Back to news
Cybersecurity Alert
June 2, 2026 by EmailMeNow IT Consulting

Texas CPA Firms Reporting Data Breaches to the OAG

Several Texas CPA and tax firms have filed data breach notices with the Texas Attorney General, exposing taxpayers' Social Security numbers and financial data. Under IRS Pub 4557 and the FTC Safeguards Rule, a written security plan is mandatory.

CPAAccountingTaxData BreachTexasOAG
Illustration of Texas CPA and tax firm data breaches reported to the Attorney General

The Texas Attorney General publishes data security breach notices for incidents affecting Texans. A search of that public database surfaces several CPA and tax firms — businesses that hold taxpayers’ most sensitive financial records.

Texas CPA & Tax Firms in the OAG Breach Database

FirmCityTexans AffectedDate Published
Keith Gardner CPA PLLCHouston1,50006/12/2025
Carranco & Lawson, P.C.Laredo44701/13/2026
AA CPA Tax Strategies LLCAustin75001/27/2026
Dana Lee CPA LLCSpring15003/27/2026

The exposed data across these notices includes names, addresses, Social Security numbers, driver’s license numbers, and financial account information — exactly the data a tax preparer holds for every client.

Why This Matters for CPA & Tax Firms

The IRS (Publication 4557) requires every tax professional to maintain a written information security plan (WISP) to keep a PTIN, and the FTC Safeguards Rule backs it with civil penalties up to $50,120 per violation, per day. A breach of taxpayer data is both a regulatory and a reputational event few small practices survive.

Check your firm’s email and domain security at audit.emailmenow.com/?industry=cpa-firms.

Recommendations

  • Enforce DMARC (p=reject), strict SPF (-all), and DKIM signing.
  • Add MTA-STS and website security headers; require MFA on anything touching client returns.
  • Document your WISP and run recurring security awareness training before filing season.

Protect your firm and your clients. Contact EmailMeNow IT Consulting for your IRS-ready written security plan and email hardening.


Source: Texas OAG — Data Security Breach Reports