In October 2023, Cl0p ransomware operators exploited a zero-day in MOVEit Transfer and hit Whitley Penn LLP — one of Texas's largest CPA firms, 900+ personnel across Dallas, Houston, Fort Worth, and Austin. Client tax returns, audit workpapers, and engagement letters were exfiltrated. Three months later, Lane Gorman Trubitt in Dallas was claimed by ALPHV/BlackCat. Here's what that means for every Texas accounting firm.
The MOVEit Precedent — Why TX CPA Firms Were in the Crosshairs
The Cl0p MOVEit campaign of May–July 2023 is the most consequential supply chain attack targeting professional services firms in the past decade. Cl0p operators discovered a zero-day in MOVEit Transfer (CVE-2023-34362) before Progress Software knew it existed. They ran a coordinated global exploitation campaign, hitting 2,000+ organizations in 60 days before patches were available.
Why does this matter specifically to accounting firms? Because MOVEit Transfer is the default enterprise file transfer platform for transmitting client deliverables — tax returns, audit reports, financial statements, engagement letters. A CPA firm's MOVEit instance is literally the pipeline through which the most sensitive client data moves.
- Whitley Penn LLP (Dallas/Houston/Fort Worth/Austin, Oct 2023): One of the largest regional CPA firms in Texas with 900+ personnel. The Cl0p campaign targeted MFT platforms specifically because that's where professional services firms concentrate client data. Whitley Penn's clients — primarily closely-held businesses, real estate investors, and professional services companies — had their financial records exfiltrated.
- The patch window problem: Zero-day exploitation means no patch existed at the time of attack. But post-disclosure, CPA firms that hadn't patched within 72 hours were still being actively exploited. Most accounting firms don't have 72-hour critical vulnerability patch SLAs — they have a "we'll get to it" IT support model.
- IRS implication: Tax return data is specifically called out in IRS Publication 4557 as requiring protection under the WISP. An exfiltration of client tax data triggers IRS Safeguards Program notification obligations and can result in suspension of e-file privileges during investigation.
Lane Gorman Trubitt — The Double-Extortion Problem for CPA Firms
Three months after Whitley Penn, Dallas-based Lane Gorman Trubitt LLC appeared on ALPHV/BlackCat's leak site in January 2024. The firm serves closely held businesses, high-net-worth individuals, private equity-backed companies, and real estate investors — exactly the client base that makes a CPA firm's data disproportionately valuable.
Lane Gorman Trubitt LLC — Dallas, TX
What happened: ALPHV/BlackCat ransomware operators claimed Lane Gorman Trubitt on their leak site in January 2024. The firm's client data — including tax returns, audit workpapers, financial projections, and ownership structure documentation for private companies and high-net-worth families — was exfiltrated before encryption was deployed.
The double-extortion dynamic: ALPHV/BlackCat does not just encrypt and demand ransom. They exfiltrate first, then maintain two separate leverage points: (1) decrypt your systems for X dollars, and (2) don't publish your client data for Y dollars. For a CPA firm, "published data" means client tax returns and financial statements available publicly. No ransom payment makes those records unexposed after publication.
PE and family office exposure: High-net-worth and PE-backed clients have elevated exposure from tax return exfiltration. A Schedule K-1 for a PE-backed company reveals ownership structure, distribution amounts, capital account balances, and partner identities — intelligence that has direct market value for competitors, counterparties, and bad actors building identity profiles.
The lesson from Lane Gorman Trubitt is that ransomware is no longer about restoring from backup. Double-extortion means a CPA firm's breach response can no longer be "we restored from backup and we're fine." The data is out. The client relationship is damaged. The TDPSA and FTC notification obligations are triggered regardless of whether systems are restored.
BST & Co. + Orrick — The Regulatory and Litigation Exposure
Two incidents outside Texas established the liability framework that now applies to every CPA firm in the state.
BST & Co. CPAs — HIPAA Business Associate Liability
What happened: BST & Co., a regional CPA firm performing accounting services for healthcare clients, faced regulatory action after client Protected Health Information was involved in a breach. CPA firms that process payroll, billing, or cost-accounting data for HIPAA-covered entities — hospitals, physician groups, home health agencies — are Business Associates under 45 CFR 164 and subject to the same breach notification and security rule obligations as the covered entities themselves.
TX relevance: Approximately 400 Texas CPA firms serve as Business Associates to HIPAA-covered entities. Any firm that touches payroll, billing, or financial records for a hospital, physician group, or health plan is in scope. The BST precedent confirms OCR will pursue CPA firms directly for HIPAA violations — not just the healthcare organizations they serve.
Orrick, Herrington & Sutcliffe — $8M Class Action Settlement
What happened: Orrick — a global law and advisory firm — suffered a breach of client confidential records and settled a class action for $8M in 2025. The settlement theory: breach of client data constitutes breach of fiduciary duty, malpractice, and contract — not just a regulatory event. This liability theory transfers directly to CPA firms.
