Why Ransomware Groups Keep Targeting Accounting Firms

Two ransomware gangs claimed two different CPA firms within 48 hours in early July 2026. That is not a coincidence. Accounting and law firms sit on exactly the kind of concentrated, high value client data that ransomware economics reward, and most run leaner security than the risk actually calls for.

Two CPA Firms, Two Ransomware Groups, 48 Hours Apart

On July 6, the ransomware group Qilin claimed Wood Ellis & Wood CPA, a U.S. accounting firm, threatening to publish client data unless the firm made contact. Two days later, on July 8, a separate group calling itself Pear claimed Tostrud & Temp, S.C., a CPA firm in La Crosse, Wisconsin, running the same playbook: steal first, then threaten to leak. A third case surfaced the same week when a Lufkin, Texas accounting firm, Todd, Hamaker & Johnson, LLP, made local news after the Akira ransomware group posted roughly 40 gigabytes of the firm's client and employee data to its leak site, including Social Security numbers, driver's licenses, and passports.

Three firms. Three different ransomware groups. One target profile.

This is not a one month blip. Halcyon, a firm that tracks ransomware activity, counts more than 200 incidents against law firms alone between 2025 and early this year, and says a single ransomware group has claimed 20 law firms on its own so far in 2026. Average data breach cost in the legal sector has climbed to $5.08 million, up about 10% year over year.

Why Accounting and Law Firms Specifically

Tax returns, audit workpapers, payroll files, M&A due diligence, litigation strategy. A single firm's file server holds identity theft material and leverage worthy secrets for dozens or hundreds of clients at once. One breach gives an attacker the data equivalent of hitting every one of those clients separately. That concentration is exactly what makes the economics of ransomware work in the attacker's favor.

The defense side of the ledger does not match the risk it is carrying. In professional services specifically, phishing accounts for 41% of incidents and business email compromise another 28%. Average recovery takes 32 hours. Only 28% of firms carry cyber insurance. Prevention spending sits at just 8% of the IT budget, the lowest share of any sector measured, well behind financial services at 18% and healthcare at 12%.

Zoom out to small and mid sized businesses generally and the imbalance gets starker. Ransomware shows up in 88% of breaches at businesses under roughly 500 employees, compared with 39% at larger organizations, according to Verizon's Data Breach Investigations Report. Attackers are not landing on smaller professional services firms by accident. They are choosing the firms least likely to have a real answer ready when the ransom note shows up.

The Tooling Is Built for Smaller Defenses, Not Just Smaller Budgets

Ransomware gangs are not the only ones adjusting their targeting. A malvertising campaign uncovered by Palo Alto Networks' Unit 42 and reported July 7 lures victims with fake cracked software downloads, then installs both the Vidar credential stealer and a cryptocurrency miner. The loader pads its file size to nearly 500 megabytes specifically to skip past sandbox limits that most small organizations never bother to adjust, and signs itself with a forged certificate borrowing a recognizable streaming brand to slide past security warnings.

Denis Calderone, chief technology officer at AI security firm Suzu Labs, told Dark Reading the campaign's evasion techniques are "specifically tuned for SMB-grade defenses." That line is worth sitting with. This is not a generic attack that happens to land on smaller firms. Someone built it, tested it, and tuned it to slip past the specific gaps that show up at a 40 or 80 person firm and not at a 4,000 person one.

What Actually Closes the Gap

Two numbers matter more than any single incident in the news this week. VikingCloud found that 96% of ransomware attacks specifically target backup locations, and in 54% of cases attackers deploy the ransomware itself within seven days of first getting in. A backup that a ransomware operator can find and encrypt alongside everything else is not a backup. A security review that happens once a quarter is reviewing an environment that may already be compromised by the time anyone looks at it.

Firms that keep operating through a ransomware attempt tend to share a short list of things that were already in place before anything happened: multi factor authentication on every account that can reach client data, backup retention that lives somewhere the ransomware itself cannot reach and that someone actually tests by restoring from it, continuous monitoring instead of a quarterly check in, and a written incident response plan that has been walked through at least once instead of existing only as an assumption. None of that is exotic. Most of it is affordable once a firm knows to ask for it: industry estimates put real prevention spending at $5,000 to $15,000 a year, against incident costs that regularly clear $500,000.

The firms in this week's headlines did not lack a general awareness that ransomware exists. Every accounting and law firm knows the word by now. What separates the ones still operating from the ones negotiating with Qilin or Pear over a leak site countdown is whether someone was actually responsible for closing those specific gaps before the countdown started, and had the discipline to keep checking.

Curious whether your backups would actually survive a ransomware attempt, or just look like they would on paper? Get in touch for a plain-language look at where the gaps are.

Frequently Asked Questions

Why are accounting and law firms specifically targeted by ransomware?

Accounting and law firms concentrate high value client data, including tax records, financial statements, Social Security numbers, and privileged communications, in one place. That concentration means a single breach yields data on dozens or hundreds of clients at once, which makes the payoff for attackers much higher relative to the effort than targeting one client at a time.

How much does a ransomware attack cost a small accounting or law firm?

Costs vary widely, but the average data breach cost in the legal sector reached $5.08 million in 2026, up about 10% year over year. Industry estimates put real prevention spending at $5,000 to $15,000 a year for a growing business, compared with incident costs that regularly clear $500,000 once recovery, downtime, and notification are included.

Does cyber insurance cover ransomware losses for professional services firms?

It depends on the policy, and coverage gaps are common. Only about 28% of professional services firms carry cyber insurance at all, and many policies exclude losses tied to unpatched software or missing basic controls like multi factor authentication, so a policy on paper does not guarantee a payout.

What is the fastest way for a growing business to reduce ransomware risk?

Start with multi factor authentication on every account that can reach client data, and confirm your backups are stored somewhere that a ransomware attack on your main systems cannot also reach. Those two steps address the two most common failure points, stolen credentials as the entry point, and backups that get encrypted right alongside everything else.

Can Microsoft 365's built in backup protect against ransomware?

Not on its own. Microsoft 365's native retention tools are built for accidental deletion and short term recovery, not for surviving a targeted ransomware attack, and they are not a substitute for an independent, immutable backup with retention your firm controls.