Accounting firms and consultancies manage sensitive information such as client identities, bank account details, and tax records. This makes them prime targets for cybercriminals, particularly those using ransomware—malicious software that encrypts data and demands payment for its release. On March 7, 2024, the National Council of the Order of Certified Public Accountants joined Cybermalveillance.gouv.fr, a public initiative initially aimed at software publishers and internet service providers. This move highlights growing concerns about cyber threats in the accounting sector. On August 20, a ransomware group named Everest claimed to have hacked the accounting firm Experts Entreprendre, allegedly stealing 1.13 terabytes of data from 2.6 million files, including annual accounts, tax returns, and personal client information. This type of data breach can enable attackers to impersonate clients, open bank accounts in their names, or redirect financial transfers to third parties. Cybercriminals may also use accounting firms as a gateway to target their clients, for example, by sending fake invoices that mimic the firm's formatting, tricking clients into making unauthorized payments. According to Cybermalveillance.gouv.fr, reports of fake transfer orders increased by 29% in 2024, while requests for help related to this kind of fraud rose by 93% during the same period. A salaried accountant at an industrial small-to-medium enterprise fell victim to a cyberattack resembling the ClickFix technique on January 12. Attackers displayed a fake error message and instructed him to paste a code into PowerShell, a command-line tool used for scripting. This allowed the attackers to steal the company's bank credentials, despite the workstation being protected by a firewall, detection software, and multi-factor authentication. The IT team had to disconnect the company's virtual private network (VPN) remotely to limit the damage and then rebuild part of the system. Many accountants access their accounting software through internet-based portals, which can be vulnerable to attacks if passwords are weak or reused. According to the CESIN barometer, 55% of French companies targeted by cyberattacks in 2025 were attacked through phishing, spear phishing, or smishing—forms of targeted fraud that use fake messages to trick users into revealing sensitive information. In 2025, 40% of French companies experienced a significant cyberattack, compared to 65% in 2019. Although the number of attacks has decreased, the impact is more severe, with 81% of affected organizations facing direct operational consequences, and a third blaming service providers or suppliers for the majority of incidents. To reduce risks, accounting firms are advised to verify any request for a change in banking details by contacting the usual phone number of the contact, train staff to recognize phishing attempts and techniques like ClickFix, enable multi-factor authentication, and limit access to accounting software based on actual employee needs. They should use a password manager with unique passwords, follow the 3-2-1 backup rule, install security updates promptly, use threat detection tools, exchange sensitive documents through secure deposit spaces, and draft an incident response plan. Firms are also encouraged to seek a diagnosis or list of qualified service providers from Cybermalveillance.gouv.fr. Cyber insurance should be tailored to the firm's size, with insurers increasingly requiring specific security measures to be in place. If a breach occurs, firms must file a complaint within 72 hours and immediately warn affected clients.