Accounting Firm Cyber Incident Report 2026: WISP Enforcement, the Breach Filings, and the 30-Day Clock

Accounting and tax firms hold the exact data an identity thief needs: Social Security numbers, financial accounts, tax transcripts, and copies of government IDs, all organized by household. Most firms holding it have under fifty people and nobody whose job is security. This report collects what the public record actually shows for CPA and tax-preparation firms through 2023 to mid-2026: the breach filings, the federal rules that now apply to every preparer, and what the broader datasets say. Every figure is tied to a source in the list at the end.
Key findings
- Every tax preparer with a PTIN is legally required to have a Written Information Security Plan under the FTC Safeguards Rule, and since the 2024 renewal cycle, Form W-12 asks preparers to certify their data-security obligations when renewing. There is no small-firm exemption.[1][2]
- Since May 13, 2024, non-bank financial institutions, a category that includes tax preparation firms, must report breaches affecting 500 or more consumers to the FTC within 30 days, and those reports land in a public database.[3]
- The largest accounting-firm breach in the recent record is Legacy Professionals LLP: 216,752 people, a LockBit 3.0 ransomware intrusion in April 2024 with member notices mailed roughly ten months later, now followed by at least five class-action suits.[4][5]
- Top-50 firm Frazier & Deeter reported 19,475 people affected after a 2023 intrusion that sat undiscovered for about three and a half months.[6]
- The pattern reaches all the way down: Edwards, Faust & Smith, a Bangor, Maine CPA firm, reported 928 people affected in 2026 after a phishing attack, first spotted by the firm's outside IT provider.[7]
- A South Carolina CPA society case study describes a Georgia firm that paid a $450,000 ransom to recover encrypted client files.[8]
- Across all industries, Verizon's 2026 DBIR found ransomware in 48 percent of breaches and third-party involvement in 48 percent, with exploitation of software vulnerabilities overtaking stolen credentials as the top way in.[9]
- The FBI logged $20.9 billion in reported cybercrime losses in 2025; the IRS Security Summit warns that schemes now target preparers' EFIN, PTIN, and CAF credentials directly, and cites estimates that most breaches begin with a spear-phishing email.[10][11]
The rules most firms have not read
Three federal requirements now apply to essentially every firm that prepares returns, regardless of size.
The WISP requirement. The Gramm-Leach-Bliley Act's Safeguards Rule treats tax preparers as financial institutions, which means every firm must maintain a written information security plan: a named responsible individual, a risk assessment, employee training, multi-factor authentication, oversight of service providers, and an incident response plan. IRS Publications 4557 and 5709 lay out the expected contents. This is not new law, but enforcement attention is, and the FTC's civil penalties run to five figures per violation.[1][2]
The W-12 certification. Renewing a PTIN now involves attesting to your data-security responsibilities on Form W-12. A firm that checks the box without a plan on paper has converted a compliance gap into a false statement to the IRS.[2]
The 30-day FTC notification. Since May 13, 2024, a breach of unencrypted client data affecting 500 or more people must be reported to the FTC within 30 days of discovery, and the FTC publishes these reports. For a firm with a few thousand 1040 clients, one compromised workstation clears that threshold easily. The state attorney general notifications that firms already owe come on top.[3]
What the filings show
Legacy Professionals LLP, Chicago
Intruders accessed the firm's network on two days in late April 2024. The LockBit 3.0 group later claimed the attack and published stolen data in August 2024. The firm's filings put the affected count at 216,752 people, with Social Security numbers, driver's license numbers, financial account, medical, and health-insurance information involved. Notices went out on February 27, 2025, about ten months after the intrusion, and at least five proposed class actions followed, several citing the notification delay itself as a harm.[4][5]
Frazier & Deeter, Atlanta
An unauthorized party entered the top-50 firm's network on May 19, 2023. The intrusion was discovered on September 5, 2023, and the firm notified the Maine Attorney General on October 11, 2023, reporting 19,475 people affected, including Social Security numbers and financial account information. Three and a half months of undetected access at a firm with nine offices is the detection story, not the entry story.[6]
Edwards, Faust & Smith, Bangor, Maine
A phishing attack led to unauthorized access that the firm's IT provider discovered on April 30, 2026. The firm reported 928 people affected, 837 of them Maine residents, with tax returns, IRS transcripts, Social Security numbers, and financial statements among the exposed data. Notices went out May 28, 2026, four weeks after discovery, which is what a working incident-response plan looks like at a small firm.[7]
The ransom case
A July 2025 South Carolina Association of CPAs article recounts a Georgia CPA firm that paid $450,000 to regain access to encrypted client files. Firms facing a filing deadline are unusually good extortion targets: the attacker's leverage is not just the data but the calendar.[8]
Why preparers specifically
The IRS Security Summit, now in its tenth year, has been explicit about why this sector draws attackers. A preparer's file server holds everything needed to file convincing fraudulent returns at scale, and a preparer's credentials, the EFIN, PTIN, and CAF numbers, are themselves the target of dedicated phishing campaigns because they unlock filing infrastructure. The Summit's guidance cites estimates that roughly nine in ten successful attacks begin with a spear-phishing email, and the Edwards, Faust & Smith filing shows exactly that path in the wild.[10][11]
The seasonal shape matters too. A firm hit in February cannot simply take systems offline for two weeks the way Patelco Credit Union did; deadlines convert downtime into client attrition, which is why the ransom-payment pressure is worse in this sector than the averages suggest.
