The Cybersecurity Risks Salt Lake City CPA Firms Can't See Coming This Summer

July 2026 | Tax Season Cybersecurity Salt Lake City | Summer Threat Awareness | IRS Phishing & BEC Targeting CPA Firms

On the surface, the water looks calm. That's what makes Shark Week fascinating every year — the danger is never visible on the surface. It's already moving underneath.

Cybercriminals targeting Salt Lake City CPA firms operate the same way. Your accounting firm just survived the most stressful filing season of the year. The pressure is off, the team is catching its breath, and the pace has finally slowed down. That calm is exactly what attackers are counting on.

CPA firms are high-value targets year-round — client SSNs, bank routing numbers, business financials, and tax return data are among the most valuable information a criminal can steal. But the summer months, when oversight thins and staff finally relaxes, create a specific window that threat actors deliberately exploit. Here are three ways they're circling Salt Lake City accounting firms right now.

1. Fake Vendor Invoices and Firm Impersonation

Attackers don't always need to hack your accounting systems. In many cases, they just need to send one believable email.

This is called business email compromise (BEC), and it targets CPA firms by impersonating vendors, software providers, or partners your accounting staff already trusts. The email arrives looking completely legitimate — a payroll software renewal from your Drake Tax or CCH Axcess vendor, an urgent invoice from your document storage provider, a payment request that appears to come from a trusted client. Someone on your team processes it. By the time anyone realizes the request wasn't legitimate, the money is gone.

These attacks spike during the post-tax season window for a predictable reason: the partners who normally approve financial requests are finally taking time off. Requests get rerouted to accounting staff who don't always know what normal looks like — and who are less likely to question urgency after months of operating in crisis mode.

The fix is straightforward: build a verification process for any financial request received via email. A quick confirmation call to a known number — not the number listed in the email — is enough to stop most BEC attacks before they go anywhere. This is a foundational requirement for IT security for CPA firms in Salt Lake City, and it costs nothing to implement.

2. Phishing Disguised as IRS Notices and State Tax Authority Emails

Phishing targeting CPA firms is more sophisticated than the generic attacks aimed at other businesses — because the criminals know exactly what your accounting staff is expecting to receive.

During summer months, threat actors send phishing emails crafted to look like IRS e-services notifications, EFIN renewal reminders, state tax authority compliance alerts, or IRS Identity Protection PIN confirmations. They know that CPA firms receive legitimate correspondence from these agencies regularly, and they know your accounting staff is trained to act quickly on anything that looks like a compliance deadline.

A distracted employee sees what appears to be an IRS e-services security alert and clicks the link to verify credentials. Someone receives what looks like a Utah State Tax Commission notice and opens the attachment. The phishing works because it's engineered around how CPA professionals actually behave — under the assumption that anything from a tax authority is time-sensitive and real.

The most effective protection for your accounting firm isn't just a spam filter — it's culture combined with technology:

  • Accounting staff need to feel empowered to slow down and verify before clicking any link in an email that claims to be from the IRS, a state tax authority, or a tax software vendor
  • Any unexpected login request for UltraTax CS, Lacerte, TaxDome, or IRS e-services should be confirmed through a separate channel
  • Emails requesting credential resets for client portal systems like ShareFile or SmartVault should be verified directly with the software provider

Speed is the weapon attackers use against CPA professionals. Slowing down — and having a clear process for flagging suspicious IRS-related communications — is how your Salt Lake City accounting firm takes that weapon away from them.

3. Software Vendor Supply Chain Risks

CPA firms rely on a complex web of interconnected software: UltraTax CS feeding into client portals, Lacerte syncing with document management systems, QuickBooks integrating with practice management tools like Karbon or Canopy, SafeSend handling completed return delivery. When any vendor in that chain is compromised, the threat doesn't stay contained. It travels directly into your firm's systems through whatever connection that vendor has to your client tax records.

This is supply chain exposure, and accounting firms have significantly more of it than they often realize. Over the course of a busy tax season, software tools get connected to firm networks quickly, contractor access gets granted under deadline pressure, and vendor integrations get configured without a full security review. By summer, most firms have never fully mapped what they've connected.

Outsourcing your software doesn't outsource your accountability for client data security. IRS Publication 4557 holds CPA firms responsible for the security of taxpayer information — including data that passes through third-party systems. To understand your supply chain exposure, you need to be able to answer three questions:

  • Which software vendors and contractors can access your client tax record systems?
  • What exactly are they connecting to — and is that access still necessary?
  • Who is internally responsible for managing and auditing those vendor relationships?

If those answers aren't clear, your firm's IRS data security posture has gaps that a compliance audit — or a breach — will surface.

By the Time You See It, It's Already Moving

Sharks don't announce themselves — and neither do the cybercriminals targeting Salt Lake City CPA firms right now.

The accounting firms that get hit aren't always the ones that ignored obvious warning signs. They're the ones who assumed everything was fine because the filing season was over and nothing looked wrong on the surface. Summer is when attention drifts, when partners are finally on vacation, and when the post-season calm feels like safety. It's also when attackers who have been watching your firm's patterns all year make their move.

Proactive cybersecurity for Salt Lake City CPA firms means building the defenses before the threat arrives — not scrambling to explain a client data breach after it happens.

Frequently Asked Questions

Do you offer cybersecurity and IT support for CPA firms in Salt Lake City?

Yes. Qual IT works with Salt Lake City CPA firms to protect client tax records, defend against IRS phishing attacks, and close the supply chain exposure that comes from complex tax software ecosystems. We understand IRS Publication 4557 requirements and the specific threats targeting accounting firms.

What is business email compromise and how do CPA firms protect against it?

Business email compromise (BEC) is a cyberattack where criminals impersonate a trusted contact — often a software vendor, payroll provider, or client — to trick accounting staff into wiring money or sharing credentials. Protection starts with verification: any financial request or credential update received via email should be confirmed by phone using a known contact number before action is taken.

Why are CPA firms targeted by IRS phishing attacks?

CPA firms are high-value targets because they hold large volumes of sensitive taxpayer data — SSNs, bank account numbers, business financials — across hundreds of clients simultaneously. Criminals craft phishing emails to look like IRS e-services notices, state tax authority alerts, or tax software security updates because they know accounting professionals are conditioned to treat these as urgent and legitimate.

How do I know if my Salt Lake City CPA firm has third-party vendor risk?

If any tax software vendor, document management provider, or contractor has access to your client tax record systems — and you don't have a clear record of what they can access and who manages that relationship internally — you have vendor risk. A managed IT security review can map your full exposure under IRS Publication 4557 and flag any access that should be revoked.

We work with Salt Lake City CPA firms to protect client data and keep systems running through tax season.

Don't wait until you see the threat. Schedule your free discovery call today.