A Canadian mid-market accounting firm engaged LeakTrace ahead of its tax season filing window to establish a pre-season exposure baseline. The audit identified credential exposure that would have created a filing-window incident risk if exploited, and remediation completed before the firm's client volume peaked.

Engagement origin

The firm operates a mid-market accounting practice with approximately sixty staff across two provinces, serving a mix of corporate, professional, and high net worth individual clients. The firm's tax season filing window historically produces a materially elevated volume of Canada Revenue Agency filings, client-directed wire instructions, and inbound client communication. The firm's principal had absorbed industry reporting on filing-window fraud attempts against comparable practices and commissioned a pre-season exposure baseline to identify and close any exposure conditions before the season window opened. LeakTrace was engaged through the firm's outside counsel.

Discovery scope

LeakTrace conducted a seventy-two-hour external attack surface audit covering the firm's registered domain, partner and staff email patterns, public directory records associated with the firm's Chartered Professional Accountants of Canada registration, and the vendor mapping visible through DNS and certificate transparency records. The audit was scoped as pre-season reference material rather than as a post-incident forensic engagement.

Findings summary

  • Staff credential exposure. Twelve staff email addresses were identified in monitored breach databases. Five had recoverable password fragments and four of those five reused the pattern across the firm's tax preparation platform login. The exposure would have permitted a targeting actor to attempt authenticated access to the platform during the season window.
  • Public tax preparation platform exposure. The firm's tax preparation platform was configured for remote access without geographic access controls. The vendor's version disclosure indicated the platform was running a release the vendor had issued a security advisory on in the prior quarter, with the advisory not yet applied at the firm level.
  • Client portal exposure. The firm's client portal, through which clients submitted tax documentation, was reachable without bot mitigation. Session lifetime was configured beyond the current industry baseline for the platform, which would extend the window during which a session token could be misused.
  • Business email authentication. The firm's Sender Policy Framework and Domain-based Message Authentication configuration would have permitted a well-formed spoofing attempt to reach client and Canada Revenue Agency-facing recipients without triggering authentication warnings, materially elevating filing-window fraud risk.
  • Partner personal exposure. The firm's senior partners had personal email exposure in monitored breach databases with reuse patterns extending into professional accounts, creating a plausible pretext for high-value client wire redirect attempts during the season window.

Firm actions

The firm executed a coordinated remediation program in the weeks preceding the season opening. Passwords were rotated across all identified exposed credentials, multi-factor authentication was enforced across the tax preparation platform and client portal, and passphrase managers were rolled out to all staff and partners. The tax preparation platform vendor's security advisory was applied and geographic access controls were configured. The client portal session lifetime was reduced to the industry baseline and bot mitigation was enabled. Sender Policy Framework and Domain-based Message Authentication configurations were revised to block spoofing attempts. Client-directed wire instruction workflow was revised to require an out-of-band voice confirmation using contact numbers held in the client intake record.

Outcome

The firm completed its tax season filing window without any documented incident against its own systems or against a client wire request. Post-season review identified two intercepted wire redirect attempts that had been blocked at the revised out-of-band confirmation step. The firm retained LeakTrace for a standing pre-season baseline refresh annually and for continuous monitoring across the intervening period, with reporting on a monthly cadence.

Methodology transparency

All findings were derived from public and monitored sources only. No portion of this engagement required access to the firm's internal systems, any client tax file, or coordination with any threat actor. This case file documents the pattern of pre-tax-season baseline engagements LeakTrace conducts with Canadian accounting firms, and is not attributed to the specific firm, staff, clients, or filings referenced.