Skip to content
Bellator Cyber Guard
Tax14 min readStandard

Business Email Compromise Prevention for Tax Firms

Learn how tax firms stop business email compromise with SPF/DKIM/DMARC, MFA, and verification rules. Practical steps you can start this week.

By Bellator Cyber Guard Security Team

What Business Email Compromise Means for Your Tax Firm

Business email compromise (BEC) is a scam in which criminals impersonate a trusted email sender, a partner, a client, a payroll vendor, to trick your staff into wiring money, changing bank details, or handing over sensitive tax data. For tax firms, BEC is one of the most common and costly threats you'll face, because filing season creates exactly the conditions attackers look for: high email volume, time pressure, and constant requests involving Social Security numbers, W-2s, and client refunds.

Preventing BEC at a tax firm requires a mix of technical email authentication, verification procedures for anything involving money or data, and staff training that treats an "urgent" request as a signal to slow down, not speed up.

Quick Answer

Business email compromise prevention for tax firms combines technical email authentication (SPF, DKIM, and DMARC), multi-factor authentication on every email account, and a mandatory phone-verification step for any request to change bank details, wire funds, or send W-2s or client tax data. Add regular staff training on impersonation tactics and a written incident response plan so your team knows exactly what to do if a request looks off. No single control stops every attempt, but layering these reduces both the odds of a successful scam and the damage if one gets through.

How BEC Scams Target Accounting and Tax Practices

Attackers research your firm before they strike. They monitor public staff directories, LinkedIn profiles, and prior data leaks to learn who handles wires, who signs off on client refunds, and when your busiest filing weeks fall. Common scenarios covered in our phishing attacks on tax professionals guide include:

  • Spoofed partner or client emails asking a bookkeeper to change a vendor's bank routing number right before a payment run.
  • Fake requests for W-2s or Social Security numbers, often timed to arrive during the first weeks of filing season when staff are moving fast.
  • Compromised vendor accounts, a real vendor's email is taken over, and the attacker sends an "updated invoice" with new payment details from an account your staff already trusts.

These scams succeed by exploiting trust and urgency, not just technical weaknesses. A firm without a verification habit will act on a convincing email even when the underlying account was never technically hacked, it was spoofed, or the display name was altered to look familiar.

BEC Prevention Checklist for Tax Firms

  • Enable SPF, DKIM, and DMARC on your firm's email domain to block spoofed sender addresses
  • Require multi-factor authentication on every email account, including shared and admin mailboxes
  • Set a hard rule: no bank detail changes or wire transfers without a verbal callback to a known phone number
  • Train staff to check the actual sender address, not just the display name, before acting on financial or data requests
  • Document your BEC response steps in your written information security program (WISP)
  • Run periodic phishing simulations focused on invoice fraud and impersonation scenarios

Steps to Harden Your Firm's Email Against BEC

1

Lock down email authentication

Configure SPF, DKIM, and DMARC, a set of standards that let receiving mail servers verify your domain actually sent a message and reject forged ones, so spoofed emails claiming to be from your firm get blocked before they reach a client's inbox.

2

Turn on MFA everywhere

Require multi-factor authentication on every account tied to your email platform, including mobile access and connected apps, so a stolen password alone can't grant an attacker access. See our guide to two-factor authentication for tax firms.

3

Build a verification habit

Require a phone call to a known, previously verified number before honoring any request to change payment details, wire funds, or release tax documents, never call a number provided in the suspicious email itself.

4

Train and test staff regularly

Run scheduled phishing simulations and short refreshers so staff recognize urgency, authority, and secrecy as red flags rather than normal business pressure.

5

Prepare an incident response plan

Document who to notify, how to attempt to freeze a pending transfer, and when to involve your bank and law enforcement if a BEC attempt succeeds.

Where BEC Prevention Fits Your Compliance Obligations

BEC prevention overlaps directly with obligations many tax firms already have. The FTC Safeguards Rule, which applies to tax preparers as "financial institutions" under the Gramm-Leach-Bliley Act, requires a written information security program (WISP) that addresses access controls and staff training, both core BEC defenses. IRS guidance in IRS Publication 4557, summarized further in our tax safeguard compliance 4557 overview, specifically identifies email-based social engineering as a risk tax professionals should document and mitigate.

If you haven't documented your email security controls in a WISP yet, our WISP template guidance walks through what the IRS and FTC expect to see. This is a compliance documentation question, not a legal one, confirm specific obligations for your firm with your compliance advisor or counsel.

Wire and Bank-Detail Requests Deserve Extra Scrutiny

If an email asks you to change a vendor's bank details, redirect a client refund, or wire funds on a tight deadline, treat it as a possible BEC attempt until you verify it by phone using a number you already had on file, not one provided in the email. According to the FBI's Internet Crime Complaint Center (IC3), business email compromise scams caused $2.9 billion in reported losses in 2023, making it one of the costliest categories of cybercrime the agency tracks.

Layer Technical Controls With a Trained Team

No filter catches every spoofed message, and no employee catches every scam on a busy filing day, that's why BEC prevention works best as layers rather than a single fix. Pair the technical controls above with the broader practices in our email security guide, and put a written incident response plan in place so your team has clear steps if a scam gets through despite your defenses.

Get a Free Email Security Review for Your Tax Firm

We'll look at your current email authentication, MFA setup, and WISP documentation, then tell you plainly what needs attention before next filing season.

Frequently Asked Questions

Business email compromise is a scam where criminals spoof or take over an email account to impersonate someone you trust, a partner, client, or vendor, in order to redirect payments or extract sensitive data. It typically relies on social engineering rather than malware, which is why email authentication alone doesn't fully stop it.

Call the requester at a phone number you already have on file, not one listed in the email, and confirm the change verbally before acting. Legitimate vendors and clients generally won't object to a quick verification call, especially for a bank detail change.

The FTC Safeguards Rule requires a written information security program covering access controls, staff training, and incident response, which overlaps with core BEC defenses like MFA and verification procedures. It doesn't name "BEC" specifically, so confirm how your documented controls map to the rule's requirements with your compliance advisor.

Contact your bank immediately to attempt to recall or freeze the transfer, report the incident to the FBI's IC3, and follow your firm's written incident response plan to notify affected clients if their data was involved. Speed matters, banks have a narrow window to reverse fraudulent wires.

Share

Share on X
Share on LinkedIn
Share on Facebook
Send via Email
Copy URL
(800) 492-6076

From requirement to defensible practice

Turn IRS and FTC expectations into a WISP your office can follow

A useful compliance path makes the obligation clear, identifies the evidence to retain, and connects written policy to the safeguards used every day.

People also look for

Keep exploring Tax security & WISP

Understand what tax professionals need to document, protect, and prepare before an IRS or FTC review.