Cybersecurity for Accounting Firms: Why CPAs Are Prime Targets
Accounting firms are targeted by cyberattacks because they hold more sensitive financial data per client than almost any other type of business. Tax returns, payroll records, bank account numbers, Social Security numbers, and full business financial statements all sit in one place, making a single successful breach extraordinarily valuable to criminals. The financial services sector averages $5.56 million per breach according to IBM’s 2025 Cost of a Data Breach Report, and smaller CPA firms face the same threat vectors as large financial institutions with a fraction of the security resources.
Why Cybersecurity Is a Top Risk for Accounting Firms
The answer starts with what accounting firms actually hold. A mid-size CPA firm serving 300 business clients and their principals may store:
- Federal and state tax returns with full identification data
- Payroll registers with employee SSNs, bank routing numbers, and wage history
- Audited financial statements with full revenue, debt, and ownership structures
- Entity formation documents and ownership agreements
- Banking and investment account credentials used during engagement work
Criminals do not have to attack a bank to get this data. They can attack the accounting firm and get the same result, often with less resistance. Researchers tracking CPA firm cyberattacks have found firms experience roughly 300 attack attempts per week, with that figure climbing toward 900 during tax season when deadline pressure creates conditions for rushed, less-scrutinized actions.
The Data Aggregation Problem
A law firm or a medical practice typically holds sensitive data for one person or one type of relationship. An accounting firm aggregates sensitive data across hundreds of clients, each with multiple data categories. A single credential compromise at the firm level unlocks all of it. For ransomware operators, this aggregation also creates powerful leverage: an accounting firm under audit deadlines or payroll processing pressure cannot afford weeks of system downtime, making it more likely to pay a ransom quickly rather than rebuild from backup.
Security Resources Are Often Mismatched to Risk
Most accounting firms are small businesses by employee count. Many operate with shared file drives, cloud accounting platforms, and a patchwork of consumer-grade security tools. Even firms with dedicated IT support often lack a formal incident response plan, a tested backup and recovery procedure, or multi-factor authentication across all systems. The 2025 Verizon Data Breach Investigations Report found that roughly 60% of breaches involved a human element, including stolen credentials, phishing, or simple employee error. That figure applies directly to accounting firm environments where staff routinely receive tax documents, payroll files, and financial data from external parties.
The Threat Landscape in 2026
Phishing and Business Email Compromise
Phishing remains the most common initial access vector for accounting firm breaches. Modern phishing campaigns no longer rely on obvious errors or implausible scenarios. AI-generated emails now replicate the writing style of known contacts, reference real client names pulled from prior breaches, and arrive during moments of predictable stress, such as filing deadlines or quarter-end close. Business email compromise (BEC) attacks specifically target accounting and finance staff because those employees have authority to initiate wire transfers, update vendor banking information, and release payroll files.
Ransomware
Ransomware groups have repeatedly listed accounting and financial services firms among their top targets. In a documented 2026 attack, the Akira ransomware group claimed responsibility for an attack on a Texas accounting firm, alleging exfiltration of approximately 40 GB of client and employee data. In 2025, the Qilin threat group published internal documents stolen from an Australian accounting firm after a ransomware attack. These are not isolated incidents. The economics are clear: firms with client obligations and compliance deadlines will pay to restore access faster than an organization that can absorb extended downtime.
Credential Theft and Identity-Based Attacks
Credential abuse now drives the majority of cyberattacks across all industries. For accounting firms, this takes a specific form: attackers obtain login credentials for cloud-based tax software, document management systems, or client portals, then quietly extract data over weeks or months before triggering an obvious incident. Many such breaches are never detected by the firm itself but surface later when clients find their information on dark-web marketplaces or when fraudulent returns are filed using stolen taxpayer data.
Third-Party and Supply Chain Risk
Accounting firms increasingly depend on third-party software providers for tax preparation, practice management, payroll processing, and document storage. A breach at any one of these vendors creates exposure for every firm using their platform. The 2025 Verizon DBIR found that third-party involvement in breaches doubled year over year, rising from 15% to 30%, and accounting firms rarely have contractual visibility into the security posture of their software vendors. A single vendor compromise can expose thousands of firms simultaneously.
Regulatory Requirements for Protecting Financial Data
Accounting firms are not operating in a regulatory vacuum on cybersecurity. Two frameworks apply directly to virtually every firm that handles client financial data.
FTC Safeguards Rule
The Federal Trade Commission’s Safeguards Rule (16 CFR Part 314) classifies tax preparers, CPAs, enrolled agents, bookkeepers, and accounting firms as “financial institutions” subject to mandatory information security requirements. The rule requires a Written Information Security Plan (WISP) that covers nine specific program elements, including a designated Qualified Individual responsible for security, annual risk assessments, access controls, encryption, employee training, and vendor oversight.
An amendment finalized in 2023 and effective May 13, 2024 requires firms to notify the FTC no later than 30 days after discovering a breach that affects at least 500 consumers. Civil penalties for knowing violations of the rule reach $51,744 per violation as of 2026 (an inflation-adjusted figure the FTC updates each January). Firms of every size are covered; there is no small-business exemption.
