It Happened Again—and It Could Happen to You
Another CPA firm got hit with ransomware. The attackers encrypted every file on the firm’s network—client tax returns, financial statements, engagement letters, internal documents—all locked behind a ransom demand. Staff arrived Monday morning to screens displaying a ransom note demanding payment in cryptocurrency. No one could access anything.
This is not a hypothetical scenario. Ransomware attacks on accounting firms have been increasing steadily, and the attackers are getting more sophisticated. CPA firms are attractive targets because they hold exactly the kind of sensitive data—Social Security numbers, financial records, bank account details—that commands premium prices on dark web marketplaces. And many firms, particularly small and mid-size practices, have security gaps that make them easier to compromise than larger organizations.
For Arizona businesses, from CPA firms in Phoenix to small practices in Tucson and the East Valley, the lessons from these attacks apply broadly. Here is what happened, how it got in, and the five things that would have prevented it.
How Ransomware Gets Into a CPA Firm
Understanding how attacks succeed is the first step toward preventing them. The most common entry points for ransomware targeting accounting firms are remarkably consistent.
Phishing Emails
The majority of ransomware attacks begin with a phishing email. An employee receives a message that appears to come from a client, a software vendor, the IRS, or a colleague. The email contains either a malicious attachment or a link to a compromised website. One click, and the attacker has a foothold in the network.
CPA firms are especially vulnerable to phishing because they receive large volumes of email from clients and third parties, often with attachments. During tax season, when staff are processing hundreds of documents daily, the likelihood of someone clicking on a malicious attachment increases dramatically.
The phishing emails targeting accounting firms have become highly targeted. Attackers research the firm, identify key staff members, and craft messages that reference real clients, real software platforms, or real tax deadlines. These are not generic spam messages—they are professionally written and carefully designed to bypass suspicion.
Compromised Remote Access
Remote Desktop Protocol (RDP) and other remote access tools remain a major attack vector. Many firms set up remote access during the pandemic and never properly secured it. Exposed RDP ports, weak passwords, and missing multi-factor authentication give attackers a direct path into the network.
Attackers use automated scanning tools to identify systems with open RDP ports, then use brute-force techniques or stolen credentials to log in. Once inside, they move through the network, escalate privileges, and deploy ransomware—often weeks after the initial compromise, during which they have mapped the network and identified the most valuable data.
Software Vulnerabilities
Unpatched software—operating systems, applications, firewalls, and VPN appliances—creates openings that attackers exploit. Known vulnerabilities in widely used business software are cataloged and shared among cybercriminal groups. If your firm is running software with known vulnerabilities that have patches available but not applied, you are a target.
This is particularly relevant for Arizona firms using older server infrastructure. A firm that has delayed server upgrades or skipped security patches is carrying risk that compounds over time.
Third-Party Access
CPA firms work with numerous third-party vendors—tax software providers, cloud hosting services, document management platforms, payroll processors. Each of these relationships creates a potential entry point. If a vendor’s systems are compromised, the attackers may be able to pivot into your network through trusted connections.
What Happens After the Attack
The immediate aftermath of a ransomware attack on a CPA firm is chaos. Here is the typical sequence:
Day 1: Staff discover they cannot access files. The ransom note demands payment, usually in Bitcoin, with a deadline. The firm cannot process returns, respond to client requests, or access any electronic records. Phone lines light up with clients asking about the status of their work.
Days 2-3: The firm scrambles to determine the scope of the damage. Are backups available? Were they encrypted too? Can the firm restore from backup, or is payment the only option? Legal counsel is engaged. Insurance carriers are notified. Forensic investigators begin analyzing how the attackers got in.
Week 1: If backups are available and uncompromised, restoration begins. This is not a quick process—verifying that restored data is clean, rebuilding compromised systems, and ensuring the attackers do not still have access takes time. If backups are not available or were also encrypted, the firm faces an agonizing decision about whether to pay the ransom.
Weeks 2-4: The firm works to restore normal operations while managing client communication, regulatory notification requirements, and potential legal liability. The true cost of downtime extends far beyond the ransom amount—lost productivity, overtime labor, client attrition, and reputational damage can dwarf the ransom itself.
Months 1-6: Regulatory consequences unfold. The FTC may investigate under the Safeguards Rule. State attorneys general may get involved. Affected clients may file lawsuits. The firm’s insurance premiums increase. Some clients leave.
The Five Things That Would Have Prevented It
Here is the frustrating part: the controls that prevent ransomware are well-known, widely available, and not prohibitively expensive. Most successful ransomware attacks exploit the absence of basic protections that every firm should have in place.
1. Multi-Factor Authentication on Everything
Multi-factor authentication (MFA) is the single most effective control against unauthorized access. When MFA is enabled, stealing a password is not enough—the attacker also needs the second factor, typically a code from a mobile app or a hardware key.
MFA should be enabled on every system that supports it: email, remote access, cloud applications, tax software, banking portals, and administrative accounts. This one control blocks the vast majority of credential-based attacks, including brute-force RDP attacks and phishing campaigns that harvest passwords.
If your firm does not have MFA on email and remote access today, implementing it should be your top priority. Not next month. This week.
