The ATO has urged tax professionals to strengthen cyber security practices and remain vigilant against malicious links, attachments and other tactics used by cyber criminals to access sensitive client and business information.
The Australian Taxation Office (ATO) has published a notice on 27 August 2026, reminding tax professionals of the importance of protecting their practices against cyber threats.
Tax professionals are being targeted by cyber criminals, primarily via malicious links in emails, attachments and other communications.
The ATO is currently providing support to a small number of impacted tax professionals. ATO systems remain secure and resilient, but as cyber criminals adapt and refine their tactics to target businesses, the ATO stresses that tax professionals must remain vigilant and exercise good cyber security practices.
One wrong click can give cyber criminals access to sensitive client information and business systems. The ATO advises tax professionals to:
- Install anti-virus software and keep it up to date — more information is available on the Antivirus software page on cyber.gov.au
- Exercise caution when opening links or attachments, or downloading files from unexpected or unknown sources
- Independently verify suspicious communications using trusted contact details
- Use multi-factor authentication (MFA) across devices and services
- Keep devices, apps and software up to date — see the How to update your device and software page on cyber.gov.au for more information
- Regularly back up important business data and test the ability to restore it
The ATO also reminds tax professionals that cyber security is as important when working from home as it is when working from the office, and that caution should be exercised regardless of location.
Tax professionals who suspect their systems have been compromised after opening a suspicious link or attachment are urged to act quickly to protect clients, seek IT support, and contact the ATO’s Client Identity Support Centre on 1800 467 033.