IRS Publication 4557 and WISP Requirements
The IRS enforces a parallel set of obligations under Publication 4557 (“Safeguarding Taxpayer Data”) and Publication 5708 (“Creating a Written Information Security Plan for Your Tax & Accounting Practice”). Both publications require paid tax preparers to maintain a documented WISP. Critically, Form W-12, Line 11 now asks preparers renewing a PTIN to acknowledge their data security responsibilities, including maintaining a WISP. Providing false information on the form carries perjury exposure and can result in PTIN revocation.
The IRS Publication 4557 and the FTC Safeguards Rule together represent the floor of required security practice, not the ceiling. The NIST Cybersecurity Framework 2.0, released in February 2024, provides a broader governance structure that accounting firms can use as a roadmap for building a comprehensive information security program, including the newly added Govern function that addresses organizational risk management strategy and supply chain oversight.
Building a Defensible Security Program
A credible security program for an accounting firm does not require a security operations center. It requires documented policies, tested controls, and consistent execution across the nine elements the FTC Safeguards Rule mandates.
Access Controls and Multi-Factor Authentication
Every system that holds client data should require multi-factor authentication. This single control eliminates the majority of credential-theft attack scenarios. Access should be scoped to what each employee needs for their role, and access should be revoked promptly when staff depart.
Employee Training
Phishing simulations and regular training are not optional extras. Staff who handle incoming tax documents, client emails, and financial files are the primary attack surface. Training should be specific and realistic, using examples that mirror the actual social engineering techniques in current use.
Incident Response Planning
A firm without a written incident response plan will lose days of response time when an incident occurs. The plan should specify who gets notified, in what order, who is authorized to contact clients, and what documentation must be preserved for regulatory reporting. The FTC’s 30-day notification window runs from the point the firm knows or reasonably should have known about a breach, not from the point the investigation concludes.
Vendor Due Diligence
Every third-party software vendor with access to client data should be assessed for their security posture before onboarding and reviewed annually. At minimum, firms should obtain vendor SOC 2 reports, review data processing agreements, and confirm breach notification obligations are included in vendor contracts.
Backup and Recovery
Ransomware is only catastrophic if it destroys the only copy of the data. Firms should maintain encrypted, air-gapped or immutable backups that are tested for restorability on a schedule. The test is not whether the backup exists; the test is whether the firm can actually restore a full working environment within a recovery time objective that keeps the business functioning.
What Finance Leaders and Firm Owners Should Do Now
The cybersecurity posture of an accounting firm is a direct reflection of how seriously it takes its obligations to clients. When a client hands a firm their payroll data, their tax returns, and their banking information, they are extending significant trust. A breach of that data harms the client, exposes the firm to regulatory liability, and often ends the relationship permanently.
The AICPA’s CPA Cybersecurity Checklist provides a structured starting point for firms that want to assess and document their current posture. For firms that work with Modus on audit and advisory engagements, cybersecurity is increasingly part of the broader risk management conversation, not a separate IT discussion.
Firms that view cybersecurity as a compliance checkbox will continue to be outpaced by threat actors who view accounting firms as high-value, low-difficulty targets. Firms that treat it as a business risk, assign ownership, test controls, and iterate will be significantly more resilient.
At Modus, our AI-native approach to audit and assurance includes working with clients to think through the data environments their financial information flows through, which increasingly means asking harder questions about who has access to what, and whether those access controls have been tested recently.
Frequently Asked Questions
Why are accounting firms targeted by cyberattacks?
Accounting firms are targeted because they aggregate high-value financial data across hundreds of clients, including tax returns, payroll records, Social Security numbers, bank account details, and full business financial statements. A single successful breach gives attackers a concentrated dataset worth far more than hacking individual targets one at a time.
What is a WISP and do all CPA firms need one?
A Written Information Security Plan (WISP) is a documented security program that describes how a firm protects client data. The FTC Safeguards Rule and IRS Publication 4557 require every accounting firm, tax preparer, and enrolled agent that handles customer financial information to maintain a WISP, regardless of firm size. There is no small-business exemption.
What happens if an accounting firm has a data breach?
Under the FTC Safeguards Rule, a firm must notify the FTC within 30 days of discovering a breach that affects 500 or more customers. State breach notification laws may impose shorter deadlines and additional requirements. Beyond regulatory penalties, which can reach $51,744 per violation, firms face client notification obligations, potential litigation, and reputational harm.
What is the average cost of a data breach for a financial services firm?
According to IBM’s 2025 Cost of a Data Breach Report, the average breach cost in financial services is $5.56 million, making it the second-most-expensive sector after healthcare. This figure includes detection, containment, notification, regulatory response, and lost business costs.
How can an accounting firm protect itself from ransomware?
Key defenses include multi-factor authentication on all systems, regular employee phishing training, encrypted and tested offline backups, a written incident response plan, and prompt patching of software vulnerabilities. Firms should also limit third-party access to client data and obtain SOC 2 reports from critical software vendors.
Does the NIST Cybersecurity Framework apply to accounting firms?
Yes. NIST CSF 2.0, released in February 2024, is designed for organizations of all sizes and sectors. For accounting firms, it provides a practical governance structure covering Govern, Identify, Protect, Detect, Respond, and Recover functions. The AICPA also references the NIST CSF as an acceptable criteria framework for SOC for Cybersecurity examinations.
Filed under: Cybersecurity & Risk