Langwasser & Company CPAs Breach Exposes Client Social Security Numbers
The Upland, California-based firm discovered the leak after unauthorized tax returns were filed using stolen client data.
Langwasser & Company CPAs has reported a data breach that exposed the Social Security numbers and financial account details of its clients. The security failure highlights the ongoing vulnerability of professional service firms that handle high-value government identifiers.
The Upland, California-based accounting firm disclosed the incident to the Attorneys General of California and Massachusetts. According to regulatory filings, the breach was discovered after the firm identified the filing of unauthorized tax returns, signaling that client data had been compromised and weaponized for fraud. In response to the leak, the firm has offered affected individuals credit monitoring services through Experian IdentityWorks.
The Vulnerability of Financial Data
Accounting firms like Langwasser & Company occupy a position of extreme trust, managing a comprehensive suite of taxation, payroll, and consulting services for individuals and small businesses. Because these firms act as intermediaries between taxpayers and the government, they maintain centralized databases containing the exact combination of data—names, addresses, and Social Security numbers—required to commit sophisticated identity theft.
Unlike a retail breach where only credit card numbers might be stolen, the loss of a Social Security number is permanent. While a credit card can be canceled and replaced, a government identifier cannot, leaving victims susceptible to long-term financial fraud, including fraudulent loan applications and illegal tax refunds.
Industry Implications
This incident underscores a growing trend of targeted attacks on CPA firms and tax preparers. These entities are often viewed as "soft targets" by cybercriminals because they possess high-value data but may lack the enterprise-grade cybersecurity infrastructure found at major banks or insurance companies. The discovery of the breach via unauthorized tax returns suggests that the attackers were specifically targeting the financial utility of the stolen data rather than simply selling it on the dark web.
What's Next
As the firm works with state regulators, the primary focus remains on the notification of affected clients and the mitigation of identity theft. While the firm has provided credit monitoring, the long-term impact on the affected individuals depends on how widely the data was distributed. Industry observers will be watching for further details on the specific vector of the breach to determine if this was a targeted intrusion or a result of systemic security lapses.