Enterprise DNA

Omni by Enterprise DNA

Enterprise DNA Resources

Thought leadership & research. Practical AI operating-system thinking for owners, operators, and teams doing real work.

220k+

Data professionals

Omni

AI agents and apps

Audit

Map the manual work

Key Findings

Agentic AI is automating cyberattacks on financial data. Here's how accounting firms can lock down client records before tax season.

Agentic AI Cybercrime Is Coming for Your Client Data
Insight ai

Agentic AI Cybercrime Is Coming for Your Client Data

Sam McKay

A recent BankInfoSecurity report on agentic AI laid out something every accounting firm owner should sit with for a minute. Cybercrime used to need a skilled human behind every attack. Now it doesn’t. An AI agent can scan thousands of targets, write a convincing phishing email in your controller’s voice, probe your practice management software for weak spots, and adapt its approach in real time, all without a person watching it work. The attack that used to take a criminal crew a week now takes an agent a few hours, run against hundreds of firms at once.

Your firm is a good target. You hold Social Security numbers, bank account details, payroll data, and tax filings for every client on your roster. Tax season concentrates that risk into a few brutal months when everyone on staff is moving fast, opening attachments, and clicking through client emails without a second thought. That’s exactly the window automated attacks are built to exploit.

What this actually looks like against a firm your size

Agentic AI cybercrime doesn’t announce itself as science fiction. It looks like a slightly-too-perfect email from what appears to be the IRS about a delayed refund, timed to land the week before a filing deadline. It looks like a fake invoice from a vendor your bookkeeper already recognizes, with bank details changed by one digit. It looks like an automated credential-stuffing run against your client portal login, trying thousands of password combinations pulled from old data breaches until one works.

What’s changed is the scale and the personalization. An agent can pull public information about your firm, your staff names from LinkedIn, and your software stack from job postings, then generate a phishing attempt tailored to each employee. It can run that attempt against every firm in a metro area simultaneously and only flag the ones that get a response. For a firm doing $1M to $25M in revenue, with a lean staff and no dedicated security person, that kind of automated, tailored pressure is a different animal than the generic spam filters were built to catch.

The gaps most firms carry into tax season

Most firms this size aren’t negligent. They’re stretched. Security work competes with compliance deadlines and it usually loses. In our conversations with firm owners, a few gaps show up again and again.

Shared logins are common. One QuickBooks Online admin account, one practice management login, passed around the team because setting up individual access with proper permissions felt like a project for later. Multi-factor authentication gets turned on for the firm’s email but not for the client portal or the bank feed connections your close process depends on. Backups exist, but they live on the same network as everything else, which means a ransomware attack that locks your production files locks your recovery files too. And endpoint detection, the software that actually watches for unusual behavior on a laptop before it becomes a full breach, is treated as an IT nice-to-have rather than something reviewed every year.

None of this is unusual for firms of this size. It’s just no longer good enough against an attacker that doesn’t get tired, doesn’t need sleep, and doesn’t need to personally believe the phishing email will work before sending ten thousand versions of it.

What this costs in real dollars

Firms in the $1M to $25M range typically carry $60K to $180K a year in leakage tied to workflow gaps and risk exposure like this, once you account for staff hours lost to incident response, client churn after a breach becomes public, and the compliance overtime that follows any data exposure event. That range holds up whether the leakage comes from an actual breach, from the insurance premium increase after a near-miss, or from the slow bleed of staff time spent manually checking things a properly configured system would have caught automatically.

The math gets worse during tax season specifically. If a ransomware attack locks your files in February, you’re not just dealing with recovery, you’re dealing with recovery during the four weeks a year when 30 to 50 percent of your staff time is already committed to month-end and year-end close work for every client on the books. There’s no slack in the calendar to absorb a week of downtime. Firms tell us the real cost isn’t the ransom, it’s the missed deadlines and the client conversations that follow.

What an AI agent doing this work actually looks like

Here’s the part that matters if you’re already thinking about automating parts of your practice, and most firms your size are. Automation and security aren’t separate projects. They’re the same project, done right or done wrong.

Picture our Month-End Close Agent running overnight, pulling bank, AP, AR, and payroll feeds, reconciling accounts, flagging variances, and preparing a partner-ready close pack by morning. That’s four separate credential sets and four live data connections moving client financial information through your systems on a predictable schedule, which is precisely the kind of pattern an attacker’s own agent is built to notice and probe. Add the Client Onboarding Agent pulling sensitive documents from new clients through a guided intake workflow, and the Advisory Insights Agent reading every client’s monthly numbers to draft talking points for partner meetings, and you’ve got three automated pathways touching the most valuable data in your firm.

Built properly, each of those agents runs on scoped credentials that can only touch what they need, logs every single data pull with a timestamp, and writes to storage that includes an offline snapshot before it processes anything. If something goes wrong, you roll back to last night’s clean version instead of negotiating with a criminal group. Built poorly, or bolted onto an existing insecure stack because someone wanted the efficiency gain without the underlying cleanup, you’ve just handed an attacker three more automated doors into your client data.

This is the piece that gets missed in most AI adoption conversations. Everyone wants to talk about time saved. Almost nobody asks what happens to the security architecture underneath. We’ve written more on how these ops agents get built inside a firm’s existing systems over on /omni/ops, and it’s worth a read before you buy any AI tool that touches client financial data.

Before tax season, do these four things

You don’t need a security department to close most of the gap. Four things move the needle for a firm your size, and none of them require a big budget.

First, get endpoint detection running on every device that touches client data, including staff laptops used at home. This is the single biggest upgrade from basic antivirus, because it watches behavior instead of just matching known virus signatures. Second, move your backups offline or to a separate, disconnected environment, and test a restore before you need one, not after. Third, turn on multi-factor authentication everywhere, not just email, including your client portal, your bank feed connections, and your practice management software. Fourth, run a short staff training refresh before the filing rush starts, focused specifically on the tax-season phishing patterns attackers lean on every year, like fake IRS notices and spoofed client requests for wire changes.

If you want a structured way to walk through this with your team, we put together a practical worksheet called the Month-End AI Close Map for Accounting Firms, which lines up your close-cycle data touchpoints against where the security gaps typically sit. It’s built for firms automating close work, not just firms worried about breaches, because as we covered above those two things are now the same conversation. You can grab the direct download here.

Where an Omni Audit fits

Most firm owners we talk to know something’s off in their systems but can’t point to exactly where. That’s what the audit is for. It’s 60 minutes, no deck, no sales pitch disguised as a workshop. You walk away with three things: a map of where your client data actually moves through your systems, a plain list of the security and workflow gaps sitting in that map, and a realistic estimate of what fixing them is worth to your bottom line, using the same dollar ranges we’ve talked about here.

For firms this size, the conversation usually surfaces one or two of the pains we hear most often, whether that’s the month-end crunch eating 30 to 50 percent of staff time in a handful of weeks, onboarding drag that pushes 20 to 30 percent of new clients into their second quarter before you bill them properly, or advisory work getting crowded out entirely by compliance deadlines even though advisory billing runs two to three times the rate. Cybercrime risk sits on top of all three, because every one of those workflows involves moving client financial data through systems that need to be locked down before you automate them further.

If you want to see how this plays out specifically for firms like yours, [see Omni for accounting and bookkeeping](/