Accountancy Under Attack

Accountancy Under Attack

The Accountancy Profession is Under Attack.

That statement is no exaggeration.

I`ve commented at length, and often, on this subject in recent days, about a series of serious cyber-attacks on the profession since mid-January, which provide growing evidence in respect of accountancy being a red-hot and growing target for malicious cyberattack. In particular umbrella groups, it seems, but the profession and sector at large has some serious risk management to consider.

And, if you read the feedback from accountancy clients on social media - they are very upset and angry at the pace of recovery and lack of communication coming out of the affected firms (which to a great extent is exacerbated by the use of VOIP telephony - read on).

No alt text provided for this image

Intuit Quickbooks (last week)

Link: https://www.bleepingcomputer.com/news/security/intuit-warns-of-phishing-emails-threatening-to-delete-accounts/

“Accounting and tax software provider Intuit?has notified customers of an ongoing phishing campaign impersonating the company and trying to lure victims with fake warnings that their accounts have been suspended.

Intuit's alert follows reports received from customers who were emailed and told that their Intuit accounts were disabled following a recent server security upgrade.

"We have temporarily disabled your account due to inactivity. It is compulsory that you restore your access within next 24 hours," the attackers say in the phishing messages, masquerading as the Intuit Maintenance Team.”

No alt text provided for this image

Parasol and Brookson Group (Jan 2022)

https://www.computerweekly.com/news/252512871/Brookson-and-Parasol-cyber-attacks-Contractor-complaints-about-delayed-payments-continue

Useful link showing cyber-attack trail and how Brookson are managing their recovery:?https://www.brooksongroup.co.uk/latest-updates/

SJD and Nixon Williams (Jan 2022)

Part of Brookson, these two firms admitted on 19th January that they had also fallen to a cyber-attack:

https://www.contractoruk.com/news/0015346sjd_accountancy_and_nixon_williams_confirm_hacking.html

No alt text provided for this image

Summary

The ripple effect of attacks on 3rd party software is best explained by this article by Carrier Management:

https://www.carriermanagement.com/news/2019/05/14/193329.htm

“Hackers will often try to compromise the servers that send out updates and patches to all users of that software, passing off their malware as a legitimate update. In some cases, the hackers’ target may be one specific firm that they know use that software and the other firms in the industry are simply considered “collateral damage.”

This is called “a waterhole attack,” because it is like hunters staking out a water source in the Savannah to find big game.

“If you get the right software, you are guaranteed to get a whole swath of victims in that specific area,”

In short, all accounting firms are busy digitally adopting, using much of the same SaaS products, and many without enough focus on cyber defence. If one (big) firm gets hit – the whole profession will feel the ripple effect.

The significant “client-facing” impacts of the Brookson/SJD/Nixon Williams attacks include taking down of their payroll service (ie they couldn’t process wages/salaries for their clients) and telephony (they use VOIP technology for their phone systems so all their phones were down).

No alt text provided for this image

On that basis some firms may reflect on the future of their VOIP telephony, as a risk to client communications. If there is one thing you really need to remain stable following a cyber-attack, is your ability to maintain two-way communication with your clients and customers.

I`d be delighted to really start building dialogue with your practice team in order to reduce your risk over in the coming months - the threat to accountancy is severe and all too real, this past few weeks has proven that without any doubt.

[email protected]

要查看或添加评论,请登录

Rich Jackson的更多文章

  • Five Behaviours to Drive Effective Cyber Risk Reduction

    Five Behaviours to Drive Effective Cyber Risk Reduction

    It`s early January 2024, and there should be no doubt in any business owner or managers mind that cyber and data…

    2 条评论
  • An Analysis of Gen Z Cyber Risk

    An Analysis of Gen Z Cyber Risk

    Are you a "Digital Native"? Is it the same group as Gen Z? Kind of. Digital Natives have grown up (and are comfortable…

    1 条评论
  • Latest from Rich Jackson

    Latest from Rich Jackson

    I come from a dairy farming family here in Cornwall, and my cousin remains firmly in the agricultural feeds sector -…

  • Partnerships Work.

    Partnerships Work.

    At Moore ClearComm we know that no two businesses are the same. This conscious view enables us to build strong, lasting…

    2 条评论
  • Partnerships Work.

    Partnerships Work.

    Giving is better than Receiving. As a Partnerships Manager this ethos is absolutely core to my work, understanding that…

  • Social Proof: The Key to Cyber Security?

    Social Proof: The Key to Cyber Security?

    One of, if not the greatest, frustrations of working in the world of cyber security and data protection - is the…

    7 条评论
  • Data Silos: Helping to Support Cyber Risk Reduction

    Data Silos: Helping to Support Cyber Risk Reduction

    Setting the Scene Since the dawn of time, the human race has endeavoured to make the things we need to do, easier and…

  • Vegan Trends: a Cyber Security Lesson

    Vegan Trends: a Cyber Security Lesson

    I know what you`re thinking! Veganism and Cyber Security. Really?! Hear me out.

    1 条评论
  • COVID-19: The Care Sector - One Year On

    COVID-19: The Care Sector - One Year On

    Today marks one year since the World Health Organization declared COVID-19 a Pandemic. At that stage we were very much…

  • Threats & Risk: Cyber Crime Sector Focus in 2021

    Threats & Risk: Cyber Crime Sector Focus in 2021

    As we enter 2021, we have hope. Following a full year of COVID-19 dominated sadness, changing lifestyles, alterations…

社区洞察

其他会员也浏览了