Home Blog TX CPA Firms Threat Brief

Download the PDF Version

Print-ready for your team, board, or compliance review. Email-gated — takes 30 seconds.

Download PDF →

In October 2023, Cl0p ransomware operators exploited a zero-day in MOVEit Transfer and hit Whitley Penn LLP — one of Texas's largest CPA firms, 900+ personnel across Dallas, Houston, Fort Worth, and Austin. Client tax returns, audit workpapers, and engagement letters were exfiltrated. Three months later, Lane Gorman Trubitt in Dallas was claimed by ALPHV/BlackCat. Here's what that means for every Texas accounting firm.

$8M
Orrick class action settlement — professional services liability precedent
$50,120
FTC civil penalty per violation per day — fully enforced since Jun 2023
241 days
average breach dwell time (IBM CODB 2025) vs CoreRecon 30-min SLA

The MOVEit Precedent — Why TX CPA Firms Were in the Crosshairs

The Cl0p MOVEit campaign of May–July 2023 is the most consequential supply chain attack targeting professional services firms in the past decade. Cl0p operators discovered a zero-day in MOVEit Transfer (CVE-2023-34362) before Progress Software knew it existed. They ran a coordinated global exploitation campaign, hitting 2,000+ organizations in 60 days before patches were available.

Why does this matter specifically to accounting firms? Because MOVEit Transfer is the default enterprise file transfer platform for transmitting client deliverables — tax returns, audit reports, financial statements, engagement letters. A CPA firm's MOVEit instance is literally the pipeline through which the most sensitive client data moves.

The IRS WISP requirement most TX CPA firms don't know exists: IRS Pub 4557 mandates a process for responding to a security incident. After an exfiltration like the Whitley Penn breach, IRS expects firms to notify affected clients, document their incident response, and maintain records demonstrating their WISP was in place before the incident. Firms without a documented WISP before a breach face both IRS and FTC penalty exposure simultaneously.

Lane Gorman Trubitt — The Double-Extortion Problem for CPA Firms

Three months after Whitley Penn, Dallas-based Lane Gorman Trubitt LLC appeared on ALPHV/BlackCat's leak site in January 2024. The firm serves closely held businesses, high-net-worth individuals, private equity-backed companies, and real estate investors — exactly the client base that makes a CPA firm's data disproportionately valuable.

Lane Gorman Trubitt LLC — Dallas, TX

January 2024 · ALPHV/BlackCat · Double-Extortion

What happened: ALPHV/BlackCat ransomware operators claimed Lane Gorman Trubitt on their leak site in January 2024. The firm's client data — including tax returns, audit workpapers, financial projections, and ownership structure documentation for private companies and high-net-worth families — was exfiltrated before encryption was deployed.

The double-extortion dynamic: ALPHV/BlackCat does not just encrypt and demand ransom. They exfiltrate first, then maintain two separate leverage points: (1) decrypt your systems for X dollars, and (2) don't publish your client data for Y dollars. For a CPA firm, "published data" means client tax returns and financial statements available publicly. No ransom payment makes those records unexposed after publication.

PE and family office exposure: High-net-worth and PE-backed clients have elevated exposure from tax return exfiltration. A Schedule K-1 for a PE-backed company reveals ownership structure, distribution amounts, capital account balances, and partner identities — intelligence that has direct market value for competitors, counterparties, and bad actors building identity profiles.

ALPHV/BlackCat double-extortion Dallas TX firm High-net-worth client data PE & family office exposure

The lesson from Lane Gorman Trubitt is that ransomware is no longer about restoring from backup. Double-extortion means a CPA firm's breach response can no longer be "we restored from backup and we're fine." The data is out. The client relationship is damaged. The TDPSA and FTC notification obligations are triggered regardless of whether systems are restored.

BST & Co. + Orrick — The Regulatory and Litigation Exposure

Two incidents outside Texas established the liability framework that now applies to every CPA firm in the state.

BST & Co. CPAs — HIPAA Business Associate Liability

2023–2024 · HIPAA BA Enforcement · Healthcare Client PHI

What happened: BST & Co., a regional CPA firm performing accounting services for healthcare clients, faced regulatory action after client Protected Health Information was involved in a breach. CPA firms that process payroll, billing, or cost-accounting data for HIPAA-covered entities — hospitals, physician groups, home health agencies — are Business Associates under 45 CFR 164 and subject to the same breach notification and security rule obligations as the covered entities themselves.

TX relevance: Approximately 400 Texas CPA firms serve as Business Associates to HIPAA-covered entities. Any firm that touches payroll, billing, or financial records for a hospital, physician group, or health plan is in scope. The BST precedent confirms OCR will pursue CPA firms directly for HIPAA violations — not just the healthcare organizations they serve.

HIPAA BA liability PHI in accounting records OCR enforcement precedent

Orrick, Herrington & Sutcliffe — $8M Class Action Settlement

2023 Breach · 2025 Settlement · Professional Services Liability Precedent

What happened: Orrick — a global law and advisory firm — suffered a breach of client confidential records and settled a class action for $8M in 2025. The settlement theory: breach of client data constitutes breach of fiduciary duty, malpractice, and contract — not just a regulatory event. This liability theory transfers directly to CPA firms.

