Accounting Firm Clone Phishing Starts With the Emails You Actually Sent
The IRS's August warning is about what lands in a firm's inbox. At a firm with a few dozen staff, the harder question is whether a client can tell which outbound email is really yours.
A client gets an email from the firm in March asking her to re-upload her 1099s. The formatting and the signature block are right. The name belongs to someone she has actually worked with — a staff accountant she met once on a video call. She uploads them. Nothing about the message was unusual, which is the entire point. Accounting firm clone phishing does not work by being strange. It works by being the fourth ordinary email of a busy week, at a firm that sends a lot of ordinary email.
What the Security Summit Warned Tax Pros About in August
On August 4, 2026, the IRS and its Security Summit partners issued IR-2026-85, part of the eleventh year of the "Protect Your Clients; Protect Yourself" summer series. It walked through the shapes these attacks take: spear phishing, which "targets a specific person or firm and delivers a more realistic email known as a lure," and clone phishing, which impersonates a legitimate sender. Tax pros were told to watch for mail falsely claiming to come from a colleague, a bank, a tax software provider, or the IRS itself.
Every item on that list describes something arriving in the firm's inbox. That is the right advice, and a firm of twenty or eighty people should train on all of it. But it covers one direction of travel.
Accounting Firm Clone Phishing Runs on Mail You Actually Sent
Clone phishing needs a template, and in a tax practice the templates are already sitting in every client's mailbox: the engagement letter, the organizer request, the note asking for a signed Form 8879 today. These are the most reproduced messages a firm produces, and increasingly they are drafted with help from a model — cleaner and more uniform than they used to be.
That matters because the tells clients were taught to look for — bad grammar, odd phrasing, a subject line that sounds slightly off — were never really security controls. They were artifacts of attackers writing in a second language under time pressure, and they are gone. What is left is a client trying to decide whether an email that looks exactly like every other email from her accountant is from her accountant.
Twenty Mailboxes and No Front Door
A sole practitioner has one identity problem and one solution: the client knows her. A firm with a few dozen people has a different problem, and it gets harder every time the firm hires.
Clients at a growing firm receive mail from people they have never spoken to. A new staff accountant asks about a missing depreciation schedule. Someone in the administrative group asks a client to confirm bank details for a refund deposit. None of these requests are unreasonable, and all arrive from names the client has no way to place. The firm knows who works there; the client does not, and has no way to find out that isn't itself an email.
Offboarding is the same problem reversed: when a senior associate leaves in June, his name is still attached to months of correspondence in clients' inboxes, and nothing tells those clients that mail from him should now be treated as suspect.
Your WISP Covers the Firm. It Doesn't Cover the Client.
Another release in the same summer series reminded practitioners that they need a Written Information Security Plan to protect client data. Most firms this size have one, and to the administrator or IT lead who maintains it, it is a familiar document: access controls, encryption, incident response, vendor management, training.
Read it with the outbound question in mind and a gap shows up. The plan describes how the firm protects data it holds. It says little about how a client, outside the firm and with none of those controls, decides whether a message claiming to come from the firm is real. That is not a defect; it is a category the plan was never asked to cover, and the category where the money leaves.
Verification Is Not Detection
Precision matters here, because overclaiming in this area does damage. A Human ID does not detect AI, and cannot tell a client whether an email was drafted by a model or typed by a person. HumanVerified confirms that a communication was personally reviewed and authorized by the person shown. It does not certify the accuracy of the content, and it does not claim the message was written without the help of artificial intelligence.
AI can help write the message. Verification tells you who is willing to stand behind it. For a client holding an unexpected document request or a change in payment instructions, that narrow fact is the useful one. She does not need to evaluate the email. She needs to know whether a real person at the firm put their name on it, and somewhere to check that isn't the email itself. Our verification policy is explicit about where that line sits.
What Rollout Looks Like at Firm Scale
Issue IDs during onboarding, in the same checklist that creates the email account and the practice-management login. Revoke them during offboarding, so a departed associate's name stops carrying the firm's authorization the day he leaves. Put the ID in the standard signature block for everyone who touches clients, not only partners — the staff accountant and the billing coordinator are the people a client is least equipped to place.
Then decide which messages get a per-message verification code rather than a permanent ID alone. In a tax practice the short list writes itself: anything changing payment or deposit instructions, anything requesting documents outside the normal portal flow, anything sent under deadline pressure. Those are the messages worth cloning, which makes them the messages worth verifying.
Firms rolling this out across a staff rather than one person can start at for organizations. None of this stops anyone from sending a convincing email with a partner's name on it. It gives the person receiving it somewhere to look that is not the message.
Verify your team's communications
Give every person on your team a verifiable identity your clients can check in seconds. Free during beta.
Request organization access