CFOtech Australia - Technology news for CFOs & financial decision-makers
Australia
How can phishing-resistant authentication strengthen AML compliance across the accounting sector?

How can phishing-resistant authentication strengthen AML compliance across the accounting sector?

Mon, 3rd Aug 2026 (Today)
Geoff Schomburgk
GEOFF SCHOMBURGK Vice President for Asia Pacific & Japan Yubico

Anti-Money Laundering (AML) compliance has traditionally centred on customer identification, transaction monitoring and reporting obligations. Yet as financial crime becomes increasingly digital, many organisations are overlooking a critical weakness sitting inside their own operations: user authentication.

Across the accounting sector, cybercriminals are increasingly targeting employee credentials to gain access to systems containing sensitive financial and identity data. Once inside these systems, attackers can manipulate transactions, alter client tax returns, intercept communications or facilitate fraudulent refunds, all while appearing to be legitimate users.

This is creating a growing convergence between cybersecurity and AML compliance. Organisations can no longer treat identity security as simply an IT issue. Authentication has become fundamental to protecting the integrity of AML controls themselves.

The challenge is particularly urgent as the Federal Government's "tranche two" reforms expand AML obligations into new sectors. Lawyers, accountants, real estate professionals and dealers in precious metals and stones will soon face stronger obligations around customer due diligence, suspicious matter reporting and risk management frameworks.

The reforms are part of amendments to the Anti-Money Laundering and Counter-Terrorism Financing Act 2006, overseen by AUSTRAC, Australia's financial intelligence agency and AML regulator.

While many organisations are preparing for procedural and reporting changes, fewer are considering whether their authentication systems can protect the sensitive financial and identity data underpinning those obligations.

That gap matters because cybercriminals are increasingly exploiting stolen credentials rather than technical vulnerabilities to gain access to systems.

The growing identity problem inside AML risk

Most AML frameworks assume that authorised employees accessing systems are who they claim to be. That assumption is becoming increasingly dangerous.

According to the Australian Cyber Security Centre (ACSC), phishing remains one of the most common cybercrime techniques affecting Australian organisations. Attackers are no longer relying solely on malware or network intrusion. Instead, they are using phishing emails, fake login pages and social engineering techniques to steal employees' credentials and simply log in, creating significant AML exposure.

If a criminal compromises the credentials of a finance manager at a real estate agency, for example, they may gain access to trust account systems, customer identification records and transaction workflows. In an accounting firm, compromised credentials could expose beneficial ownership information, tax records or financial transfers. For jewellers handling high-value purchases and customer identity verification, stolen credentials could facilitate fraudulent transactions or identity laundering.

The consequences extend well beyond a cyber incident. Compromised accounts can undermine customer due diligence processes, create gaps in audit trails and potentially expose organisations to compliance failures.

Traditional security controls are increasingly struggling to stop these attacks.

Many businesses still rely heavily on passwords combined with SMS-based multi-factor authentication (MFA). While this is often viewed as "good enough", attackers have repeatedly demonstrated ways to bypass these controls through adversary-in-the-middle phishing kits, MFA fatigue attacks and SIM-swapping techniques.

This is why regulators and cybersecurity authorities are increasingly encouraging organisations to adopt phishing-resistant authentication approaches.

Why phishing-resistant authentication changes the equation

Phishing-resistant authentication is designed specifically to prevent attackers from stealing or reusing login credentials, even if a user unknowingly interacts with a malicious website.

Unlike passwords or SMS one-time codes, phishing-resistant authentication methods such as FIDO2 security keys and passkeys use cryptographic authentication tied directly to legitimate websites and applications. This means authentication credentials cannot be replayed on fraudulent sites created by attackers.

Importantly, phishing-resistant authentication removes reliance on shared secrets, which remain one of the biggest weaknesses in traditional identity systems.

The Australian Signals Directorate (ASD) Essential Eight framework has already recognised the limitations of weaker MFA approaches. SMS-based MFA does not satisfy Essential Eight Maturity Level Two requirements because of its vulnerability to interception and social engineering. Among these methods, a physical security key is considered the most secure option.

This matters because AML compliance increasingly depends on the integrity and trustworthiness of digital systems. If organisations cannot be confident that only authorised employees are accessing sensitive systems, the effectiveness of AML controls becomes significantly weakened.

Authentication is no longer simply about protecting logins. It is about protecting the integrity of financial compliance itself.

Accounting firms are high-value targets

Accounting firms sit at the centre of highly sensitive financial ecosystems. They often manage privileged access to taxation records, ownership structures, trusts and company arrangements, all of which are highly valuable to cybercriminals and organised crime networks.

The sector is also experiencing increasing scrutiny around data protection and cyber resilience.

Professional bodies such as CPA Australia and Chartered Accountants Australia and New Zealand (CA ANZ) have both highlighted the growing importance of cybersecurity governance and data protection for accounting professionals.

Yet many accounting firms still operate with legacy authentication models that rely heavily on passwords and mobile-based MFA.

This creates a growing vulnerability, particularly in hybrid working environments where staff regularly access cloud applications remotely.

Phishing-resistant authentication offers accounting firms a practical way to significantly reduce the likelihood of credential-based attacks without introducing major friction for employees.

This is especially important for mid-sized firms that may not have large internal cybersecurity teams but still hold highly sensitive financial and identity information.

Reducing the risk of account compromise can help protect the integrity of customer records, financial reporting and AML-related processes.

AML and cybersecurity are now inseparable

One of the most important shifts organisations must recognise is that AML compliance and cybersecurity are no longer separate disciplines.

Cybercriminals are targeting identities because identities provide access to financial systems, customer records and compliance workflows. Weak authentication, therefore, becomes both a cybersecurity vulnerability and a compliance vulnerability.

Phishing-resistant authentication will not eliminate every AML risk. However, it can significantly enhance the trustworthiness of digital systems, thereby strengthening customer due diligence, transaction integrity and financial reporting.

As AML obligations expand across the accounting sector, organisations that continue relying on passwords and vulnerable MFA methods may find themselves increasingly exposed, not only to cyber breaches but also to regulatory, operational and reputational consequences.

The organisations best positioned for the future will be those that recognise identity security as a foundational pillar of financial crime prevention.