Phishing, email takeover and ransomware at accounting firms

Tax season is phishing season. What if one email gets through?

Fake client emails, a hijacked mailbox, files locked on a Monday morning. Here is the risk, what good looks like, and what we do.

Free consult with Tony. No pressure, no jargon.

The risk on a Monday morning

Illustrative, not a client story. This is a made up sketch. It is not about a Benson Hunt client.

It is the busy part of tax season. A message arrives that looks like it is from a regular client, saying their slips are ready and asking you to sign in. The page looks right. A staff member types in a password. Nothing seems to happen. Over the next days someone reads along, learns who your clients are, and picks a moment. It might be a payment redirected. It might be a program that locks the files on the server over a weekend. On Monday morning the question is simple: could the firm work today, and how long until it can?

That sketch is made up, but it does happen. Read the real story of an Alberta accounting firm hit in the middle of tax season. We were one of its clients.

Good looks like MFA on email and remote access, Huntress on every managed computer, DNS filtering, and backups that stay locked for 30 days so a bad day cannot reach every copy.

No setup can promise to stop every bad email. What we can do is make a stolen password less useful, spot trouble sooner, and keep a Monday morning recoverable. For the shared stack (Hyper-V, RAID 10, Meraki, Huntress, MFA and backups), see the accounting IT support overview and why firms run servers on Hyper-V.

What we put in place

  • MFA on email and remote access. A stolen password alone is far less useful when a second check is required. Coverage matters as much as the method.
  • Huntress and DNS filtering. Huntress on every managed computer, with DNS filtering that blocks known bad sites before the page loads. If something looks wrong, our security operations team (SOC), the people who watch for threats around the clock, sends a text alert. We keep computers patched, with disk encryption on by default unless your software vendor says otherwise.
  • Remote desktop never exposed to the internet. Access goes through a secured gateway with MFA. Safe remote access.
  • Backups that ransomware cannot erase. Server backups run on Veeam and follow the 3-2-1 rule, stay immutable for 30 days, keep an offsite copy in Vancouver, BC, and we test restores. If a server itself fails, we restore it in under 2 hours. More on backups.
  • A Meraki firewall and separate networks. So one infected computer has a harder time reaching the servers.
  • A person to call, day or night. A person answers (604) 813-7881 24/7 for emergencies. Every firm also gets its own group chat with dedicated technicians on WhatsApp, Slack, Google Chat or Microsoft Teams. It is for IT help, so keep SINs and client financial details out of the chat.

Also see

Phishing and ransomware questions we hear

Can IT stop phishing completely?

No. Phishing works through people, so sign in protection and quick alerts matter as much as any filter. Good IT makes a mistake less costly and easier to catch.

What should someone do if they think they clicked something bad?

Tell someone straight away, even if it feels awkward. Early helps. Call us on (604) 813-7881, where a person answers 24/7 for emergencies. Then speak to your insurer and your own advisers about next steps, because those depend on what happened.

Is antivirus enough?

On its own, no. Protection on each computer helps most when someone is watching. Every managed computer runs Huntress, and a person answers emergencies 24/7.

What do cyber insurers often ask for?

Questionnaires often ask about MFA, backups, protection on each computer, patching and staff training. We help you answer accurately, without overstating what is in place. Your broker and insurer decide coverage and terms, and we cannot promise approval.

Want a second pair of eyes before the next busy season?

Call (604) 813-7881 and ask for Tony, or send us a note. Regular hours are Monday to Friday, 7am to 5pm MT, and a person answers emergency calls on the same number 24/7.