Were you recently affected by a data breach?

Langwasser & Company CPAs Data Breach

Langwasser & Company CPAs, an Upland, California accounting firm, disclosed that unauthorized tax returns were filed using client information after a security incident, and notified the IRS and affected clients while investigating the full scope of the exposure.

Langwasser & Company CPAs
Date of Breach: Discovered on or around May 5, 2026
CAU logo

Who was affected:

Clients of Langwasser & Company CPAs

Impacted Data:

Not publicly disclosed by the company; the firm’s cybersecurity specialists could not confirm the full scope of information accessed

Langwasser & Company CPAs, an accounting and tax preparation firm based in Upland, California, has notified clients of a security incident after learning that unauthorized tax returns were filed using information the firm maintained on their behalf. Because tax preparers routinely hold some of the most sensitive financial and identifying information their clients possess, an incident like this raises real concerns even before every detail is confirmed, and companies entrusted with that data carry a corresponding responsibility to safeguard it and to be transparent when something goes wrong.

Langwasser & Company CPAs’s Data Breach Investigation

According to a notification letter filed with the California Attorney General, Langwasser & Company CPAs learned on or around May 5, 2026 that a limited number of unauthorized tax returns had been filed using client information the firm maintained. The firm states that clients directly affected by the fraudulent filings have already been contacted individually. Upon discovering the issue, Langwasser & Company CPAs immediately notified the Internal Revenue Service and began working with outside cybersecurity professionals experienced in handling this type of incident to investigate further.

Following that investigation and an extensive review of the firm’s files, Langwasser & Company CPAs determined that an unauthorized actor may have had access to additional personal information beyond what was used in the fraudulent filings themselves, though the firm’s cybersecurity specialists were unable to confirm the full extent of what was actually accessed or acquired. That kind of uncertainty is common in the early aftermath of a security incident, particularly one involving unauthorized tax filings, where investigators must reconstruct what happened after the fact using system logs and forensic evidence rather than a complete real-time record of every file an intruder touched.

Accounting and tax-preparation firms are attractive targets for cybercriminals precisely because of what they store: Social Security numbers, dates of birth, bank account and routing numbers, prior-year tax returns, and other information that can be used to file fraudulent returns, open new lines of credit, or otherwise commit identity theft. An unauthorized tax return filing, as described in this incident, is itself one of the more direct and immediate ways that stolen identifying information gets monetized, since a fraudulent refund can sometimes be claimed before the legitimate taxpayer ever files their own return. This is also why the IRS maintains dedicated processes, including the Identity Protection PIN program, specifically to help taxpayers who have been affected by this kind of fraud.

Notification timelines for incidents like this one often unfold in stages: an initial letter goes out once a firm has confirmed that at least some clients were affected and has a baseline understanding of what occurred, even while the deeper forensic investigation into the full scope of accessed data continues in parallel. Clients who receive an initial notice should not assume the situation is fully resolved or fully understood at the time the letter arrives, and should take the recommended precautions seriously even if the letter does not yet specify every detail of what was exposed.

When Did This Breach Occur?

Langwasser & Company CPAs states that it learned of the unauthorized tax return filings on or around May 5, 2026. The firm has not publicly disclosed additional detail about when any unauthorized access to its systems may have first begun or how long it may have gone undetected before discovery. Affected clients were notified beginning around the same period after the firm completed its initial investigation and engaged outside cybersecurity assistance.

What Information Was Breached?

Langwasser & Company CPAs has stated that its cybersecurity specialists were unable to confirm the full extent of the information an unauthorized actor may have accessed. The firm’s notification letter indicates that the files at issue included each recipient’s name in combination with certain other personal data elements specific to that individual, without publicly specifying a single universal list of data types for all affected clients. Because the firm is a tax preparation and accounting practice, the types of information it typically maintains for clients can include Social Security numbers, dates of birth, and financial account details, though Langwasser & Company CPAs has not confirmed that these specific categories were involved in this particular incident.

What You Can Do

  • Enroll in the complimentary Experian IdentityWorks membership offered in the notification letter.
  • Consider applying for an IRS Identity Protection PIN, which can help prevent fraudulent tax filings in your name going forward.
  • Place a fraud alert or security freeze on your credit files with Equifax, Experian, and TransUnion.
  • Request a free credit report from each of the three major credit bureaus and review it for unfamiliar accounts or inquiries.
  • Monitor your accounts and any IRS correspondence closely for signs of continued fraudulent activity.

File a Data Breach Lawsuit Against Langwasser & Company CPAs

If you received a notice from Langwasser & Company CPAs about this incident, or if you have discovered that a fraudulent tax return was filed in your name, you may have legal options available to you.

Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.

Were you recently affected by a data breach?
Other Data Breaches
Date of Breach: December 22, 2025 to December 30, 2025
Date of Breach: Discovered on or around May 5, 2026
Date of Breach: Not publicly disclosed
Related News

Frequently Asked Questions

A data breach occurs when sensitive, confidential, or protected information is accessed, stolen, or disclosed without authorization. Data breaches often occur through phishing emails, malware, weak passwords, insider threats, or unsecured databases. Indicators of a data breach can include unexpected password resets, suspicious account activity, unauthorized transactions, or notifications from companies about compromised information.If you suspect your data has been compromised, you must take measures and act quickly. Change passwords, enable two-factor authentication, review your financial accounts for unusual activity and consider freezing your credit.

Once stolen, your personal information may be sold on the dark web or used for identity theft and financial fraud. In some cases, hackers use the data to extort companies or launch further attacks. Victims often face long-term risks, including damage to credit and privacy.

If you receive a data breach notification, don’t ignore it. Immediately change passwords for the affected account and any others that share credentials. Enroll in any free credit monitoring services offered and monitor financial statements closely.

To pursue a data breach claim, you’ll need documentation showing your information was compromised and proof of resulting harm, such as fraudulent charges, credit score damage, or identity theft reports. Notification letters, financial records, and communication with the breached company can help support your claim.

Yes. If a company fails to protect consumer data or delays notifying victims, it may be held liable under state and federal privacy laws. Many victims join class action lawsuits to recover financial losses and hold negligent organizations accountable.

Data breach settlements vary widely depending on the size of the breach, type of data compromised, and damages suffered by victims. Payouts may include cash compensation, identity theft protection, or reimbursement for losses. Many settlements range from a few hundred to several thousand dollars per person. A skilled data breach lawyer can guide victims through the complex legal process, ensuring their rights are protected. If you’ve received a data breach notification or believe your personal data was exposed, you may be eligible for compensation. Contact Class Action U to learn more about how to join a data breach lawsuit and understand the process of filing.