Home  /  Publications  /  No. 011

ACCOUNTING·16 AUG 2021·3 min read

The Attack That Targets Your Accounts Team

Most attacks on accounting data are not technical. They are an email asking you to change a supplier's bank details.

Position as at August 2026

It works, it is common in the UAE, and one control stops almost all of it.

How it actually runs

The attacker gets into an email account somewhere in the chain. Sometimes yours, often your supplier's, sometimes a smaller party neither of you thought about.

They read quietly for weeks. They learn who pays whom, on what terms, in what tone, and when the large invoices go out.

Then they send an email that looks entirely normal. Same signature, same thread, same writing style. New bank details for the next payment.

Your accounts clerk updates the supplier record and pays.

Why finance teams fall for it

Because nothing about it looks wrong.

The email is on a real thread. It refers to a real invoice for a real amount. The tone matches. There is often light time pressure, and it usually arrives when the person who would normally check is away.

This is not carelessness. It is a well-researched attack aimed at a routine task.

The one control that stops it

Any change to a supplier's bank details is verified by phone, on a number you already held, before any payment is made.

Not the number in the email. Not the number in the new signature block. The number you had before this request existed.

That is the whole control. It costs two minutes and it defeats the attack, because the attacker controls the email and not the phone.

Write it down as a rule so it does not depend on who is at the desk that day.

Four supporting controls

Two-factor authentication on every email account, especially finance.

A second approver for any payment above a threshold, and for any first payment to new details regardless of amount.

Remove access when people change role. Old permissions accumulate invisibly.

Watch for forwarding rules quietly set on mailboxes. That is how an attacker keeps reading after a password change.

If it has already happened

Speed matters more than anything else.

Call your bank immediately and ask them to attempt recall. Hours matter. Report it to the police.
Assume the mailbox is still compromised. Change passwords, force sign-out everywhere, and check for forwarding rules before you use email to discuss it. Tell the real supplier, because their account may be the one that was breached.

The wider point about your accounting data

Your ledger contains your customer list, your margins, your bank details and your payroll. Treat it as you would treat cash.

That means access limited to who needs it, removed when they leave, and backups you have actually tested restoring rather than assumed were running.

Where we fit

We see this attempted against clients regularly. If you do not have the phone verification rule written down, that is the highest value thing you can change this week.

Have a question on this?

Ask a tax question. The law answers.

AskCALX searches the official corpus and answers with the article quoted, word for word.

Ask a tax question →

Let’s get startedYour engagement

One engagement letter. One file. Every deadline met.


Let’s talk!

Newsletter

Stay up to date with our newsletter.

Latest in UAE business, tax and technology, once a month.

Thank you, you are on the list.

Visit us

Office 1316, Aspin Commercial Tower
Sheikh Zayed Road, P.O. Box 10415, Dubai
Open in Google Maps →

© 2026 CALX International Auditing of Accounts L.L.C. · All rights reserved · Privacy