BLOG

BEC and Phishing at Tax Season: How Attackers Target Accounting Firms

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 25, 2026

Key Takeaways

  • BEC attacks against accounting firms exploit the trusted financial relationships firms hold with clients, enabling fraudulent wire redirects and payment interception.
  • Phishing volumes targeting accountants spike during tax season and often impersonate the CRA, IRS, or clients.
  • Credential theft from cloud tax and audit platforms gives attackers quiet access to client financial records.
  • Email authentication controls (DKIM, SPF, DMARC) and MFA are the minimum baseline that stops the majority of these attacks.
  • A managed cybersecurity service with phishing-aware controls and seasonal monitoring gives accounting firms the coverage generalist IT providers cannot deliver.

Why Do BEC Attacks Hit Accounting Firms So Hard?

Accounting firms are in the business of moving money on behalf of clients. Wire instructions, payment authorizations, and financial transfers flow through firm email as a routine part of audit, tax, and advisory work. An attacker who can convincingly impersonate a partner or a client within that email flow has access to a trusted channel for fraud, which is what makes firms such a concentrated target for business email compromise.

A successful BEC attack against an accounting firm does not require breaking into a network or deploying malware. It requires a spoofed email address or a compromised inbox, a plausible pretext, and a staff member or client who acts on a seemingly legitimate request before verifying through a separate channel.

The losses are significant. BEC attacks are among the highest-value fraud categories in cybercrime statistics, and accounting firms represent a concentrated target because of both the volume of transactions they handle and the trust their clients extend to firm communications.

How Do Attackers Use Tax Season to Their Advantage?

Tax season is not just a busy period for accounting firms. It is a structural vulnerability that sophisticated attackers plan around. Several factors converge during filing season to increase BEC and phishing success rates.

Deadline pressure reduces scrutiny. A partner managing multiple complex returns is less likely to pause and verify a client email requesting a changed wire destination than they would be in a slower period. The volume of legitimate urgent requests during filing season provides effective cover for fraudulent ones.

Temporary and seasonal staff add access without the same security awareness as permanent employees. They are more likely to click a phishing link, reuse a weak password, or act on a social engineering request without following established verification procedures.

The cost of any disruption during filing season is highest at precisely the moment attackers make their move. A firm that detects suspicious email activity during the week of a major filing deadline faces a genuine dilemma: investigate and potentially disrupt operations, or continue and risk enabling fraud.

What Do Phishing Attacks Against Accountants Actually Look Like?

CRA and IRS Impersonation

Phishing emails impersonating the Canada Revenue Agency or Internal Revenue Service are perennial and effective against accounting staff. These messages typically claim an urgent filing issue, a client audit trigger, or a required credential re-authentication. The goal is harvesting the accountant’s login to tax preparation platforms or firm email.

The credibility of these messages is enhanced by the fact that accountants do receive legitimate communications from tax authorities. A message that arrives during a heavy filing week, formatted to look like a CRA notification, can slip past staff who are processing dozens of real filings simultaneously.

Client Impersonation for Wire Fraud

Attackers research accounting firm client relationships through public sources, LinkedIn, and dark web credential dumps. With enough information about a real client, a fraudulent email requesting a change to payment details or wire instructions can be nearly indistinguishable from a legitimate client message.

Firms that rely on email alone to authorize financial changes without a secondary verification step, such as a phone call to a known client number, are exposed to this attack type. The authorization chain needs a channel that an attacker cannot intercept by controlling a single email account.

Credential Harvesting for Cloud Platform Access

Cloud-based tax preparation, document management, and audit platforms require credentials that give direct access to client financial files. Phishing pages mimicking these platforms capture usernames and passwords, giving attackers authenticated access to client data without triggering network alerts.

Once inside, an attacker can exfiltrate records quietly, monitor ongoing work for intelligence, or prepare a ransomware deployment timed for maximum disruption. MFA on every cloud platform is the control that stops credential theft from becoming a full breach.

What Technical Controls Reduce BEC and Phishing Risk?

Email authentication controls are the foundation. DKIM, SPF, and DMARC records, properly configured and set to enforcement policy, prevent attackers from spoofing a firm’s domain in emails sent to clients. Without these email authentication controls, a firm’s domain can be used to send fraudulent messages that appear to originate from within the firm.