Why CPA firms need to understand this: Orrick is a law firm, not an accounting firm. But CPA firms hold client data under identical confidentiality obligations — engagement letter commitments, AICPA Rule 301, and state CPA licensing regulations all create fiduciary-equivalent duties. Post-Orrick, a CPA firm breach is a potential $5M–$15M class action, not a $500K insurance claim. Most TX CPA firms carry $1M–$3M in professional liability coverage — insufficient against simultaneous FTC enforcement, TDPSA penalties, and a post-Orrick class action.

$8M class action settlement Fiduciary duty breach theory Class action risk for all prof. services

The Four-Mandate Compliance Stack — All Enforced Simultaneously

Texas CPA firms face four overlapping compliance mandates with four separate enforcement authorities. Most firms are aware of the IRS WISP requirement. Fewer understand that FTC Safeguards, TDPSA, and GLBA create independent enforcement tracks — meaning a single breach triggers simultaneous regulatory actions from multiple agencies.

IRS Publication 4557 — WISP

Every PTIN holder must maintain a Written Information Security Plan: designate coordinator, assess risks, implement safeguards, oversee service providers, incident response plan. IRS can suspend e-file privileges during breach investigation. Non-compliance is an AICPA ethics issue under Rule 301 (confidentiality standard).

E-file suspension + PTIN revocation

Source: IRS Pub 4557; IRS FY2025 "Dirty Dozen" (tax preparer identity theft)

FTC Safeguards Rule — 16 CFR Part 314

CPA firms are financial institutions under GLBA. Full enforcement since June 2023. 8 requirements: written ISP, Qualified Individual, risk assessment, MFA, encryption, IR plan, vendor oversight, annual pen test. 30-day FTC breach notification for 500+ records. FTC enforcement actions against accountants began 2024.

$50,120/violation/day — FTC civil penalty

Source: 16 CFR Part 314 (FTC, enforced since June 2023)

TDPSA — Texas Data Privacy Act

Effective July 1, 2024. $7,500/violation civil penalties. Any CPA firm doing business in TX processing Texas resident data is in scope. 45-day consumer request response. GLBA-regulated data partially exempt but marketing databases and CRM data are not. Separate TX AG enforcement track.

$7,500/violation — TX AG enforcement

Source: TX Data Privacy and Security Act (eff. July 1, 2024)

SOC 2 — Client Contractual Requirement

Enterprise clients, PE sponsors, and government contractors increasingly require SOC 2 Type II from their CPA firms. SOC 2 Trust Service Criteria (Security, Availability, Confidentiality) map directly to IRS WISP and FTC Safeguards requirements — one compliance program satisfies all three. Without SOC 2, firms lose enterprise RFP eligibility.

Client loss — RFP disqualification

Source: AICPA SOC 2 Trust Service Criteria (2017, updated 2022)

The multi-regulator problem most TX CPA firms haven't modeled: A single breach involving 500+ client records triggers IRS WISP failure documentation, FTC civil penalty ($50,120/day per violation count), TDPSA TX AG enforcement ($7,500/violation), and class action liability post-Orrick. Most TX CPA firms carry $1M–$3M in professional liability coverage. This is insufficient against concurrent multi-agency enforcement + class action. The correct risk question is not "what's our premium?" — it's "what's our maximum concurrent liability exposure?"

IRS WISP Compliance — The 8-Requirement Walkthrough

IRS Publication 4557 specifies eight requirements for a compliant Written Information Security Plan. Most TX CPA firms either have no WISP or have a PDF checklist document that doesn't reflect their actual security controls. Here's what a compliant WISP actually requires:

  1. Designate an Information Security Coordinator (ISC): A named individual responsible for implementing and maintaining the WISP. For firms without an in-house CISO, an outside vCISO satisfies this requirement — FTC guidance explicitly permits outside parties to serve in this role, and the same applies to IRS WISP.
  2. Written risk assessment: Documented identification of foreseeable risks to client data security, confidentiality, and integrity. Must cover internal threats (employee error, theft), external threats (ransomware, phishing, MFT exploitation), and environmental threats. Updated annually and after any significant change.
  3. Technical safeguards: Encryption for all client data in transit and at rest. MFA on all systems accessing client data — tax software, client portals, email, file storage. Automatic logoff for inactive sessions. Secure disposal of hardware containing client data.
  4. Physical safeguards: Access controls to physical areas housing client data. Visitor logs. Secure disposal procedures for paper records. Lock-screen policy for unattended workstations.
  5. Service provider oversight: Written agreements with all service providers handling client data (Thomson Reuters, Intuit, Drake, cloud storage, MFT providers). Contractual requirement for them to implement appropriate safeguards.
  6. Incident response plan: Documented procedures for responding to a breach: detection, assessment, containment, notification (IRS, clients, regulators as required), and post-incident documentation. Must be tested annually.
  7. Ongoing employee training: Annual security awareness training with documented completion records. Covers phishing recognition, password security, data handling procedures, and incident reporting.
  8. WISP updates and reviews: Annual review and update of the WISP document. Update triggered after: any security incident, changes to operations, or changes in service providers. IRS audit readiness — maintain WISP document with version history.
CoreRecon Command tier delivers: All 8 IRS WISP requirements satisfied through technical controls (SOC monitoring, MFA enforcement, encryption verification, MFT monitoring), program management (WISP authorship, annual updates, risk assessment), and the designated vCISO serving as Information Security Coordinator. WISP documentation maintained in auditor-ready format for IRS Safeguards Program review.

