HumanVerified is in beta — free while we build it.Help us make it better →
Small BusinessAccounting & BookkeepingSep 9, 20264 min read

Accounting Firm Payment Redirect Fraud Is a Staffing Problem, Not an Email Problem

Portals and email authentication prove your systems are secure. Neither tells a client whether the message asking them to change a payment came from anyone at your firm.

Listen to this article
Audio narration
Narrated in a natural voice

A controller at one of your client companies gets an email on a Thursday in mid-September. It uses the first name of someone at your firm she half-recognizes — one of five people who have written to her since January — refers to the extension she filed, and gives new instructions for where the estimated payment should go. Nothing about it looks wrong. Accounting firm payment redirect fraud works because a forty-person firm hands every client five plausible senders and no way to tell them apart.

Why accounting firm payment redirect fraud scales with your staff, not your risk appetite

The IRS and its Security Summit partners have spent years telling tax professionals the same thing: firms are targets because of what sits in their systems, and the way in is a convincing email. The annual Dirty Dozen list keeps returning to spear phishing aimed at preparers, including the "new client" message that arrives with an attachment during the busiest weeks of the year. IRS Publication 4557 and the FTC Safeguards Rule turned the response into a compliance obligation — a written information security plan, access controls, staff training.

All of that is aimed at keeping attackers out of your firm. It does very little about the other direction, which is a message going to your client with your firm's name on it that never came from your firm at all. That risk does not scale with how careless your people are. It scales with how many of them the client has met. A sole practitioner has one name for a client to learn. A forty-person firm has partners, managers, seniors, an administrator, a billing contact, and — right now, in extension season — temporary staff the client has never spoken to, all writing to the same controller about the same return.

Your existing controls answer a question the client is not asking

Run through what a well-run firm already has. A secure client portal. Multi-factor authentication. Email authentication records so mail from your domain passes. A written information security plan on file. All of it is worth having; none of it is optional.

But look at what each one proves. Portal access proves someone holds credentials. Domain authentication proves a message left a server your IT provider controls, which says nothing about a lookalike domain an attacker registered last week. The client's question is narrower than any of these: did a real person at this firm review this specific message and authorize sending it? Nothing in the stack answers that, so the client falls back on the only method available — call the main line and ask.

Deadline season is when the gap opens widest

September and October are the weeks when a firm's outbound volume is highest and a client's patience is lowest. Extension deadlines produce a flood of legitimate messages that look exactly like the fraudulent ones: urgent, deadline-referencing, sent from a name the client may not recognize, carrying a link or a payment instruction.

The cost lands in two places, and a firm administrator sees both. The first is the fraud that succeeds, where a client sends an estimated payment to an attacker and everyone spends the next month on the phone with a bank. The second is quieter and larger — legitimate work that stalls because clients have been trained to distrust exactly the kind of email your staff sends. Document requests go unanswered for days. Portal invitations get deleted as phishing. A senior spends an afternoon calling clients to confirm that yes, that really was her.

What a firm-issued verified identity changes at the operations level

The alternative is to give the client something they can check themselves, without calling you. That is what a Human ID is: a permanent identifier issued to each person at the firm and included in the messages that person personally reviewed and authorized. The recipient enters it at HumanVerified.biz and sees the person's name, their organization, and their current status. When a message carries payment instructions or a document request, the sender can attach a single-use code tied to that one communication. How it works covers the mechanics.

For whoever runs the firm's operations, the useful parts are administrative. Issuing an ID is a line on the onboarding checklist, which matters when seasonal staff arrive in January and again in August. Revoking one is a line on the offboarding checklist, and revoked status shows publicly and immediately — a better answer than hoping a departed manager's old messages stop circulating. Issuances, suspensions, and revocations are recorded and kept, which gives the firm a defensible record of who was authorized to write to clients on any given date. For Organizations sets out what a firm gets.

What it does not do, stated plainly

A control that gets oversold becomes a liability, so the boundaries matter. Verification confirms that a communication was personally reviewed and authorized by the person shown. It does not certify that the content is accurate, and it does not validate wiring instructions, account numbers, or any payment detail in the message. Your callback procedure for changed payment instructions stays exactly where it is; this does not replace it. It also makes no claim about whether AI helped write the message, because that is not a claim anyone can honestly make. AI can help write the message; verification tells the recipient who is willing to stand behind it.

Where a firm administrator would start

Not firm-wide on day one. Start with the messages that leave the portal — the emails and texts landing in a client's ordinary inbox and phone, especially anything referencing a payment or a deadline. Issue IDs to the people who send them, put the ID in the signature block, and add one line to the firm's website telling clients how to check it. Fraud attempts will not stop. But a client who wants to verify a message stops having to call you to do it.

Verify your team's communications

Give every person on your team a verifiable identity your clients can check in seconds. Free during beta.

Request organization access

More Commentary