Multi-factor authentication on firm email, cloud platforms, and remote access eliminates the value of stolen credentials. A phished password alone cannot access an MFA-protected account. For accounting firms with cloud-based practice management, MFA is a non-negotiable control.

Phishing simulation and staff awareness training give partners and staff the pattern recognition to spot suspicious messages, particularly the impersonation attempts that are most effective during tax season. A firm whose staff have been tested against realistic phishing scenarios performs measurably better against real attacks.

Conditional access policies that restrict login from unexpected locations or devices add a layer of detection. An attacker using stolen credentials from an overseas IP attempting to access a Toronto-based firm’s tax platform should trigger an alert and require additional verification.

Why Does This Require More Than Standard IT Support?

A standard IT provider can configure email and manage user accounts. They are not equipped to run phishing simulations calibrated to accounting firm attack patterns, configure DMARC enforcement without disrupting legitimate email flows, or produce the evidence of email security controls that cyber insurers and SOC 2 questionnaires require. Armour Cybersecurity’s approach to accounting firm email security includes authentication controls hardened for tax-season targeting, phishing-aware staff training, cloud platform MFA enforcement, and continuous monitoring that increases during peak filing periods. The programme is built around how accounting firms operate, not generic email security defaults.

What Happens After a BEC Attempt Succeeds?

When a BEC attack results in a fraudulent transfer or credential compromise, the response timeline matters. Funds transfer fraud has a narrow recovery window; the faster a firm contacts its financial institution, the higher the likelihood of partial recovery. Credential compromises require immediate password resets, session revocation, and a review of what the attacker accessed. Firms without a documented incident response plan lose critical time during initial confusion about who to call, what to preserve, and how to notify affected clients. A breach response plan and a relationship with a cybersecurity firm before an incident occurs shortens that timeline significantly.

Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the accounting firms that shrug off a BEC attempt are almost always the ones that made the attacker’s job impossible before filing season started, DMARC at enforcement, MFA on every platform, and a standing rule that no wire change is actioned on email alone, so the fraudulent message arrives and simply has nowhere to go.

Frequently Asked Questions

How do we know if our firm’s domain is being used to spoof clients?

DMARC reporting tools provide visibility into emails sent claiming to be from your domain. Armour can configure DMARC with aggregate and forensic reporting so you see attempted spoofing before clients report receiving suspicious messages. Many firms are surprised to discover their domain is being actively spoofed before any controls are in place.

Is phishing training really effective, or do staff just click links anyway?

Structured phishing simulation programmes that provide immediate feedback when a staff member clicks a test link, followed by targeted training, consistently reduce click rates over time. The firms with the highest phishing resilience run regular simulations, not one-time annual training. Armour’s awareness training programme covers the accounting-specific scenarios that matter most.

What should we do if a client reports receiving a suspicious email from us?

Treat it as a potential security incident immediately. Engage your cybersecurity provider, review email authentication records for evidence of domain spoofing, check for any signs of inbox compromise, and notify other clients who may have received similar messages. Delaying the response while investigating internally increases the window for fraud.

Do we need to report a BEC attack to regulators?

In Canada, PIPEDA and Quebec Law 25 require notification of material privacy breaches. A BEC compromise that results in unauthorized access to client financial information likely triggers reporting obligations. CPA professional bodies also have conduct expectations around breach notification. Legal and regulatory guidance should be obtained promptly after any confirmed incident.

The Bottom Line

BEC and phishing against accounting firms are not random spray-and-pray; they are timed to your calendar, aimed at your trusted client relationships, and most dangerous in the weeks you can least afford disruption. The reassuring part is that these attacks rely on gaps that are fixable in advance: a domain protected by DMARC enforcement, MFA on every platform, staff trained on the exact impersonation patterns that spike at tax season, and a firm-wide rule that no payment change is authorized on email alone. Armour Cybersecurity helps accounting firms and CPA practices harden their accounting firm email security and reduce BEC and phishing risk with controls built around filing-season pressure, not generic email defaults, so the busiest weeks of your year stop being the most dangerous.

Leave the first comment