top of page
Search

QR Code Phishing: A New Twist on an Old Trick

Feb 20, 2023
1 min read

Updated: Sep 2

Phishing remains the most common way attackers get a foothold in accountancy firms, precisely because it targets people rather than technology. Fake HMRC emails, invoice fraud, and payment diversion scams are all variations on the same idea: convince someone to act quickly, without checking.

Why accountants are a favoured target

Finance teams routinely handle payment requests, client data, and time-sensitive deadlines, which makes them a natural target for business email compromise and invoice fraud. Attackers often research a firm's real clients and suppliers first, making their messages look plausible rather than obviously fake.

Building resilience

Technical controls like email filtering and DMARC/SPF/DKIM authentication help, but regular phishing simulations — sending realistic test emails and seeing who clicks — are one of the most effective ways to build genuine awareness. The goal isn't to catch people out; it's to normalise pausing and verifying before acting on an unexpected request.

We run phishing simulations and staff training tailored to how accountancy firms actually work — get in touch if you'd like to see how your team currently performs.

 
 
 

Recent Posts

See All

Comments


bottom of page