Business email compromise doesn’t succeed at CPA firms because staff are careless — it succeeds because the fraudulent email looks exactly like the hundreds of legitimate ones that come through every tax season.
It is 4:45 on a Thursday afternoon.
Tax season is close.
Everyone in the office is already stretched thin.
An email arrives from a client the firm has worked with for six years.
The subject line references an actual, real engagement.
The tone sounds exactly like him.
He explains that his bank account changed recently.
He needs this year’s refund, once processed, sent to the new account instead.
He apologizes for the late notice.
He asks if it’s too much trouble to update it today, since he’s traveling tomorrow.
Nothing about the email feels unusual.
It reads like every other email this client has ever sent.
The staff member updates the account information.
She replies to confirm.
She moves on to the next task in a very long day.
Two weeks later, the real client calls, confused about a refund he never received.
Nobody in the office sent anything fraudulent.
Nobody clicked a suspicious link.
Nobody ignored an obvious red flag.
The email simply looked exactly like it was supposed to.
That is the entire problem.
The New Face of Fraud Doesn’t Look Like Fraud
Most people still picture cybercrime as something obviously suspicious.
Poor grammar.
A strange foreign sender address.
A link to an unfamiliar website.
An urgent demand for gift cards.
Those attacks still happen.
But the attacks costing CPA firms real money increasingly look nothing like that.
They look like a normal client.
A normal vendor.
A normal partner asking a normal question at a normal time of year.
The FBI’s Internet Crime Complaint Center has tracked business email compromise as one of the most financially damaging categories of cybercrime reported to it, with billions of dollars in losses linked to it since it began tracking the category. These schemes work precisely because they exploit trust and routine business communication rather than technical vulnerabilities.
An accounting firm is an especially attractive target.
CPA firms move money.
They handle refunds.
They manage sensitive financial documents.
They communicate constantly about deadlines, wire instructions and account details.
An attacker who can insert themselves convincingly into that flow of communication does not need to break into a server.
They only need one email to be believed.
Why CPA Firms Specifically Attract This Kind of Attack
Consider what a typical accounting practice deals with every single day.
Client tax documents containing Social Security numbers.
Bank account and routing numbers.
Refund information.
Payroll data.
W2 and 1099 forms.
Wire transfer instructions.
Retirement account details.
Business financial statements.
Merger and acquisition documents for business clients.
Trust and estate information.
To a criminal, that is an extraordinarily valuable stream of information and financial activity to infiltrate.
The IRS has repeatedly warned tax professionals that they are specifically targeted by identity thieves precisely because of the sensitive data concentrated in their systems. The IRS’s ongoing guidance to tax and accounting professionals emphasizes that safeguarding client data is not optional protection against a generic threat. It is protection against attackers who are actively and specifically targeting the profession.
That distinction matters.
This is not “cybersecurity in general.”
This is an attack pattern built around exactly what a CPA firm does all day.
How the Email Ends Up Looking So Real
There are several ways an attacker can make a fraudulent email nearly indistinguishable from a legitimate one.
Sometimes the client’s own email account has been compromised.
The attacker is not impersonating the client from an outside address.
They are using the client’s real account, reading real prior conversations and replying inside a real email thread.
Sometimes the attacker registers a look-alike domain.
A single character changed.
A letter swapped for a similar looking one.
An extra letter added.
At a glance, in a busy inbox, it looks correct.
Sometimes the attacker has been quietly monitoring a mailbox for weeks, learning the client’s tone, the accountant’s name, ongoing projects and typical phrasing before ever sending a fraudulent message.
This is sometimes described as a “man in the middle” of a business relationship rather than a man in the middle of a network.
The attacker is not intercepting data in transit.
They are inserting themselves into an ongoing trusted conversation.
CISA’s guidance on phishing and business email compromise describes exactly this pattern: attackers frequently study real communications and impersonate trusted contacts rather than relying on obviously fake messages.
Tax Season Makes Everything Worse
Attackers understand deadlines as well as accountants do.
During tax season, staff are moving faster.
Inboxes are fuller.
Requests feel routine because so many similar requests are actually happening.
“Please update my bank information for the refund.”
“Please resend my W2, I can’t find the copy you sent.”
“Please confirm the wiring instructions for this transaction.”
All of those requests happen constantly and legitimately during a normal season.
That is exactly why a fraudulent version blends in so easily.
The IRS has specifically warned tax professionals about phishing campaigns that spike around filing deadlines, often impersonating the IRS itself, tax software providers or clients directly.
A message that would seem slightly unusual in July can seem completely ordinary in March.
Attackers know this.
They plan around it.
What a Well-Trained Employee Still Cannot See
This is the part that is difficult for many firm owners to accept.
A hardworking, careful, well-trained employee can still fall for a well-executed business email compromise attempt.
That is not a failure of diligence.
It is the nature of the attack.
The email arrives from a familiar address.
It references a real client, a real engagement or a real ongoing conversation.
It uses a normal tone.
