Too Small to Be a Target? Why Small Accounting Firms Are Easy Marks for Cybercriminals

Technology | October 5, 2026

Too Small to Be a Target? Why Small Accounting Firms Are Easy Marks for Cybercriminals

A small practice can hold enough client data to fuel hundreds of identity theft cases. Here's how firm leaders can close the gaps attackers count on.

Scott Carr

Many accounting firm owners believe cybercriminals go after large firms, banks, and corporations, not a five-person practice with a server in the back office. It’s an understandable belief. It’s also one of the easiest ways to get breached.

Attackers don’t pick targets the way a business development team picks prospects. Most attacks start with automated tools that scan the internet around the clock for weak passwords, exposed remote access, and unpatched systems. Those tools don’t look up a firm’s revenue or headcount. They look for an open door. In my work monitoring client networks, automated login attempts and scans show up every day against small offices, not just large ones.

Small firms also tend to have fewer defenses, which makes them easier to break into. Verizon’s 2025 Data Breach Investigations Report found ransomware in 88% of breaches at small and midsized businesses, compared with 39% at large organizations.

Small firm, large data set

A firm’s size says little about the value of its data. Even a small practice holds Social Security numbers, employer identification numbers, bank account and routing details, W-2s, and complete returns for hundreds of individuals and businesses. To a criminal, that’s an identity theft kit for every client on the list, plus the information needed to file fraudulent returns and redirect refunds.

The IRS has warned for years that sole practitioners are just as vulnerable to data theft as large firms. Attackers also go after firm credentials, including Electronic Filing Identification Numbers and Preparer Tax Identification Numbers, so they can file fraudulent returns that appear to come from a legitimate preparer.

When a firm is breached, the impact reaches its clients. They may face fraudulent filings, delayed refunds, drained accounts, and years of identity monitoring.

The compliance picture

Tax and accounting firms are financial institutions under the FTC Safeguards Rule. The rule requires a written information security plan (WISP), a qualified individual overseeing the security program, multifactor authentication for anyone accessing customer information, and encryption of that information. Firms must also notify the FTC within 30 days of discovering a breach involving unencrypted information on 500 or more consumers.

Recommended Articles

None of these obligations shrink for smaller firms.

A hypothetical scenario

Consider a fictional four-person firm in mid-March. A staff accountant clicks what looks like a client’s document upload link, and it captures her email password. The firm hasn’t turned on multifactor authentication. Over the next week, the attacker quietly downloads saved returns and then emails several clients asking them to “confirm” bank details for direct deposit.

The firm now has to notify clients, report to the IRS and the FTC, and rebuild trust during its busiest season. No advanced hacking was needed. The door was simply unlocked.

Practical steps for firm leaders and IT

  1. Turn on multifactor authentication for email, tax software, client portals, and remote access. The FTC Safeguards Rule requires it, and it stops most password-based attacks.
  2. Write or update your WISP and name the person responsible for it. IRS Publication 5708 offers a template for small practices.
  3. Move document exchange to a secure client portal and stop accepting tax documents by email.
  4. Encrypt client data on laptops, servers, and backups.
  5. Keep backups with at least one offline or immutable copy, and test a full restore before tax season.
  6. Monitor systems around the clock so suspicious logins are caught quickly, including nights and weekends during busy season.
  7. Train staff to recognize phishing that imitates clients, the IRS, and software vendors, and require a phone call before acting on any request to change payment details.
  8. Document your reporting steps in advance, including your IRS Stakeholder Liaison, state authorities, the FTC, and your cyber insurer.

Questions your clients may ask

Clients are increasingly aware of data theft risks. Firms that answer these questions clearly build confidence.

Q: How do you protect my tax information?
A: Explain your WISP, encryption, multifactor authentication, and secure portal in plain terms.

Q: Why can’t I just email my documents?
A: Standard email isn’t a secure way to send Social Security numbers and financial records. A portal protects the client as much as the firm.

Q: How do I know an email from your firm is legitimate?
A: Tell clients you’ll never request bank account changes by email, and encourage them to call a known number to confirm any unusual request.

Q: What happens if your firm is breached?
A: Clients want to hear that you have a response plan, will notify them promptly, and know what steps to take to limit the damage.

Size is not a security strategy

Being small doesn’t make an accounting firm invisible. It often makes a firm easier to breach. The good news is that the controls that matter most are practical and affordable for firms of any size. Firms that put them in place protect their clients, meet their regulatory obligations, and avoid finding out the hard way that they were never too small to be a target.

ABOUT THE AUTHOR:

Scott Carr, owner of Farmhouse Networking in Grants Pass, Oregon, is a veteran Network & Computer Systems Architect with over 30 years of IT experience. For over a decade, he’s led his team in delivering proactive, secure, and fully managed IT services to more than 80 businesses—including accounting and finance firms that rely on data security, compliance, and efficiency. Scott’s hands-on, jargon-free approach ensures every client understands their technology and gains confidence in their systems. His firm is known for fast, responsive support—most issues are resolved within 15 minutes—and deep expertise in cybersecurity, network design, and IT compliance. Learn more about how Farmhouse Networking supports the accounting industry at https://www.farmhousenetworking.com/finance-it-support/.

Photo credit: FotoRichter/Pixabay

Sign in to get access to this free resource, and all of our whitepapers and reports.

Download this content today!

Register to get free access to this content, as well as newsletters, continuing education, podcasts, and more…

Leave a Reply

Scott Carr

Scott Carr

Scott Carr, owner of Farmhouse Networking in Grants Pass, Oregon, is a veteran Network & Computer Systems Architect with over 30 years of IT experience. For over a decade, he’s led his team in delivering proactive, secure, and fully managed IT services to more than 80 businesses—including accounting and finance firms that rely on data security, compliance, and efficiency. Scott’s hands on, jargon free approach ensures every client understands their technology and gains confidence in their systems. His firm is known for fast, responsive support—most issues are resolved within 15 minutes—and deep expertise in cybersecurity, network design, and IT compliance. Learn more about how Farmhouse Networking supports the accounting industry at https://www.farmhousenetworking.com/finance-it-support/.