CoreRecon Threat Intelligence  •  Texas Accounting & CPA Firms  •  July 2026 V43

TX Accounting & CPA Firms:
The Tax Season Kill Zone

Landmark Admin (TX TPA, 2024) lost 800,000 claimant records. Whitley Penn (Oct 2023) and Lane Gorman Trubitt (Jan 2024) both confirmed ransomware. IRS Publication 4557 mandates a 14-element WISP for every PTIN holder. The 2023 FTC Safeguards Rule amendment explicitly classifies tax preparation firms as financial institutions. PCAOB audit-client flow-down adds AS 1000/QC 1000/AS 1215 obligations. Tax-prep credentials — EFIN tokens, QuickBooks admin, UltraTax CS — are the modern IOLTA for CPA firms.

Download the Full Threat Brief — Free
July 2026 CoreRecon Intelligence Report V43 IRS Pub 4557 + FTC §314 + TDPSA + PCAOB 62+ Verified Sources
800K
Landmark Admin
TX TPA records
2024 ransomware
207d
Median dwell time
accounting & FS
IBM X-Force 2024
$300K
Avg. BEC wire loss
per CPA firm incident
FBI IC3 2024
14
IRS Pub 4557 WISP
elements required
every PTIN holder
30min
CoreRecon IR SLA
TX-resident SOC
SDVOSB certified
What This Brief Covers

TX Accounting & CPA Firms
Cyber Threat Brief

Full intelligence report on the attack surface facing Texas CPA firms and accounting practices — from the Landmark Admin TX TPA breach (800K records) and the confirmed Whitley Penn + Lane Gorman Trubitt ransomware cases, to the IRS Pub 4557 WISP requirement, FTC Safeguards Rule 2023 amendment, TDPSA sensitive-data scope, and PCAOB AS 1000/QC 1000/AS 1215 audit-client flow-down. Coverage built for managing partners, firm administrators, IT directors, and compliance officers in CPA practices with 10–100 endpoints.

62+ Verified Sources Including:

  • Landmark Admin TX TPA (2024) — 800,000+ claimant records, ransomware, exfiltrated before encrypt
  • Whitley Penn (Oct 2023) — Top-20 TX CPA, ransomware, IRS Office of Safeguards coordination
  • Lane Gorman Trubitt (Dallas, Jan 2024) — 80-year firm, practice management + tax-prep encrypted, client return data exfiltrated
  • BST & Co. (CPAs touching PHI) — illustrative OCR exposure pathway, $28K HHS OCR settlement
  • IRS Pub 4557 (Rev. 11-2021) — 14 mandatory WISP elements for every PTIN holder
  • FTC Safeguards Rule 2023 (16 CFR §314) — Qualified Individual, MFA, encryption, 30-day breach reporting
  • TDPSA §541 — Texas taxpayer data as "sensitive data," 30-day AG notification, $7,500/violation civil penalty
  • PCAOB AS 1000 / QC 1000 / AS 1215 — auditor workpaper integrity for firms with PCAOB audit clients
  • Top 5 attack vectors: BEC during tax season, tax-software ransomware, credential theft, ProSeries/UltraTax/Lacerte supply chain, insider risk
  • 30/60/90-day hardening checklist with IRS Pub 4557 + FTC §314 + TDPSA + PCAOB control mapping
  • CoreRecon Sentinel / Fortress / Command tier fit for 10–100 endpoint CPA firms

Access the Full Brief

We email it as a PDF attachment. No newsletter. No spam. One delivery.

Submission failed — please try again or email john@corerecon.com

Brief Sent.

Check your inbox — the PDF is on its way. If it lands in spam, drag it to your inbox so you find it later.

Want it immediately? Download below — we already emailed a copy.

Download PDF Now → Book Free Assessment →

Questions before then? Call (800) 955-2596 — live TX SOC, not a call center.

SDVOSB Certified • TX-Based SOC • No offshore data routing
Questions? (800) 955-2596
✅ 62+ verified sources
✅ IRS Pub 4557 + FTC §314 + TDPSA + PCAOB covered
✅ 8-section 30/60/90 checklist
✅ TX-specific incidents: Landmark Admin, Whitley Penn, Lane Gorman Trubitt
✅ One email delivery, one PDF