Whitley Penn. Lane Gorman Trubitt. BST & Co. Orrick's $8M settlement. The accounting sector saw more named ransomware and MFT incidents in 2023–2025 than any prior two-year window. Tax returns, audit workpapers, and client financial records are the highest-value identity theft packages available.
These aren't generic ransomware statistics. These are documented incidents at named accounting and professional services firms — each with regulatory, legal, and reputational consequences that reshaped how clients, bar associations, and federal regulators view CPA firm cybersecurity.
What happened: Whitley Penn — one of Texas's largest regional CPA firms, 900+ personnel — was hit by Cl0p ransomware through the MOVEit managed file transfer vulnerability. Client financial records, tax workpapers, and audit engagement letters were exfiltrated. Cl0p's MOVEit campaign hit 2,000+ organizations globally in 60 days.
Why it matters for TX CPA firms: MOVEit and GoAnywhere are the standard file transfer tools for transmitting tax returns, audit deliverables, and client financial statements. Every CPA firm that processes client data via MFT platform was in scope for the same CVE. The vulnerability existed in every unpatched MOVEit installation — patch timing was the only differentiator.
IRS implication: Exfiltrated tax data triggers IRS Safeguards Program notification requirements and potential suspension of e-file privileges during investigation. Client notification obligations under TDPSA apply to any Texas resident whose data was involved.
What happened: Lane Gorman Trubitt, a Dallas-based CPA firm serving closely held businesses and high-net-worth individuals, was claimed by ALPHV/BlackCat in January 2024. The firm's client roster — private equity-backed companies, real estate investors, and family offices — made their audit workpapers and tax returns exceptionally high-value targets. Double-extortion: data exfiltrated before encryption deployed.
The double-extortion model: ALPHV/BlackCat does not just encrypt — they exfiltrate first, then threaten to publish on their leak site. For a CPA firm, "published data" means client tax returns, ownership structures, financial account information, and business valuation workpapers — all publicly accessible. Client relationships are permanently damaged even if the firm pays and systems are restored.
What happened: BST & Co., a CPA firm that performed accounting services for healthcare clients, faced regulatory action after client PHI exposure. CPA firms that process financial records for covered entities — hospitals, physician groups, home health agencies — are Business Associates under HIPAA and subject to the same breach notification and security rule obligations as the healthcare organizations themselves.
TX relevance: Approximately 400 CPA firms in Texas serve as Business Associates to HIPAA-covered entities. Any firm that touches payroll, billing, or cost-accounting data for a hospital or physician practice is in scope. The BST precedent confirms OCR will pursue CPA firms — not just healthcare providers — for HIPAA violations.
What happened: Orrick — a global law firm that handles M&A, PE, and corporate transactions — suffered a breach of client confidential records. The $8M class action settlement (2025) established a significant liability precedent for professional services firms: breach of client data is actionable as breach of fiduciary duty, malpractice, and contract — not just a regulatory event.
Why CPA firms should care: Orrick is a law firm, not an accounting firm — but the liability theory is identical. CPA firms hold client data under engagement letter confidentiality obligations. Post-Orrick, any CPA firm breach is a potential class action, not just an insurance claim. The $8M settlement came from a firm with substantial professional liability coverage. Smaller TX CPA firms with $1–$5M policy limits face existential exposure.
Texas CPA firms face a compliance stack that grew significantly in 2023–2024. Most firms are aware of IRS WISP requirements. Fewer understand that FTC Safeguards, TDPSA, and GLBA create independent obligations — with separate enforcement authorities and penalty structures.
Every PTIN holder must maintain a Written Information Security Plan. Designate a coordinator, conduct risk assessment, implement safeguards, oversee service providers, incident response plan. IRS can revoke e-file privileges during breach investigation. Non-compliance is also cited in AICPA ethics rules under the confidentiality standard.
Source: IRS Pub 4557; IRS Dirty Dozen 2025 (tax preparer identity theft)
CPA firms are classified as financial institutions under GLBA. Full enforcement since June 2023. 8 requirements: written ISP, Qualified Individual, risk assessment, MFA, encryption, IR plan, vendor oversight, annual pen test. 30-day FTC breach notification for 500+ customer records. FTC enforcement actions against accountants began 2024.
Source: 16 CFR Part 314 (FTC, enforced since Jun 2023)
Effective July 1, 2024. $7,500/violation civil penalties. Any CPA firm doing business in Texas that processes personal data of Texas residents is in scope. 45-day consumer data request response. Data Protection Assessment required for high-risk processing. GLBA-regulated data partially exempt but marketing/analytics databases are not.
Source: TX Data Privacy and Security Act; TX Attorney General
Enterprise clients, PE sponsors, and government contractors increasingly require SOC 2 Type II certification from their CPA firms. SOC 2 Trust Service Criteria (Security, Availability, Confidentiality) map directly to IRS WISP and FTC Safeguards requirements — a single compliance program can satisfy all three. Without SOC 2, firms may lose RFP eligibility for enterprise audit engagements.
Source: AICPA SOC 2 Trust Service Criteria (2017 update)
Month-to-month. No long-term contracts. SDVOSB pricing. All tiers include 24/7 SOC monitoring, IRS WISP-compatible controls documentation, and FTC Safeguards technical control evidence.
Service-Disabled Veteran-Owned Small Business. Qualifies for GSA Schedule set-asides, SBA 8(a) program access, and state procurement preferences. TX state vendor via AT&T — active on TX Department of Information Resources (DIR) contracts.
IBM CODB 2025: industry average breach identification = 241 days. A CPA firm breached in January (tax season) faces simultaneous client impact, IRS notification risk, and FTC 30-day clock. Our 30-minute SLA for critical incidents means detection happens in hours, not months.
Client tax data and financial records processed by a TX SOC staffed by TX-based engineers. No offshore SOC handling IRS client data. TX state residency for data processing is increasingly required by TX state agency and municipal contracts.
We understand Thomson Reuters UltraTax, Drake, ProSystem fx, Intuit ProConnect, and the MFT platforms that carry client deliverables. Our playbooks are built around tax season risk windows, month-end close, and engagement letter workflows — not generic enterprise security templates.
30-minute call with a CPA firm security specialist. We map your IRS WISP compliance gaps, FTC Safeguards QI status, MFT platform exposure (MOVEit/GoAnywhere), and TDPSA notification readiness. Written report delivered in 14 days at no cost.
Book Free Assessment →SDVOSB Certified · 30-Min SLA · TX-Based Team · No Long-Term Contracts