Langwasser & Company CPAs Data Breach Analysis
Analysis of the Langwasser & Company CPAs data breach disclosed 2026-05-05
Langwasser & Company CPAs Breach Exposes SSNs and Financial Identity Data of Unknown Scope
Langwasser & Company CPAs, an accounting and financial services firm based in Upland, California, has begun notifying individuals that their Social Security numbers, names, addresses, and dates of birth were compromised in a data security incident disclosed on May 5, 2026. The firm has not disclosed how many people were affected, when the incident occurred, or how attackers gained access — a pattern of limited disclosure that is becoming increasingly common among small and mid-sized financial services firms handling sensitive tax and financial data.
Key Facts
- Company: Langwasser & Company CPAs (Upland, CA)
- Disclosed: May 5, 2026
- Records affected: Undisclosed
- Data exposed: Social Security numbers, names, addresses, dates of birth
- Attack vector: Not disclosed
- Remediation offered: Credit monitoring referral, standard identity theft guidance
The notification letter provided to affected individuals is notably thin on operational detail. It includes boilerplate language about "numerous safeguards" and "continually evaluating" internal controls, along with the standard triad of credit bureau contacts (Equifax, Experian, TransUnion) and security freeze instructions. What it does not include is any description of the incident itself — no mention of ransomware, phishing, a compromised vendor, or an exposed system. For a firm holding the kind of data CPAs routinely collect (SSNs, financial records, and often full tax returns), this omission is a meaningful gap for anyone trying to assess their actual exposure.
Timeline: What We Know and What's Missing
Public breach notification filings for this incident currently show only a single confirmed date: disclosure on May 5, 2026. Critically absent are:
- Date of occurrence — when the unauthorized access or acquisition actually happened
- Date of discovery — when Langwasser & Company identified the incident
- Gap between discovery and notification — the interval most state breach notification statutes are designed to constrain
This absence matters. Most state breach notification laws — including California's own (Cal. Civ. Code § 1798.82), the state where Langwasser is headquartered — require notification "without unreasonable delay," with several states imposing hard caps (30-60 days from discovery in stricter jurisdictions). Without published occurrence and discovery dates, it is impossible for affected consumers, journalists, or regulators to evaluate whether the firm met its statutory notification obligations. Firms that omit these dates from notification letters make it harder for both consumers and enforcement bodies to hold them accountable to notification timelines — intentionally or not.
What Data Was Exposed — And Why It's Dangerous
The combination of SSN, full name, address, and date of birth is the exact data set needed to pass "knowledge-based authentication" checks used across the financial system — for opening new credit lines, filing fraudulent tax returns, applying for unemployment benefits, or taking over existing accounts. Unlike a stolen credit card number, which can be canceled and reissued in days, an SSN-DOB-address combination is durable. It doesn't expire, and it can be reused indefinitely by threat actors or sold repeatedly on criminal marketplaces.
For a CPA firm specifically, this data set is often bundled with additional context — income figures, dependents, bank account and routing numbers from direct-deposit refund setups, and prior-year tax filings — that dramatically increases fraud yield even when a breach notice describes only the "core four" elements (SSN, name, address, DOB). Tax season fraud, specifically stolen-identity refund fraud (SIRF), remains one of the most lucrative uses of accounting-firm breach data, and the IRS has flagged tax preparers and accounting firms as a persistent target for exactly this reason.
This incident sits alongside a broader trend of breaches at financial data intermediaries exposing similar identity elements — see our coverage of the 700Credit breach, where SSNs of auto loan applicants were exposed through a vendor web application, and the Ashton Thomas Private Wealth breach, where an email compromise exposed client financial records. Small and mid-sized financial services firms — accounting practices, wealth managers, lending intermediaries — are consistently the weakest link in a supply chain that ultimately touches regulated banks and credit unions.
How the Attack Happened
The notification letter provides no attack vector detail whatsoever. There is no mention of ransomware, business email compromise, third-party vendor involvement, or unauthorized network access — the categories that typically appear in breach filings even when firms are otherwise tight-lipped. This total absence of technical detail is itself informative: it suggests either the firm's forensic investigation was limited in scope, legal counsel opted for maximally conservative disclosure language, or both. For a firm of Langwasser's size, a limited or no forensic investigation is a plausible explanation — smaller CPA practices frequently lack in-house incident response capability and may rely entirely on outside counsel and a third-party forensics firm operating under attorney-client privilege, which tends to minimize public technical disclosure.
Regulatory Implications
CPA and accounting firms occupy an interesting position in financial regulation: they are frequently swept into "financial institution" status under the GLBA Safeguards Rule (16 CFR Part 314) because tax preparation and financial planning services fall within the Federal Trade Commission's broad definition of financial activities. Under the amended Safeguards Rule (effective since June 2023), covered firms are required to maintain a written information security program, designate a qualified individual responsible for it, encrypt customer data at rest and in transit, implement multi-factor authentication, and — critically — report notification-triggering security events involving 500+ consumers to the FTC within 30 days of discovery.
If Langwasser & Company's breach affected 500 or more individuals, an FTC filing should already exist or be forthcoming, and it would likely contain more incident detail than the consumer notification letter — worth checking for firms tracking this incident. If the firm is licensed or does business with clients in New York, NY DFS Part 500 obligations could also apply depending on whether the firm is a "covered entity" under DFS's broad licensee definition, though this is less likely for a California-based CPA practice without NY financial licensure.
More broadly, this incident is a reminder that state attorneys general — starting with California's AG, who maintains a public breach notification database — and the FTC increasingly scrutinize accounting and tax preparation firms as a distinct enforcement category, separate from banks and credit unions but subject to comparable data protection expectations given the sensitivity of the data they hold.
The Bigger Picture
Accounting and tax preparation firms have become a structurally attractive target: they aggregate exactly the identity and financial data attackers want, they often operate with security budgets and staffing far below what banks or credit unions maintain, and they are frequently exempt from the direct examination cadence that federal banking regulators apply to depository institutions. The result is a growing category of breaches — CPA firms, tax preparers, small wealth managers — where the data exposed rivals what's stolen in major bank breaches, but the security maturity and disclosure quality lag significantly behind. Firms like 700Credit, LLC and other financial data vendors have shown the same pattern: high-value data, mid-tier security investment.
For CPA firms specifically, this incident should reinforce that "we take this seriously" boilerplate is not a substitute for demonstrable controls — and increasingly, regulators and plaintiffs' attorneys are treating vague notification letters as evidence of an inadequate incident response program, not just poor communications practice.
Action Items for Peer Institutions
-
Verify GLBA Safeguards Rule compliance now, not after an incident. Confirm your firm has a designated Qualified Individual, a current written information security program, and documented encryption and MFA coverage across systems that store client SSNs and tax data.
-
Build breach notification templates that include occurrence and discovery dates by default. Regulators and plaintiffs' counsel increasingly flag their absence as evidence of inadequate incident response documentation — don't let counsel strip them out for the sake of brevity.
-
Audit vendor and email security independently of your core practice management system. Many CPA firm breaches originate in email compromise or third-party portals rather than the primary client database — treat email as a Tier 1 asset requiring MFA and monitoring.
-
Confirm your FTC Safeguards Rule breach notification obligations (500+ affected individuals, 30-day clock) are owned by a specific person, not assumed to be handled by outside counsel by default.
-
Extend fraud monitoring guidance beyond generic credit monitoring offers. Given the tax-season fraud risk specific to CPA firm data, proactively recommend clients set an IRS Identity Protection PIN in addition to standard credit freezes — a step most standard breach notification templates omit entirely.