Free Resource · guide

How Do Accounting Firms Stop Wire Fraud and Business Email Compromise?

The control that actually stops the wire is a procedure, not a product: verify every payment instruction, banking change, or disbursement request by calling a number you already have on file, never one from the email that asked. Around that procedure you layer MFA on every account, SPF, DKIM, and DMARC enforcement, advanced filtering, mailbox rule monitoring, and training for the people who touch money. Accounting firms are prime targets because they sit directly in the flow of client funds, and clients act on email from their CPA without a second thought.

Wire fraud against accounting firms rarely looks like a hack. It looks like a normal Tuesday. A long-time client emails asking that a disbursement go to a different account, the message sits in a real thread with real history, and someone on your team makes the change. Or it runs the other direction: an attacker gets into one of your firm’s mailboxes and starts emailing your clients, and because the message genuinely comes from their CPA, they comply. Business email compromise is consistently among the most expensive crime categories the FBI’s Internet Crime Complaint Center tracks, and firms that sit in the flow of client money are exactly who it targets.

Here is why accounting practices draw this attack, the specific plays to expect, the layered defense that works, and what to do in the first hour if money has already moved.

Why are accounting firms such attractive BEC targets?

  • You sit in the money flow. Firms initiate, approve, or instruct disbursements, refunds, estimated payments, and trust transfers. An attacker who can insert one instruction into that flow gets paid without touching a single system.
  • Your email carries borrowed trust. Clients act on messages from their CPA. A compromised firm mailbox is not one victim, it is a launch platform aimed at every client in your book, and the reputational damage lands on you even though the client took the loss.
  • Deadline pressure is built into the calendar. Filing deadlines, extension dates, and quarterly estimates create windows where everyone is moving fast and unusual requests feel normal. Attackers know the tax calendar as well as you do.
  • The data itself is money. Even when no wire moves, the SSNs, W-2s, and financial records a firm holds convert directly into fraudulent refund filings and identity theft.

What do the common attacks actually look like?

Four plays account for most of what firms see. These are the generic industry patterns, not any specific client’s story:

  1. The spoofed or compromised client. An email arrives from a client, or from a lookalike domain one character off, asking that an upcoming disbursement, refund, or payment go to new banking details. The thread history is real or convincingly cloned, the timing lines up with a payment the attacker learned about by reading mail, and the only thing wrong is the account number.
  2. The compromised firm mailbox. An attacker phishes or password-sprays into a staff or partner account, reads quietly for weeks, then emails clients with “updated remittance instructions” or a link to a fake portal that harvests their credentials. They typically plant a hidden inbox rule that forwards or deletes replies so the real owner never sees the responses.
  3. Fake IRS and e-file notices. Messages dressed as IRS correspondence, e-file rejections, or EFIN verification requests, aimed at harvesting credentials or planting malware. The IRS initiates contact by mail, not email, but during filing season a rejection notice gets clicked before it gets questioned.
  4. W-2 and tax data theft requests. An email impersonating an executive at a business client, or a partner at your own firm, asks for all employee W-2s or a batch of client tax records. No money moves in this play. The data is the payout.

Notice what these have in common: at the moment of loss, nothing technical fails. The mail is often genuinely from the account it claims. That is why the core defense is procedural.

What is the one procedure that stops the wire?

Verify every payment instruction, disbursement change, banking update, or bulk data request by calling a phone number you already had on file, never a number, link, or contact from the message that made the request.

That single rule defeats the attack even when the sender’s mailbox is fully compromised, because the attacker controls the email channel but not your existing phone records. Replying to the email accomplishes nothing, the attacker answers your reply.

To make it hold up in a real busy season:

  • Write it down as firm policy, have the partners sign it, and apply it with no urgency exceptions. Urgency is the tell, not a reason to skip the call.
  • Build a known-good contact list for every client and vendor at onboarding, before any change request ever arrives.
  • Require a second approver for disbursements above a threshold you choose, so two people have to be fooled instead of one.
  • Tell clients up front, in the engagement letter or onboarding packet, that you will never change banking details on email alone and will always call. It protects both sides and makes the call expected rather than awkward.
  • Treat bulk data requests, W-2s, client records, exactly like money. Verify by phone before anything leaves the firm.

What technical controls back the procedure up?

The procedure stops the loss. The technical layer makes the attack harder to launch and easier to catch early:

  • MFA on every account, no exceptions. Most BEC starts with a compromised mailbox, and MFA blocks the bulk of account takeover attempts. Cover email, remote access, tax software portals, and admin accounts, and prefer app-based methods over SMS.
  • SPF, DKIM, and DMARC at enforcement. These let receiving mail systems reject messages that fake your domain, which protects your clients from attackers impersonating your firm. Many firms have SPF alone and assume they are covered. DMARC needs to be at an enforcement policy, not just monitoring.
  • Advanced email filtering. Beyond spam, modern filtering flags lookalike domains one character off from clients you actually correspond with, tags external mail visibly, and detects credential-harvest links behind IRS-themed lures.
  • Mailbox rule and forwarding alerts. Attackers who get into a mailbox almost always create hiding rules or external auto-forwards to cover their tracks. Alerting the moment a new rule or forward appears catches an intrusion in the watching phase, before any client gets emailed and before any money moves.
  • Conditional access. For a Texas firm, a successful login from overseas should never be silent. Blocking sign-ins from countries you do not operate in and requiring compliant devices closes off most credential-stuffing wins.
  • Awareness training aimed at the people who touch money and data. Generic phishing training helps, but the staff who process disbursements and the admins who can export client records need scenario training on these exact plays, including simulated banking-change and W-2 requests.
  • A written incident response plan. Who calls the bank, who files with the FBI, who notifies clients, decided before the bad day, not during it.

