- Affected
- ~5m registered businesses
- Service
- WebFiling
- Cyber ranked top risk by
- 65% of professional firms
- Source
- Everywhen survey, 2026
What happened
A vulnerability in the Companies House WebFiling service left personal data of company directors across around five million registered UK businesses accessible to anyone holding a login.
Not to a sophisticated attacker. To anyone with an account.
For an accountancy practice this is an unusual kind of incident, because there is nothing you could have done. You did not choose the platform, you cannot audit it, and you file through it because filing through it is the job.
The uncomfortable question it raises
How much of your risk sits in systems you do not control?
Work through it honestly for a mid-sized practice. Companies House. HMRC agent services. Your practice management platform. Cloud bookkeeping across several vendors because clients chose differently. Payroll. A client portal. Document signing. Email.
Every one of those holds client data, most of them hold credentials that reach many clients at once, and you have meaningful control over roughly none of them.
That is not an argument for despair, and it is certainly not an argument for moving everything back onto a server in the office. It is an argument for being clear about which risks are yours to manage and which are yours to survive.
What is actually yours to manage
Three things, and they are the three that keep appearing in ICO enforcement against practices:
- Multi-factor authentication on everything, with no partner exemptions. The absence of MFA on email is the most common finding in enforcement action against accountants. Exempting senior people because they find it irritating inverts your risk model, because those are the accounts with the most access.
- Agent credentials and who holds them. Your agent access reaches every client's tax account. Shared logins mean no action can be attributed to a person, which matters enormously the day you need to establish what happened.
- Offboarding. Accounts belonging to people who left months ago are a routine finding, and they are the accounts nobody is watching.
None of that would have stopped the Companies House issue. All of it stops the attacks that actually reach practices.
Why practices get targeted disproportionately
A twenty-five person practice can hold payroll for several hundred employees across dozens of client businesses, VAT records for a couple of hundred more, personal tax data for hundreds of individuals, and bank details used for direct debit and BACS submissions.
From an attacker's point of view that is a far better return than attacking eighty separate businesses individually. The concentration is the attraction, and it does not scale with your headcount.
The sector has noticed. An Everywhen survey in 2026 found 65% of professional firms ranked cyber attacks as their main concern, well ahead of economic pressures at 18%, professional negligence at 9% and regulatory change at 8%.
The attack that actually happens
It is rarely dramatic. A partner's email is compromised, usually through a convincing phishing message. The attacker then sits quietly and reads, learns how the practice talks to clients, and waits for a payment conversation.
Then they send a client updated bank details, from a real address, in the middle of a real thread, in the right tone of voice.
Nothing about that requires technical sophistication. It requires access to one mailbox and patience. Which is why mailbox rules quietly forwarding a partner's email are worth checking for specifically, and why almost nobody does.
What to do about it, in order
- Cyber Essentials. It addresses MFA, patching, access control and supported software, which is most of the realistic risk. It also answers a large proportion of client security questionnaires in one document. See Cyber Essentials certification.
- Check for mailbox forwarding rules across every account, not just the ones you suspect.
- Review agent access. Who holds it, whether it is individual, and what happens when they leave.
- Test what faces the internet. Your client portal, your remote access, anything published during the pandemic and never withdrawn. Covered under penetration testing.
- Know what you would do if a client called to say they had paid the wrong account. That is incident response, and having a plan is most of it.
On timing
Nobody in this sector wants to think about security in January, and remediation done under self-assessment pressure is remediation done badly. Autumn is the sensible window, and if a client questionnaire has already landed, send us the wording and we will tell you what would actually satisfy it.
More on how we work with practices on our accountancy sector page.
Common questions
Were we affected by the Companies House issue?
That is a question for Companies House rather than for us. What we can tell you is what your own systems expose, which is the part you can act on.
Isn't this just a reason to distrust cloud services?
No. Your own server would not have been better, and would almost certainly have been worse. The lesson is about knowing where your dependencies are and controlling what you can, not about retreating from platforms that are on the whole more secure than anything a small practice runs itself.
A client has sent us a security questionnaire. Do we need a penetration test?
Often not. A great many are satisfied by Cyber Essentials certification plus honest answers. Send us the questionnaire and we will tell you which parts genuinely need work. That conversation is free.
What does the ICO actually fine accountants for?
Enforcement has focused on missing multi-factor authentication on email, unencrypted devices holding payroll data, failure to notify within 72 hours, and inadequate due diligence on cloud sub-processors. The pattern is consistent and none of it is exotic.
How much should a practice our size be spending?
Less than most vendors will tell you. Cyber Essentials plus fixing what it surfaces is the right first year for most practices. Testing follows once the basics hold, and we will say so rather than sell you the test first.
Related
Solusec
Typically replies within one business day
Had an incident, or need a pen test at short notice?
Tell us what you're dealing with and we'll come back to you.
+44 (0)1902 288763 ✉️ Email us
info@solusec.co.uk 📝 Leave a message
We'll reply within one business day