logo

Accounting Firms Can't Skimp on Cybersecurity

ID: d9ec9a4a-36ad-598b-97e4-5e1daf433a37

STIX ID: report--d9ec9a4a-36ad-598b-97e4-5e1daf433a37

Feed Name: Dark Reading

Threat Score
70/100

Date Published: 2025-04-15

Date Updated: 2026-05-05

Author: Joan Goodchild

...
...

Early in 2024, attackers used deepfake video and audio to impersonate senior executives during a routine video call with an employee at UK engineering firm Arup, resulting in the theft of $25 million. The article warns that accounting teams are especially at risk due to SaaS sprawl, reused credentials, insecure communications (email/SMS), and limited identity controls at smaller firms, and it recommends baseline technical controls (MFA, VPN, encryption, MDM), secure client portals, least-privilege access, and regular security awareness and out-of-band verification practices to mitigate such social-engineering and impersonation attacks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.