Austin Buonasera
 • 
March 16, 2026
 • 
8
 Minute read

Case Study: How an Attacker Gains Access to Critical Systems Inside a Small CPA Firm

How a CPA firm actually gets breached: a busy accountant, a fake Microsoft 365 login, six quiet weeks, and the basic controls that stop the attack cold.

Quick Summary

  • CPA firms are high-value targets: a tax return is a complete identity kit, and most small firms have no dedicated security — so one breach can expose thousands of clients along with the firm's EFIN.
  • The attack is almost never a firewall hack. It's a phishing email and a fake Microsoft 365 login; once an attacker controls a staff mailbox, they can reach the tax software, client portal, and files, then commit refund fraud, EFIN theft, wire fraud, or ransomware.
  • The defenses are basic and affordable: enforce app-based MFA, verify every bank or wire change by phone, train staff on real phishing lures, keep tested offline backups, and maintain a written WISP (required under the FTC Safeguards Rule).
Sunset over foggy mountains with dark silhouettes and a cloudy sky.
It's mid-March. One of your staff accountants has been at her desk since 7 a.m., and there's a stack of organizer questionnaires she hasn't touched. An email lands from a name she half-recognizes — a prospective client — with a OneDrive link labeled "2024 tax docs." The page that opens looks exactly like the Microsoft 365 sign-in she uses fifty times a day. She types her password. Nothing loads. She shrugs and goes back to a K-1.

Nobody notices anything for six weeks.

That's how most accounting firm breaches actually start. Not with someone brute-forcing your firewall — with a busy person, a plausible email, and a login page that isn't real. We've responded to incidents at tax and accounting firms, and the attack paths are depressingly consistent. So let's walk through it the way an attacker would: how they get in, what they take, and what it costs a firm that figured security could wait until after busy season.

Why a 12-person CPA firm is worth attacking

Attackers aren't sentimental about firm size. They care about data density, and CPA firms are some of the densest targets around. A single Form 1040 contains a Social Security number, date of birth, address, employer, income, dependents with their SSNs, bank and routing numbers from the direct deposit line, and a signature. Criminal marketplaces call that a "fullz" — a full identity kit — and a tax return is the richest version of it. One compromised firm can mean thousands of complete identities in a single haul.

Then there's timing. Tax season is a deadline factory. People click fast, open anything labeled "client docs," and skip the verification call. Attackers know this the way retailers know Black Friday.

And finally, there's posture. Most firms under 50 people have no dedicated security staff. IT is outsourced, "security" is an antivirus license, and nothing is written down. The IRS has said this plainly for years through its Security Summit: tax professionals are a top target, and the agency fields a few hundred data-theft reports from tax pros every year — each one potentially exposing hundreds of clients.

The way in: how the attack actually unfolds

Step one: recon, which takes about twenty minutes. Your website hands over names, titles, and your email format. LinkedIn shows who the staff accountants are and who just got hired — new employees click more. A job posting from last year that says "experience with CCH Axcess a plus" tells the attacker your software stack. If your client portal sits at a guessable subdomain, they note that too.

Step two: the hook. Usually one of four lures:

  • A fake "new client" sharing documents (the IRS has specifically warned tax pros about this one)
  • A fake IRS or e-Services notice — "your EFIN needs re-verification"
  • A fake alert from your tax software vendor — "update required before filing season"
  • A plain credential phish: "your mailbox is full," "your password expires today"

The login page is a pixel-perfect Microsoft 365 clone. The moment she enters her credentials — sometimes even her MFA code, if the attacker is relaying the login in real time — they have the keys.

Step three: the mailbox. This is the part firms underestimate. Email is the skeleton key. The attacker signs in, sets a rule to auto-delete any reply containing "hacked" or "phishing," then reads sent items to learn how your people write — who signs "Best," who's on a first-name basis with which clients. From the inbox, they reset passwords to everything else: the tax software, the client portal, the document management system. Reset links go to the email address they now own. Every system that trusts your email now trusts them.

Step four: expansion. They pull the client list. Maybe they phish internally — a message from the managing partner's real account to the bookkeeper: "Send me the payroll export for [client name]." It comes from the right address, at the right time of year. It gets answered.

Step five: the endgame. Four common plays:

  • Quietly download a few thousand returns and file fraudulent refunds before the real clients file.
  • Steal the firm's EFIN and file fraudulent returns through the firm's own identity — the IRS has warned about EFIN theft specifically.
  • Business email compromise: reply-all to an active client thread with "updated wire instructions." Because it lands inside a real conversation, it works frighteningly often. The FBI's IC3 puts reported BEC losses at roughly $2.8 billion a year — and that's just what gets reported.
  • Ransomware, detonated the Friday before April 15, when the pressure to pay is at its peak.