Why CPA firms need to understand this: Orrick is a law firm, not an accounting firm. But CPA firms hold client data under identical confidentiality obligations — engagement letter commitments, AICPA Rule 301, and state CPA licensing regulations all create fiduciary-equivalent duties. Post-Orrick, a CPA firm breach is a potential $5M–$15M class action, not a $500K insurance claim. Most TX CPA firms carry $1M–$3M in professional liability coverage — insufficient against simultaneous FTC enforcement, TDPSA penalties, and a post-Orrick class action.
The Four-Mandate Compliance Stack — All Enforced Simultaneously
Texas CPA firms face four overlapping compliance mandates with four separate enforcement authorities. Most firms are aware of the IRS WISP requirement. Fewer understand that FTC Safeguards, TDPSA, and GLBA create independent enforcement tracks — meaning a single breach triggers simultaneous regulatory actions from multiple agencies.
IRS Publication 4557 — WISP
Every PTIN holder must maintain a Written Information Security Plan: designate coordinator, assess risks, implement safeguards, oversee service providers, incident response plan. IRS can suspend e-file privileges during breach investigation. Non-compliance is an AICPA ethics issue under Rule 301 (confidentiality standard).
Source: IRS Pub 4557; IRS FY2025 "Dirty Dozen" (tax preparer identity theft)
FTC Safeguards Rule — 16 CFR Part 314
CPA firms are financial institutions under GLBA. Full enforcement since June 2023. 8 requirements: written ISP, Qualified Individual, risk assessment, MFA, encryption, IR plan, vendor oversight, annual pen test. 30-day FTC breach notification for 500+ records. FTC enforcement actions against accountants began 2024.
Source: 16 CFR Part 314 (FTC, enforced since June 2023)
TDPSA — Texas Data Privacy Act
Effective July 1, 2024. $7,500/violation civil penalties. Any CPA firm doing business in TX processing Texas resident data is in scope. 45-day consumer request response. GLBA-regulated data partially exempt but marketing databases and CRM data are not. Separate TX AG enforcement track.
Source: TX Data Privacy and Security Act (eff. July 1, 2024)
SOC 2 — Client Contractual Requirement
Enterprise clients, PE sponsors, and government contractors increasingly require SOC 2 Type II from their CPA firms. SOC 2 Trust Service Criteria (Security, Availability, Confidentiality) map directly to IRS WISP and FTC Safeguards requirements — one compliance program satisfies all three. Without SOC 2, firms lose enterprise RFP eligibility.
Source: AICPA SOC 2 Trust Service Criteria (2017, updated 2022)
IRS WISP Compliance — The 8-Requirement Walkthrough
IRS Publication 4557 specifies eight requirements for a compliant Written Information Security Plan. Most TX CPA firms either have no WISP or have a PDF checklist document that doesn't reflect their actual security controls. Here's what a compliant WISP actually requires:
- Designate an Information Security Coordinator (ISC): A named individual responsible for implementing and maintaining the WISP. For firms without an in-house CISO, an outside vCISO satisfies this requirement — FTC guidance explicitly permits outside parties to serve in this role, and the same applies to IRS WISP.
- Written risk assessment: Documented identification of foreseeable risks to client data security, confidentiality, and integrity. Must cover internal threats (employee error, theft), external threats (ransomware, phishing, MFT exploitation), and environmental threats. Updated annually and after any significant change.
- Technical safeguards: Encryption for all client data in transit and at rest. MFA on all systems accessing client data — tax software, client portals, email, file storage. Automatic logoff for inactive sessions. Secure disposal of hardware containing client data.
- Physical safeguards: Access controls to physical areas housing client data. Visitor logs. Secure disposal procedures for paper records. Lock-screen policy for unattended workstations.
- Service provider oversight: Written agreements with all service providers handling client data (Thomson Reuters, Intuit, Drake, cloud storage, MFT providers). Contractual requirement for them to implement appropriate safeguards.
- Incident response plan: Documented procedures for responding to a breach: detection, assessment, containment, notification (IRS, clients, regulators as required), and post-incident documentation. Must be tested annually.
- Ongoing employee training: Annual security awareness training with documented completion records. Covers phishing recognition, password security, data handling procedures, and incident reporting.
- WISP updates and reviews: Annual review and update of the WISP document. Update triggered after: any security incident, changes to operations, or changes in service providers. IRS audit readiness — maintain WISP document with version history.
8 Controls Every TX CPA Firm Should Implement Now
The 8-Point Action Checklist
Find Out if Your CPA Firm's WISP and MFT Platform Are Audit-Ready
30-minute call. Map your IRS WISP compliance gaps, FTC Safeguards QI status, MFT platform exposure (MOVEit/GoAnywhere), and TDPSA notification readiness. Written report delivered in 14 days — no cost.
Get Free Assessment →SDVOSB Certified · 30-Min SLA · TX-Based Team · IRS WISP + FTC Safeguards Expertise