2. Immutable, Tested Backups
Backups are your last line of defense against ransomware. But not all backups are equal. Modern ransomware specifically targets backup systems—attackers look for backup servers, network-attached storage, and cloud backup repositories and attempt to encrypt or delete them before deploying the main ransomware payload.
Your backups need to be immutable, meaning they cannot be modified or deleted by anyone—including an attacker who has administrative access to your network. This typically requires a backup architecture where backup copies are stored in a separate environment with independent authentication, and where retention policies prevent deletion within a defined window.
Equally important: backups must be tested. A backup that has never been restored is a hope, not a plan. Test full restores at least quarterly, including restoring to clean hardware. Document the process and the time required, so you know your actual recovery time—not a theoretical one.
Our guide on disaster recovery planning covers how to build a backup and recovery strategy that actually works when you need it. And your backup infrastructure should be designed to survive the specific threats facing your firm.
3. Advanced Endpoint Protection
Traditional antivirus software uses signature-based detection—it identifies known malware by matching files against a database of known threats. This approach fails against new or modified malware, which is what modern ransomware attackers use.
Advanced endpoint protection uses behavioral analysis, machine learning, and automated response to detect and stop threats that signature-based tools miss. When a ransomware payload begins encrypting files, behavioral analysis can detect the unusual file access patterns and stop the process before significant damage occurs.
Beyond detection, application control capabilities prevent unauthorized executables from running on your workstations and servers. If ransomware cannot execute, it cannot encrypt. This zero-trust approach to application management is one of the most effective ransomware defenses available.
Every endpoint in your firm—workstations, laptops, servers, and remote devices—should be running advanced endpoint protection with automated response enabled.
4. Email Security and Phishing Protection
Since phishing is the most common ransomware delivery mechanism, email security is critical. Modern email security goes beyond spam filtering to include advanced threat detection: sandboxing attachments to test them for malicious behavior, analyzing URLs for known and unknown threats, and detecting impersonation attempts.
Business email compromise and phishing attacks are becoming more sophisticated, and the defenses need to match. Your email security should catch the threats that users cannot identify on their own.
But technology alone is not sufficient. Employee training is essential. Regular phishing simulations, security awareness education, and a culture that encourages reporting suspicious messages all reduce the likelihood that a phishing email will succeed.
5. Network Segmentation and Access Controls
When ransomware gets into a network, it spreads. It moves from the initially compromised system to other systems on the same network, looking for file shares, servers, and additional endpoints to encrypt. Network segmentation limits this lateral movement by dividing your network into isolated segments.
If your firm’s accounting systems are on a separate network segment from general workstations, an attacker who compromises a workstation cannot easily reach the accounting servers. If your backup systems are on an isolated segment with restricted access, the attacker cannot encrypt your backups.
Access controls complement segmentation. Users should only have access to the systems and data they need for their job function. Administrative privileges should be strictly limited. A staff accountant does not need administrator access to the firm’s servers, and granting it unnecessarily expands the damage a compromised account can cause.
The Local Context for Arizona Businesses
Arizona businesses face the same ransomware threats as businesses nationwide, but there are local factors worth noting.
Arizona’s growing business community includes a large number of small and mid-size firms that are prime ransomware targets. These businesses often lack dedicated IT security staff and rely on general-purpose IT support that may not include advanced cybersecurity capabilities. The cyber hygiene basics that prevent ransomware are often missing.
The state’s rapid growth also means many businesses are in transition—upgrading systems, moving offices, adding staff—creating windows of vulnerability when security controls may not be fully implemented.
Arizona’s economy includes concentrations of CPA firms, medical practices, defense subcontractors, and professional services firms—all industries that handle sensitive data and all prime ransomware targets. The intersection of high-value data and often-modest security budgets makes the Arizona small business landscape particularly attractive to ransomware operators.
What to Do Right Now
If you have read this far and recognize gaps in your firm’s defenses, here is a prioritized action list:
This week: Enable MFA on email, remote access, and cloud applications. This is the highest-impact, lowest-cost security improvement you can make.
This month: Verify your backup architecture. Are backups immutable? Are they stored in a separate environment? When was the last test restore? If you do not like the answers, fix this immediately.
This quarter: Evaluate your endpoint protection. If you are running traditional antivirus, upgrade to a solution with behavioral analysis and automated response. Deploy application controls to prevent unauthorized software from executing.
Ongoing: Conduct regular phishing simulations and security awareness training. Review and update access controls. Maintain a Written Information Security Plan that reflects your current environment and threats.
Do Not Wait for Your Own Ransomware Story
The firms that get hit with ransomware always wish they had acted sooner. The investments that seem expensive before an attack look like bargains afterward. A comprehensive cybersecurity program costs a fraction of what a ransomware recovery costs—and it protects your clients, your reputation, and your livelihood.
Asteroid IT helps Arizona businesses build ransomware-resistant environments. We assess your current security posture, identify gaps, and implement the controls that prevent attacks from succeeding. We have seen what ransomware does to small businesses, and we are committed to helping our clients avoid that experience.
Contact us for a free security assessment to find out where your firm stands and what you need to do to protect yourself from ransomware.