It asks for something routine, just with new account details.
Nothing about the message triggers the instinctive alarm that a stereotypical scam email would.
This is why relying entirely on “staff will notice something is wrong” is not a complete security strategy.
The message is specifically designed not to look wrong.
Verification Has to Happen Outside the Email Itself
This is the single most important defense against this type of fraud, and it does not require complicated technology.
If a client asks to change banking information, confirm it through a separate communication channel.
Call the client using a phone number already on file, not a number provided in the email.
Do not call a number that appears in the suspicious message itself.
Ask a verbal question only the real client would know the answer to, if there is any doubt.
Treat any request involving changed payment details, wiring instructions or sensitive account information as something that requires a live conversation before action, no matter how convincing the written message appears.
CISA’s guidance on business email compromise specifically recommends verifying payment or account changes through an independently confirmed phone number rather than relying on email alone, precisely because the email channel itself may already be compromised.
This single habit, applied consistently, stops the overwhelming majority of successful business email compromise attempts before any money moves.
The IRS “Security Six” and Why It Exists
The IRS has published specific recommendations for tax professionals aimed directly at this category of risk, often referred to as the Security Six.
These recommendations include using antivirus software, firewalls, multifactor authentication, encrypted drives, secure backups and virtual private networks as part of an everyday practice environment.
Multifactor authentication deserves particular attention here.
If an attacker manages to steal an employee’s email password through a separate phishing attempt, multifactor authentication can prevent that stolen password from actually granting access to the mailbox.
That single control can be the difference between a close call and a serious compromise.
CISA similarly recommends multifactor authentication as one of the most effective and immediately available protections against account takeover, particularly phishing resistant methods where practical.
Email Authentication Technology Matters More Than Most Firms Realize
Beyond staff training, there are technical protections that reduce how easily an attacker can impersonate a domain in the first place.
Email authentication standards such as SPF, DKIM and DMARC help receiving mail servers verify whether a message actually originated from where it claims to originate.
Properly configured, these standards make it significantly harder for an attacker to send a message that appears to come directly from a real domain the firm or its clients use.
Many small and mid-sized firms have never had these settings properly configured, often because nobody outside of a specialized IT provider thought to check.
This is exactly the kind of protective measure that operates silently in the background, similar to network segmentation or backup testing.
Nobody notices it working.
Everybody would notice if it were missing during an actual attack.
The Wire Transfer Request That Almost Always Works
Of all the business email compromise scenarios accounting firms encounter, one pattern shows up again and again: the urgent wire transfer request.
It usually arrives claiming to be from a partner, a senior manager or a trusted client who is “unavailable by phone right now.”
The message emphasizes urgency.
A deadline that cannot wait.
A deal that will fall through without immediate action.
A traveling executive who can only communicate by email for the next few hours.
The request is specific enough to sound legitimate and vague enough to avoid raising immediate questions.
“Please process this wire today, I’ll explain the details when I’m back online.”
Employees who are asked to move quickly, without the ability to confirm details verbally, are placed in an extremely difficult position.
Refusing feels risky if the request turns out to be legitimate and time-sensitive.
Complying feels routine if nothing about the message seems obviously wrong.
That tension is exactly what the attacker is counting on.
A firm-wide policy that simply states “wire transfers and payment changes always require verbal confirmation, no exceptions, regardless of urgency” removes that tension entirely from the employee’s shoulders.
The policy does the hard work.
The employee simply follows it.
Why Attackers Often Study Their Targets First
Business email compromise attempts are rarely random.
Attackers frequently spend time researching a firm and its clients before ever sending a fraudulent message.
Publicly available information such as staff names, titles, client relationships mentioned in press releases, and even out-of-office replies can all provide useful details.
An out-of-office message stating that a partner is traveling internationally for two weeks and referring inquiries to someone else is genuinely helpful to clients.
It is also genuinely helpful to an attacker planning the timing of a fraudulent request.
This does not mean a firm should never use out-of-office replies or maintain a professional online presence.
It means staff should understand that seemingly harmless details can be pieced together into a convincing pretext, and that awareness should factor into how verification policies are designed and enforced.
It is worth being direct about the consequences, because they extend well beyond a single financial loss.
Funds sent to a fraudulent account are frequently unrecoverable, particularly once they move through multiple accounts or across borders.
The firm may face a difficult conversation with the actual client, who is understandably upset that funds intended for them were redirected.
Depending on the circumstances, the firm may face liability questions about whether reasonable safeguards were in place.
Client trust, once shaken, is not easily repaired.
Other clients may hear about the incident.
Staff morale can suffer, particularly for the employee directly involved, even though the fault rarely lies with them personally.
None of this requires a large firm or a dramatic breach.
It only requires one convincing email and one moment of routine trust.
A Practical Response Checklist If You Suspect Compromise
If a fraudulent transaction is suspected, speed matters immensely.
Contact your financial institution immediately and request a recall or reversal of the transaction.
