Accounting Firm Data Breaches: A Growing Risk for CPA Firms and Their Clients

The October issue of the Journal of Accountancy includes an article written by Sarah Beckett Ference, CPA on accounting firm data breaches.  Examples were drawn from the AICPA Professional Liability Insurance Program and include:

  • “A CPA clicked on a phishing email, granting access to his system, including tax return preparation software. In early April, the CPA discovered that multiple in-process returns were submitted to the taxing authority without authorization but not before bank account information was changed to redirect refunds to the bad actors.
  • In the middle of busy season, a CPA received multiple calls from individuals who received an email from the CPA with a link to click and download a secure document. An investigation revealed that the bad actor had gained access to the CPA’s email system and sent a phishing email to more than 2,000 contacts, some of whom took the bait.
  • A CPA firm was subject to a ransomware event that encrypted a workstation, two servers, and local backups. In addition, the firm’s backup service was not currently synced. The firm was down for multiple weeks and had to redo hours of additional work.”

In addition to obtaining satisfaction that the CPA has the training and experience to service your tax needs, you need to obtain the same level of satisfaction that the CPA has appropriate defenses in place to protect your data from a cyber attack on the accounting firm.  For more assistance, contact Kevin Ortiz in our office.  To read the entire Journal of Accountancy article see Are you prepared for the cost of a data security incident?

Recent Posts

Tracing Billions: How Blockchain Analytics Uncover Crypto Scams

In November 2024 we traced $1.8 million in scammed BTC. As of today, we have traced a total of $1.7 billion of cryptocurrency scammed over several years.  Because of the immutable nature of blockchains, they provide visible, permanent, tamper-proof records that can be analyzed years later.   Reactor, the software we use to trace cryptocurrency and […]

Learn more

OCC Conditionally Approves National Trust Bank Charters for Major Digital Asset Firms

On December 12, 2025, the Office of the Comptroller of the Currency (OCC) announced that “[t]he OCC conditionally approved applications for de novo national trust bank charters for First National Digital Currency Bank and Ripple National Trust Bank. The OCC also conditionally approved applications to convert from a state trust company to a national trust […]

Learn more

Bank of America Approves Limited Digital Asset Allocations for Client Portfolios

Yesterday, Investment News, reported that Bank of America approved an advisor-endorsed allocation of from 1% to 4% of digital assets in portfolios owned by clients of Merrill, Bank of America Private Bank, and Merrill Edge platforms.  Two years I attended a speech given by Ric Edleman, a major investment advisor, where he stated he had […]

Learn more

Why BlackRock’s Larry Fink Is Bullish on Bitcoin

Because of an article in Cryptopolitan today, I asked AI for a little research on why Larry Fink, CEO of BlackRock, is strong on BitCoin.  Although I still have my doubts about its long term value proposition, the resulting research does deserve careful consideration, especially since the thoughts of BlackRock’s CEO carry some weight.   Here […]

Learn more

OCC Chief Urges Banks to View Stablecoins as Opportunity, Not Threat

As reported by CoinDesk writer Jesse Hamilton, OCC chief Jonathan Gould, speaking at the American Bankers Association Annual Convention on Monday, downplayed fears that stablecoins could trigger a sudden deposit crisis, urging community banks to see them as competitive tools rather than threats. While banks push Congress to tighten the GENIUS Act amid projections of […]

Learn more

The Rising Threat of Romance Scams Targeting the Elderly

In our business we see a lot of different scams including many involving cryptocurrency and blockchains.  Recently we have seen a pickup in “romance” scams that do not involve cryptocurrency or even computers.  Simply put, these cases involve scumbags that prey on the elderly, often taking most if not all of their retirement funds.  The […]

Learn more