioritised to ensure salaries, invoicing or tax deadlines are met? These questions are difficult to resolve when computers are down and the phone is ringing.

For Swiss fiduciaries, cyber security is therefore becoming a key aspect of professional quality. It protects data, but also ensures the continuity of mandates, safeguards the firm’s reputation and maintains the trust of SME directors. The issue is no longer the sole preserve of IT specialists: it must be incorporated into accounting procedures, internal controls and regular discussions with clients.

Need personalised advice?
Our experts are at your service.

Contact us