Accounting and tax practices
Tax season phishing: what accounting firms should watch for
· PS ProTech
Attackers know the tax calendar as well as you do. In the weeks before filing deadlines, your staff are tired, inboxes are full and every message looks urgent. That is when phishing works best.
Here are the patterns aimed at tax and accounting practices, and what stops them.
The emails to expect
The new client. Someone asks whether you are taking new clients. After a friendly exchange they send their "prior-year documents" as a link or attachment, which installs malware or asks for your email password.
The software vendor. A message that appears to come from your tax software provider says your account needs to be verified or updated before you can e-file. The link leads to a copy of the login page.
The IRS. A notice about your e-Services account, EFIN or PTIN, asking you to sign in or send documents. The IRS does not start contact with preparers by email to ask for credentials.
The existing client. A real client's mailbox has been compromised, and the attacker replies within a genuine conversation asking you to change the bank account for their refund.
The partner. A message that appears to come from a firm partner asks a staff member for client W-2s or for an urgent payment.
What the attacker wants
Usually one of three things: your credentials for tax software and email, the client data needed to file fraudulent returns, or a redirected payment. A practice's stolen EFIN and client files let criminals file returns that look legitimate.
Defenses that work
Multi-factor authentication everywhere. On email, tax software and client portals. A stolen password alone is then not enough.
Email filtering. Good filtering removes most impersonation attempts before anyone sees them.
A verification rule for bank changes. Any change to a refund or payment account is confirmed by phone using a number already on file, never one from the email.
A secure portal for documents. If clients always send documents through your portal, an emailed attachment is immediately suspicious.
Endpoint protection on every machine. Including the laptops of seasonal staff and anything used at home.
A two-minute briefing before the season. Show staff the five patterns above and tell them who to forward a suspicious message to. Make reporting easy and blame-free.
If someone clicks
Speed matters more than fault. Disconnect the machine from the network, change the affected passwords from a different device and call your IT provider. If client data may have been exposed, you may have reporting obligations, including to the IRS; get advice promptly.
All of these defenses are included in our Business and Secure plans.
