Accounting and bookkeeping practices hold exactly the kind of information scammers want: tax file numbers, bank details, identity documents and access to ATO online services. If you suspect a breach, the first hours matter, and so does doing things in the right order.
This guide covers the practical steps. It is general information rather than legal advice, so speak to your adviser or insurer about your specific obligations.
Signs you may have had a breach
- A client tells you they received an email from your address that you did not send
- Staff notice sign-in alerts or password reset emails they did not request
- A mailbox has forwarding rules nobody set up
- The ATO or a client reports unusual activity on a client account
- Files have been encrypted or renamed, or a ransom message appears
Step 1: Contain it
Stop the problem spreading before you investigate. Change the password on any affected account and sign it out of all sessions, check multi-factor authentication is switched on, remove any suspicious forwarding rules, and disconnect any computer that may be infected from the network.
Call your IT provider at this point, so the problem is contained without losing the evidence of what happened.
Step 2: Call the ATO

The ATO asks tax professionals to contact its Client Identity Support Centre on 1800 467 033 as soon as possible after a breach, so it can put protections in place for your practice and your clients (ATO).
If someone has misused myID access, the ATO also lists the myID support line on 1300 287 539 (option 2).
Step 3: Work out what was accessed
Your IT provider should check sign-in logs, mailbox activity and file access to work out what the attacker could see, and for how long. The answer decides who needs to be told.
A compromised mailbox, for example, may expose years of attachments containing tax returns and identity documents, even if the attacker was only in for a day.
Step 4: Check the Notifiable Data Breaches scheme
Under the Privacy Act, the Notifiable Data Breaches scheme requires covered organisations to notify affected people and the Office of the Australian Information Commissioner when a breach is likely to cause serious harm.
The scheme covers businesses with annual turnover above $3 million. It also covers anyone who holds tax file number information, in relation to that information, so a practice that holds client TFNs needs to consider the scheme regardless of its size (OAIC).
If you suspect a breach, the OAIC expects you to finish assessing it within 30 days, and to notify as soon as practicable once you decide it is an eligible breach. The ATO also suggests checking the Tax Practitioners Board’s information on how the scheme affects your registration.
Step 5: Tell your clients

Clients whose information was involved should hear from you clearly and early. Explain what happened, what information was involved, what you have done and what they should watch for. The ATO may also contact affected clients directly.
IDCARE, on 1800 595 160, offers confidential identity support at no cost for anyone worried about identity theft, and is worth including in your message to clients.
Step 6: Fix the cause
Once the immediate problem is handled, close the gap that let it happen. That usually means multi-factor authentication on every account, better email filtering, staff phishing training, and removing old accounts and access that are no longer needed.
If the breach started in a software provider’s system, contact them so they can investigate on their side.
Preparing before anything happens
- Keep a one-page incident plan with phone numbers for your IT provider, bank, insurer and the ATO
- Make sure Microsoft 365 email and files are backed up separately
- Review who has access to client files and ATO online services every quarter
- Check your cyber insurance policy and what it expects you to have in place
How Digitek helps accounting and bookkeeping practices
If you think your practice has had a breach, call us straight away on 02 4504 8643. We help secure the affected accounts, work out what was accessed, restore data where needed and explain what needs to happen next.
Day to day, we look after Microsoft 365, multi-factor authentication, backups and security for accountants and bookkeepers, and we avoid making changes during tax time. Find out more about our IT support for accountants.