These controls are configuration and monitoring work inside Microsoft 365, the kind of hardening we do as part of our cybersecurity services when we take on a new firm.

How does this connect to the FTC Safeguards Rule?

Directly. The Safeguards Rule requires firms handling customer financial information to run a documented security program, and the elements it names, access controls, MFA, encryption, monitoring, risk assessment, awareness training, incident response, a designated person accountable for the program, are the same controls listed above. Building your BEC defense is not a project competing with compliance. It is the compliance work, and the documentation you produce for one serves the other. Our guide to the FTC Safeguards Rule for CPA firms walks the full requirement list, and IRS Publication 4557 points tax professionals at the same set of controls.

What should you do in the first hour if money already moved?

Speed is the only variable you still control. In order:

  1. Call the sending bank’s fraud department immediately. Request a recall of the wire and a freeze, and ask them to contact the beneficiary bank. Funds often sit briefly in the first account before hopping onward.
  2. File at ic3.gov right away. The FBI’s Internet Crime Complaint Center runs a recovery process for recently wired funds, and it works best within the first hours and days. Do not wait for internal investigation to finish before filing.
  3. Preserve everything. Original emails with full headers, the fraudulent instructions, call logs. Nobody deletes or cleans up anything.
  4. Assume the involved mailbox is still compromised. Reset the password, revoke active sessions, and check for hidden inbox rules and forwarding before sending a single email about the incident. The attacker may be reading in real time.
  5. Notify affected clients by phone. If a firm mailbox was compromised, clients may be receiving fraudulent instructions from your domain right now, and a fast honest call protects them and the relationship. Then notify your cyber insurance carrier, and expect the carrier to ask whether your verification procedure was followed.

Who handles this for accounting firms in Houston and DFW?

Braintek has supported Texas businesses since 2002, with staff in Houston, DFW, and the Philippines, and BEC hardening is one of the first things we put in place for CPA firms and financial advisors: the Microsoft 365 controls above, the mailbox monitoring, and the written verification policy modeled on the one we run internally for our own wires. Fully managed support fits firms of roughly 10 to 50 employees, and co-managed arrangements cover larger practices up to around 1,500. When something looks off, a suspicious banking-change email is exactly the kind of call our team typically answers in about 60 seconds, and emailed tickets typically get a response within about 2 hours.

For the rest of the picture, see how the same controls map to Safeguards Rule compliance, how to get your systems ready before the crunch in our tax season IT readiness guide, and, if you want to see the identical scam through another industry’s eyes, the construction payment diversion playbook covers the same attack against progress payments.

Would a swapped account number get past your firm today?

Tell us how disbursement requests and banking changes move through your practice. We'll trace the path an attacker would take, show where a fraudulent request would slip through, and lay out the verification policy and email controls that close the gap, controls that also count toward your FTC Safeguards program.

By submitting, you agree to be contacted by Braintek about your inquiry.

FAQs

What is business email compromise for an accounting firm, in plain terms?

An attacker either breaks into a real mailbox, yours or a client's, or convincingly imitates one, watches how money and documents move, then sends a request that looks routine: a client asking to redirect a disbursement, a partner approving a wire, an IRS notice with a link. Nothing fails technically at the moment of loss. Someone is simply persuaded to send real money or real data to the wrong place.

Why are CPA firms targeted more than other small businesses?

Three reasons. You sit in the money flow, so a single fraudulent instruction can move client funds. Your email carries unusual authority, because clients act on a message from their CPA without questioning it. And your busy season runs on deadline pressure, which is exactly the condition these scams exploit. On top of that, one compromised firm mailbox opens a door to every client in your book.

Is replying to the email to confirm a banking change good enough?

No. If the sender's mailbox is compromised, the attacker receives your reply and politely confirms their own fraudulent account. Verification only counts when it leaves the email channel entirely: a phone call to a number you had on file before the request arrived.

We already have spam filtering. Doesn't that cover BEC?

Filtering catches bulk phishing, but a BEC message often comes from a real, compromised account belonging to an actual client or vendor. It passes SPF, DKIM, and every other technical check because it is technically legitimate mail. Filtering is one layer. The callback procedure is the one that stops the loss.

What should we do in the first hour if money already moved?

Call the sending bank's fraud department and request a wire recall and freeze, then ask them to contact the receiving bank. File at ic3.gov, the FBI's Internet Crime Complaint Center, immediately, since their recovery process works best in the first hours. Preserve the original emails with full headers, assume the involved mailbox is still compromised, and reset credentials and check for hidden rules before emailing anything about the incident.

Do these controls count toward FTC Safeguards Rule compliance?

Yes. MFA, access controls, monitoring, awareness training, and a written incident response plan are required elements of the information security program the Safeguards Rule mandates for firms handling customer financial information. Building your BEC defense builds your compliance program at the same time, and the same documentation serves both.

What is a W-2 or tax data theft request, and why does it matter?

Attackers impersonate an executive or a client and ask a firm to send employee W-2s or tax records, usually during filing season when such requests seem normal. The stolen data feeds fraudulent refund filings and identity theft. Treat any bulk data request the same way you treat a banking change: verify by phone on a known number before anything leaves the firm.

Ready for IT that just works?

Book a no-pressure discovery call. We'll review your setup and show you exactly where you stand.