
Spear phishing vs PR accountants: tax season, peak risk
Emails with tax authority logos and "urgent" attachments. Why accounting firms are premium targets in Jan–Apr.
Between January and April, accounting firms in San Juan, Bayamón, and Miami serving Puerto Rico clients receive spear phishing waves with logos from Hacienda, the IRS, or local banks. Brian Krebs has documented BEC campaigns against continental tax preparers; in PR the vector is identical but the email arrives in flawless Spanish referencing Form 480 or extension deadlines.
The attacker researches: firm website, partner LinkedIn, public clients
The attacker researches: firm website, partner LinkedIn, public clients. The email asks to "update portal credentials" or includes a ZIP with "urgent tax documentation." One click and malware steals portal cookies, email credentials, or installs a keylogger while the accountant prepares dozens of returns.
OWASP publishes social engineering guidance applicable beyon
OWASP publishes social engineering guidance applicable beyond development: out-of-band verification, callbacks to known numbers, and never processing bank account changes by email alone. For accounting firms we separate tax prep workstations from general email, block macros, and require MFA on e-filing portals.
Season-specific training: simulations in January before the peak, not July after damage is done. Bruce Schneier insists the human link fails under deadline pressure — exactly the tax season environment. Include "client requests urgent refund transfer" scenarios in cwAWARE workshops.
One compromised accounting firm in PR exposes hundreds of taxpayers: W-2s, Form 480, banking data. That is a reportable incident, reputational damage, and possible professional liability. Investing in controls in December costs less than responding in March under audit.

Operations and execution — connecting strategy with what the team ships every week.