The broader numbers
Verizon's 2026 Data Breach Investigations Report, covering more than 22,000 confirmed breaches, found ransomware present in 48 percent of them and a third party involved in 48 percent, with vulnerability exploitation, at 31 percent, passing stolen credentials as the leading entry point for the first time.[9] The FBI's Internet Crime Complaint Center recorded 1,008,597 complaints and $20.9 billion in losses in 2025.[10] For accounting firms the third-party number deserves the underline: the Bangor firm's breach was found by its IT provider, and for most small firms the IT provider, the tax software host, and the portal vendor are the perimeter.
What a 5-to-50 person firm should actually do
- Write the WISP as a working document, not a checkbox. Name the responsible person, date the risk assessment, and review it before each filing season. The W-12 attestation makes the checkbox itself a legal statement.[2]
- Turn on MFA everywhere that touches client data, including the tax software, the portal, email, and the IT provider's remote-access tools.
- Drill the phishing scenario, because that is the front door in this sector: EFIN/PTIN credential lures, fake IRS correspondence, and client-impersonation emails during season.[11]
- Put the 30-day clock in the incident plan. Who decides it is a notification event, who files with the FTC, who calls the state AGs, who tells clients. The firms that notified in four weeks had this written down; the ten-month notifications are now class-action exhibits.[3][4][7]
- Treat the IT provider as part of the security program. Ask how they would detect access to your file server, what their own MFA posture is, and whether their remote tools are patched. Third parties sit in nearly half of all breaches.[9]
- Know your exposure count. If the client file holds more than 500 people, and almost every firm's does, the FTC reporting duty applies to you, not just to the big firms.[3]
None of this requires hiring a security executive. It requires a few accountable hours a month from someone who has run this playbook, and a record that survives an FTC question or an insurer's renewal questionnaire.
Related from BlueRadius: what a fractional CISO costs for a firm this size, our virtual CISO service, how we run SOC 2 and audit programs, and a free assessment that starts with the WISP and the vendor list. For the financial-institution side of this picture, see the Credit Union and Community Bank Cyber Incident Report 2026; for planning, the incident response planning guide and cyber insurance guide.
Methodology and limits
Incident details come from state Attorney General filings (Maine, Vermont, Massachusetts) and HHS OCR reporting as covered by the security and legal press, cited per incident. The WISP and notification requirements are drawn from the FTC's rule text and business guidance and IRS publications. Cross-industry statistics are from Verizon's 2026 DBIR and the FBI's 2025 Internet Crime Report. There is no central public count of accounting-firm breaches; the FTC's notification database, live since mid-2024, is the closest thing emerging and covers only 500-plus-consumer events reported to it. Claims that circulate without a traceable source, including a widely repeated percentage increase in CPA-firm breaches, were left out.
Sources
- FTC, Safeguards Rule: What Your Business Needs to Know; IRS, Publication 5709: How to Create a Written Information Security Plan
- IRS, Protect Your Clients; Protect Yourself (Pub 4557 guidance and PTIN/W-12 data-security responsibilities)
- FTC, Safeguards Rule notification requirement now in effect (May 2024)
- BankInfoSecurity, Accounting Firm Notifying 217,000 of Health Data Hack
- teiss, Chicago accounting firm faces class-action lawsuits over 2024 data breach
- Vermont Attorney General, Frazier & Deeter breach notice; Turke & Strauss, Frazier & Deeter investigation
- Maine Attorney General breach filing as reported by ClaimDepot: Edwards, Faust & Smith
- South Carolina Association of CPAs, When Ransomware Hits a CPA Firm
- Verizon, 2026 Data Breach Investigations Report
- FBI Internet Crime Complaint Center, 2025 Internet Crime Report
- IRS, Security Summit: tax pros should watch out for phishing; IRS, National Tax Security Awareness Week 2025
Related from the BlueRadius Library
Sourced posts on adjacent topics, ranked by tag overlap.
Leadership
12 Questions to Ask Before Hiring a vCISO (2026)
Hiring a virtual CISO? Ask these 12 questions first, covering scope, frameworks, pricing, integration, references, and how to evaluate the answers.
ReadAI Security
Securing AI Agents: An Agentic AI Security Guide for 2026
An agentic AI security guide for mid-market: the agent attack surface, prompt injection, excessive agency, non-human identities, and a checklist.
ReadCompliance
PCI DSS 4.0.1 Compliance: A Mid-Market Guide for 2026
A PCI DSS 4.0.1 compliance guide for mid-market companies: merchant levels, SAQ selection, what changed in 4.0, and a step-by-step readiness checklist.
ReadManaged Security
Managed Cybersecurity Services for Mid-Market Companies 2026
What mid-market companies (50-2,000 employees) need from managed cybersecurity services in 2026: coverage, pricing components, and where engagements fail.
ReadIndustry
How to Add a Cybersecurity Practice to Your MSP Without Hiring a CISO
How MSPs add a cybersecurity practice without hiring a full-time CISO: vCISO partnership model, revenue share, technology stack, and client onboarding.
ReadCompliance
HIPAA Breach Report 2026: OCR Data, Ransomware Trends, and What Mid-Market Healthcare Must Do Next
Factual 2024 HIPAA breach analysis: 276 million records exposed, 725 OCR-reported breaches, and Change Healthcare at 190 million. Fully sourced.
ReadRelated services