8 Controls Every TX CPA Firm Should Implement Now

The 8-Point Action Checklist

Written IRS WISP with designated Information Security Coordinator, current risk assessment, annual review schedule, and documented incident response procedures. Required for IRS e-file privileges.
MFA on all systems holding client tax data — Thomson Reuters UltraTax/CS, Drake, ProSystem fx, Intuit ProConnect, client portals, and all email accounts. GLBA 16 CFR 314.4(c)(5) requirement and IRS WISP technical safeguard.
MFT platform monitoring and 72-hour critical patch SLA for MOVEit, GoAnywhere, Cleo, ShareFile, and any file transfer platform used for client deliverables. Whitley Penn was MOVEit. The next wave will be a different platform — same attack surface.
GLBA Qualified Individual vCISO as designated ISC — delivers WISP authorship, annual risk assessment, annual management report, vendor oversight, and incident response planning. FTC and IRS both permit outside parties in this role.
Annual penetration test scoped to client portal, tax software integrations, MFT platform, email, and internal lateral movement paths. Required under FTC Safeguards Rule and IRS WISP framework. Document results and remediation timeline.
Vendor oversight program for Thomson Reuters, Intuit, Drake, document management platforms (iManage, NetDocuments, ShareFile), and any SaaS tool handling client financial data. FTC requires documented service provider oversight — contracts, security reviews, breach notification clauses.
TDPSA + FTC Safeguards dual compliance mapping — one program, two regulatory tracks. TDPSA TX AG notification ($7,500/violation) and FTC 30-day customer notification require different workflows. Pre-build both before a breach forces improvisation under fire.
BEC controls on client fund flows — tax refund wire diversion, estimated tax payment fraud, trust account BEC patterns. FBI IC3 2024: professional services BEC losses up 28% YoY. Out-of-band verbal verification for any wire instruction change exceeding $10K.

Find Out if Your CPA Firm's WISP and MFT Platform Are Audit-Ready

30-minute call. Map your IRS WISP compliance gaps, FTC Safeguards QI status, MFT platform exposure (MOVEit/GoAnywhere), and TDPSA notification readiness. Written report delivered in 14 days — no cost.

Get Free Assessment →

SDVOSB Certified  ·  30-Min SLA  ·  TX-Based Team  ·  IRS WISP + FTC Safeguards Expertise

TX CPA Firm Security → Gated PDF Brief → TDPSA Readiness Quiz → Breach Cost Calculator → TX Law Firms →
Sources & Citations Progress Software MOVEit Transfer security advisory CVE-2023-34362 (May 2023) • Cl0p MOVEit campaign reporting: KrebsOnSecurity, Bleeping Computer, Reuters (2023) • Whitley Penn LLP MOVEit incident reporting — multiple TX media outlets (Oct 2023) • Lane Gorman Trubitt ALPHV/BlackCat claim — ALPHV leak site (Jan 2024) • BST & Co. HIPAA BA regulatory action reporting (2023–2024) • Orrick Herrington & Sutcliffe class action settlement reporting (2025) • IRS Publication 4557: Safeguarding Taxpayer Data (rev. 2024) • IRS FY2025 "Dirty Dozen" — Tax Preparer Identity Theft • FTC Safeguards Rule, 16 CFR Part 314 (enforced since June 9, 2023) • Gramm-Leach-Bliley Act, 15 USC §6801 • Texas Data Privacy and Security Act (eff. July 1, 2024) — TX Attorney General • AICPA Code of Professional Conduct Rule 301 (confidentiality) • AICPA SOC 2 Trust Service Criteria (2017, updated 2022) • 45 CFR Part 164 HIPAA Security Rule (Business Associate obligations) • IBM Cost of Data Breach Report 2025 (241-day dwell time, $10.22M US avg, 600 orgs) • FBI IC3 2024 Annual Report ($2.77B BEC losses, professional services +28% YoY) • FBI IC3 2025 Annual Report ($20.877B total cybercrime losses) • CISA StopRansomware.gov — ALPHV/BlackCat advisory (Dec 2023) • Thomson Reuters Professional Services breach incidents (2024) • CPA firm security benchmarking: AICPA PCPS Member Survey (2024) • AccountingToday: CPA firm cybersecurity coverage (2023–2025) • Journal of Accountancy: cybersecurity for tax practitioners (2024)