File a complaint with the FBI’s Internet Crime Complaint Center as soon as possible, since early reporting meaningfully improves the odds of fund recovery in some cases.
Notify affected clients directly and transparently.
Preserve the fraudulent email and any related communications rather than deleting them.
Change passwords and review account activity for any mailbox that may have been involved.
Consult with your IT provider and, where appropriate, legal counsel regarding notification obligations.
Review how the fraudulent request was received and identify what verification step, if implemented, would have caught it.
That final step matters most for prevention going forward.
Training Has to Be Specific, Not Generic
Generic phishing training slideshows delivered once a year rarely change behavior in a meaningful way.
Effective training for accounting firms should focus specifically on the scenarios employees are most likely to actually encounter.
A “client” requesting a last-minute change to refund banking details.
A “partner” urgently requesting a wire transfer while claiming to be unreachable by phone.
An email referencing a real, specific ongoing engagement in convincing detail.
A message that creates time pressure, discouraging the recipient from pausing to verify.
Training should walk through real, anonymized examples of what these attempts look like, not just abstract warnings about “phishing.”
It should be reinforced multiple times per year, with particular attention before and during tax season, when volume and urgency both increase simultaneously.
What a Mature Email Security Posture Actually Looks Like
A resilient CPA firm does not rely on any single defense.
It layers several together.
Multifactor authentication on every account, particularly email.
Properly configured email authentication standards to reduce domain spoofing.
Email filtering and threat detection tuned for business email compromise patterns, not just obvious spam.
A firm-wide policy requiring independent verification for any change to payment or banking details.
Ongoing, scenario-specific staff training.
A clear, documented incident response process if a suspicious or fraudulent request is identified.
None of these measures alone guarantees safety.
Together, they dramatically reduce both the likelihood of a successful attack and the damage if one still occurs.
Ask Your IT Provider These Questions
Do we have multifactor authentication enabled on every email account, without exception?
Are our email authentication settings such as SPF, DKIM and DMARC properly configured?
Does our email filtering specifically address business email compromise patterns, not just generic spam?
Do we have a documented policy requiring independent verification of any banking or payment detail change?
When did our staff last receive training on realistic, current business email compromise scenarios?
If a fraudulent wire request were sent tomorrow, would every employee know exactly what to do?
If your IT provider cannot answer these clearly, it may be worth finding out why.
Trust Is Necessary. Blind Trust in Email Is Not
None of this is about training staff to distrust every client or every message.
Accounting firms are built on relationships, responsiveness and trust.
The goal is not suspicion of every email.
The goal is recognizing that certain categories of requests, specifically those involving money movement or account changes, deserve a brief, independent verification step regardless of how convincing the message appears.
That single habit, supported by reasonable technical safeguards, closes the gap that business email compromise is specifically designed to exploit.
ITva Technologies provides managed IT and cybersecurity services for CPA and accounting firms across Miami-Dade and Broward, with a focus on email security, multifactor authentication, phishing-resistant configurations and the realities of a profession that attackers specifically target.
Our managed IT services help firms configure and maintain the technical safeguards that make domain spoofing and account takeover significantly harder to pull off.
Our cybersecurity services layer email threat detection, multifactor authentication and ongoing monitoring around the accounts your firm depends on every day.
If your firm has never specifically reviewed its email security posture against business email compromise, that is worth doing before the next convincing email arrives, not after.
Schedule a free email security and cybersecurity assessment with ITva.
We will review your current email authentication settings, multifactor authentication coverage, filtering configuration and staff readiness, then show you where risk may exist.
Because the email that costs a firm the most is never the one that looks fake.
It is the one that looks exactly right.
Frequently Asked Questions
What is business email compromise, in simple terms?
Business email compromise is a type of fraud in which an attacker impersonates a trusted contact, such as a client, vendor or colleague, often through a compromised account or a look-alike domain, in order to convince someone to send money or sensitive information to the wrong destination.
Why are CPA firms specifically targeted?
CPA firms handle sensitive financial data, tax documents, banking information and frequent money movement as part of normal operations. That combination makes them an attractive target for attackers seeking either financial gain or valuable personal information.
Can multifactor authentication really prevent this kind of attack?
Multifactor authentication cannot prevent every scenario, but it significantly reduces the risk that a stolen password alone will grant an attacker access to an email account, which is a common precursor to business email compromise schemes.
What is the single most effective defense against this type of fraud?
Independently verifying any request involving changed banking details or payment instructions, through a phone number already on file rather than one provided in the suspicious message, stops the majority of these schemes before funds are lost.
Is it possible to recover money sent to a fraudulent account?
Sometimes, particularly if the transaction is reported quickly to the financial institution and to the FBI’s Internet Crime Complaint Center. Recovery becomes significantly less likely the longer the delay before reporting.
Do email authentication settings like SPF, DKIM and DMARC actually help?
Yes. Properly configured, these standards make it considerably harder for an attacker to send email that appears to originate from a legitimate domain, reducing one of the common techniques used in business email compromise and phishing attacks.