Business Email Compromise During Tax Season: How Arizona CPAs Get Targeted

Why Arizona CPA Firms Are Prime BEC Targets

Business Email Compromise cost American businesses over $2.9 billion in 2023 according to FBI data. CPA firms are disproportionately targeted because they handle exactly what attackers want: wire transfer authority, client financial data, and W-2 information.

Arizona CPA firms face an especially intense window from January through April when the urgency of tax season overrides normal caution. A partner who would normally verify a wire transfer request takes the email at face value because there are 200 returns due in five days. A preparer who would normally question a client’s unusual document request fulfills it because they’re working 70-hour weeks and can’t afford the delay.

That urgency is exactly what attackers exploit.

How BEC Attacks Target CPA Firms

Partner impersonation

An attacker compromises or spoofs a partner’s email account and sends a wire transfer request to the firm’s bookkeeper. The email looks legitimate because it comes from (or appears to come from) the partner’s actual address. The request is urgent because “the client needs this today.”

Client impersonation

An attacker poses as a client requesting their tax documents be sent to a “new email address.” The preparer, juggling dozens of clients during busy season, sends the documents without verifying through a second channel. Now the attacker has the client’s SSN, W-2, and complete financial profile.

IRS impersonation

Emails claiming to be from the IRS demanding immediate action on a “filing discrepancy.” These exploit tax preparers’ fear of IRS enforcement and create urgency that bypasses normal verification.

Vendor invoice fraud

An attacker intercepts or forges an invoice from a software vendor, cloud hosting provider, or office supplier and changes the payment details. The firm pays the invoice to the attacker’s account.

The Email Security Layers That Stop BEC

DMARC, DKIM, and SPF

These email authentication protocols prevent domain spoofing. When properly configured, they make it impossible for an attacker to send emails that appear to come from your firm’s domain. If your firm hasn’t implemented all three, your domain can be spoofed to attack your clients.

Advanced threat protection

Modern email security goes beyond spam filtering. Advanced threat protection analyzes email headers, sender behavior, and content patterns to detect impersonation attempts that pass basic filters. It flags emails where the display name matches an internal contact but the sending address doesn’t.

Multi-factor authentication

MFA on all email accounts prevents account takeover, the first step in most BEC attacks. If an attacker can’t get into a partner’s email, they can’t send legitimate-looking requests from it.

Verification procedures

Technology alone isn’t enough. Your firm needs documented procedures requiring verbal verification (via a known phone number, not the one in the email) for any wire transfer, payment change, or sensitive data request. This is the human layer that catches what technology misses.

The Tax Season Playbook

Before tax season starts, every CPA firm should:

  • Verify all email authentication (DMARC, DKIM, SPF) is properly configured
  • Test MFA on every account that touches client data
  • Run a phishing simulation to baseline staff awareness
  • Document and distribute the verification procedure for financial requests
  • Review the pre-tax season IT checklist with your IT provider

During tax season:

  • Brief staff weekly on current BEC patterns
  • Flag any email requesting wire transfers, payment changes, or document redirects
  • Never change payment instructions based solely on email
  • Report suspicious emails immediately, even if they turn out to be legitimate

Protecting Your Firm

Asteroid IT provides email security and cybersecurity services for CPA firms across the Phoenix metro area. We configure DMARC, deploy advanced threat protection, and run phishing simulations so your team recognizes BEC attempts before they become losses.

If your firm handles wire transfers or sensitive client data (and every CPA firm does), talk to us about your email security posture before the next busy season.

Call us at 480-937-7021 or schedule a conversation.

Scroll to Top