A real-world footnote: in May 2019, Wolters Kluwer — the company behind CCH — was hit by a malware attack (widely reported as ransomware) and its tax software went dark for days, mid filing season, for firms around the world. Even when your own shop is clean, your software supply chain can take you down.

What walks out the door

  • 1040s: complete identity kits for every client, plus spouses and dependents
  • Business client records: financial statements, general ledgers, payroll registers, EINs, officer SSNs
  • W-2s and 1099s with wage data
  • Bank details from organizers and direct deposit forms
  • Your EFIN
  • Your entire email archive — every client conversation and attachment, going back years

The downstream harm lands on your clients. Fraudulent returns get filed in their names, and their legitimate refunds freeze. IRS identity-theft resolution has improved but still drags; the National Taxpayer Advocate has clocked average resolution times of about 22 months in its most recent report. Now imagine making that phone call to 800 clients.

The cost of "we'll get to it after April 15"

Regulatory. The FTC's amended Safeguards Rule, in force since June 2023, classifies tax preparation firms as financial institutions. That makes a written information security program (WISP), a designated qualified individual, MFA, encryption, vendor oversight, and an incident response plan legal requirements — not best practices. IRS Publication 4557 and the PTIN renewal process push the same obligations. A breach with no WISP on file is a very different conversation with regulators than a breach with one.

Financial. IBM's latest Cost of a Data Breach Report puts the global average at $4.44 million, with financial services running higher at $5.56 million. A small firm won't touch those figures, but forensics alone for a modest incident routinely runs $30,000 to $100,000 or more — before notification letters, credit monitoring, legal fees, and the tax-season revenue lost while your systems sit offline.

Trust. Accounting is a confidence business. Clients hand you everything because they trust you with everything. Breaches in small markets become local news, and the retention math afterward is ugly.

Meanwhile, Verizon's Data Breach Investigations Report finds — year after year — that roughly 60% of breaches involve a human element, and phishing plus stolen credentials dominate the pattern for professional services firms. Attackers aren't outsmarting your firewall. They're out-busying your staff.

What actually stops this

Here's the encouraging part: the attack above dies at multiple points with basic controls. In rough order of impact:

  1. MFA on everything, starting with email and tax software. App-based, not SMS. This one control breaks step two for most commodity attackers.
  2. A call-back rule. Any change to bank details, any wire, any unusual request — verified by phone on a number you already have. Write it down. No exceptions for "the partner's in a hurry."
  3. Training with real lures. Show your staff the actual "new client" and "EFIN verification" emails making the rounds. Run simulations. People who have seen the trick spot the trick.
  4. Patch and close doors. No remote desktop exposed to the internet. VPNs and firewalls current. Modern endpoint detection instead of legacy antivirus.
  5. Backups that are offline or immutable — and restore-tested. A backup you've never restored is a rumor.
  6. Write the WISP. It's required anyway, and the IRS literally publishes a free template in Publication 5708. Starting takes an afternoon.
  7. Vet your vendors. Ask your software providers about their incident history and their controls. Wolters Kluwer proved vendor risk is your risk.
  8. Know who you'll call. An incident response contact, your cyber insurance carrier, and fast reporting — the IRS Stakeholder Liaison for tax data theft, the FBI's IC3 for everything else. Speed genuinely changes outcomes.

None of this requires a security department or a six-figure budget. It requires deciding that the deadline pressure attackers count on isn't going to be your security strategy. The firms that get hurt aren't the ones that couldn't afford protection — they're the ones that assumed nobody was looking at them.

Somebody is. If you want a second set of eyes before busy season — a WISP review, a phishing simulation, or an honest look at where an attacker would start with your firm — that's exactly the work we do.

CPA firms: bring us in before busy season, not after a breach. A short exposure check covers email, MFA, backups, vendors, and your WISP — the same places an attacker would probe first. It takes about three minutes.

Check your firm's exposure · Book a consultation

Cards showing CPA firms scored 3/8 on client-data protection risks with notes on regulatory penalties and breaches.
3 minutes or less

Not sure what's exposed? Start here.

Answer a short set of questions about email, devices, vendors, backups, and access. No passwords, no system details — just the questions an attacker has already answered about you.
Get Your Risk Assessment