
How to Protect Client Financial Data From Phishing and Ransomware
Protecting client financial data from phishing and ransomware is really one problem wearing two masks. Phishing is how attackers get in. Ransomware is what they do once they're inside. Defend the inbox well and you've defused most ransomware before it starts; prepare for ransomware anyway, because "most" isn't "all." For a firm holding tax returns, bank details, and Social Security numbers, this pair is the threat model. Everything else is a footnote.
What the modern lure looks like
Forget the misspelled emails from strangers. The message aimed at your firm is clean, correctly formatted, and plausible. It knows your partners' names from the website and your clients' names from LinkedIn. It arrives as a document request from "opposing counsel," a shared file from "the bank," or new wire instructions from "a client" whose real deal genuinely is closing this week. Sometimes it comes from a real client's actual mailbox, because the client got compromised first and the attacker read six months of correspondence before writing a single word.
And the timing is chosen. Which brings up a pattern anyone in this industry will recognize.
The 11pm email
A version of this plays out every filing season, at firms of every size, and the shape of it is always the same. It's 11pm in February. A preparer is still at the desk, forty emails behind, running on vending machine dinner. A message arrives from what looks like a client. Nothing fancy: a worried sentence and an attachment named like an IRS notice. At 11am, rested, that preparer would notice the reply address is slightly off and that this client has never once emailed at night. At 11pm they open it, because tired eyes click things rested eyes wouldn't, and the people who built the lure knew exactly which week and which hour to send it.
Nobody in that story is careless. The story is about load. Which is why part of the fix has nothing to do with security software: firms that manage the February crush deliberately, including how after-hours calls and messages get handled so they don't all become midnight inbox triage, simply present fewer exhausted people to the people hunting for them. Attackers target fatigue. Reducing fatigue is a security control, even though it never appears in the budget under security.
Hardening the inbox
The filtering you want checks link destinations at click time, not just at delivery, because attackers arm links after the email lands. It detonates attachments in a sandbox before a human can. It notices when "your bank" writes from a domain registered on Tuesday, and it puts a visible banner on anything from outside the firm.
Add enforcement-level SPF, DKIM, and DMARC so your own domain can't be borrowed for attacks on your clients. This whole layer is precisely what our phishing protection service builds, and it's the control with the best ratio of breaches prevented to dollars spent, because it stands in front of the mistake instead of behind it.
Some things still get through the best filter. Arithmetic, not defeatism. It's why the next layers exist.
What ransomware actually threatens now
The encryption is only half the extortion. Modern crews copy your data out before they lock it, so the demand carries two threats: pay or lose access, pay or the client files go public. That second threat is aimed at professional firms specifically, because a construction company's project files leaking is embarrassing, while a CPA firm's client returns leaking is a notification event with regulators attached. It also means a perfect backup doesn't make you immune to extortion. It makes you immune to the downtime half, which is still worth a great deal. Downtime in March is its own catastrophe.
Assuming the click happens
**EDR on every machine.** Ransomware behaves unmistakably once it starts: rapid file access, encryption calls, shadow-copy deletion. Endpoint detection and response recognizes the behavior and isolates the machine mid-act. Bare antivirus mostly recognizes last year's samples.
**Segmentation.** One infected laptop shouldn't be able to reach every file the firm owns. Separate client data from the general network, and both from guest Wi-Fi, so a foothold stays a foothold.
**Least privilege.** When credentials get stolen, the thief inherits exactly the victim's permissions. Hand those out with the same care as office keys, and the seasonal preparer's stolen password stops mattering much.
**Backups the attacker can't reach.** Copies stored off the network, under different credentials, ideally immutable so even an admin login can't delete them. The gangs check for backups before they pull the trigger. Make yours the kind they can't touch, and restore-test them quarterly, for real.
The money rules
Two process rules stop the most expensive category of loss outright. Payment details never change on the strength of an email; a phone call to a number you already had confirms every change. And large or unusual transfers get a second approver, every time, even when the requester is a partner in a hurry. Especially then, actually, since "partner in a hurry" is the exact costume this fraud wears.
People, drilled kindly
Run phishing simulations that mirror your real threats: fake IRS notices in February, fake e-file confirmations, fake client attachments. Keep training short and frequent. And build the no-blame reflex, because the person who reports their own click within five minutes has saved you weeks of quiet compromise, while the person who's scared to report has donated those weeks to the attacker. Speed of confession is a security metric. Treat it like one.
Be honest about your MFA story too. It helps enormously and it can be bypassed, so it rides alongside these layers rather than replacing any of them.
If today is the bad day
Unplug the affected machine from the network. Don't power it off, because memory holds evidence. Then start the clock on your first 24 hours after a breach: insurer, isolation, scope, documentation. What you do before help arrives sets the ceiling on how well this ends.
The wider frame
Phishing and ransomware sit inside the bigger picture of cybersecurity for accounting firms, and the full defensive stack, insurance and compliance included, is mapped in our cybersecurity guide for firms. If you fix one thing this week, fix the inbox. If you fix two, test the backups.



