Platt, Miller & Jacobs, CPAs, LLP, an accounting firm, has notified clients that an unauthorized user got into an employee’s Microsoft Outlook email account. The firm’s notice says sensitive personal and financial information was accessible to the intruder.
Accounting firms collect Social Security numbers, bank details, and other records that clients cannot easily replace. A firm that keeps that information is responsible for protecting it, including the email accounts where so much of it ends up.
Platt, Miller & Jacobs, CPAs, LLP’s Data Breach Investigation
Platt, Miller & Jacobs, CPAs, LLP sent clients a Notice of Data Breach dated September 28, 2026. A copy appears on the Massachusetts state government’s public list of data breach notification letters and is the main public record of the incident. The copy posted publicly is a template with the recipient name and enrollment details left blank.
According to the notice, the firm discovered on March 11, 2026 that an unauthorized user had gained access to an employee’s Microsoft Outlook email account the day before. The person used the account to send phishing emails to some of the firm’s clients. The notice says the intruder did not reach the firm’s tax return or file storage systems. The firm hired third-party IT specialists to investigate, and says that work has now concluded.
The investigation found that clients’ sensitive personal information was accessible to the unauthorized user. The firm says it has no information showing that the data was misused. It also says it has told the FBI, the IRS, and the Secret Service, and that law enforcement did not ask it to delay the notice. The letter does not say how the account was compromised, how long the intruder had access, or how many clients were affected.
Email account takeovers at accounting practices are a recurring problem, and they are often followed by phishing. Once an attacker controls a real employee mailbox, messages sent from it look trustworthy to clients who expect to hear from their accountant. Clients may be asked to open a link, share documents, or confirm financial details. Anyone who got an unexpected message from the firm in early March 2026 should be cautious about what they clicked or shared.
Accounting email accounts also tend to hold years of attachments, including prior year returns, W-2s, identification scans, and bank statements that clients sent over for tax preparation. That is why the firm’s notice lists a broad set of data types. The gap of roughly six and a half months between the discovery of the incident and the date of the notice reflects the time needed to work out whose information was in the account.
The firm says it has added security measures, increased employee training, and placed stricter limits on system access. It is also offering 18 months of identity monitoring through Kroll at no cost, which includes credit monitoring, fraud consultation, and identity theft restoration. Attorneys are looking into whether the firm had reasonable safeguards in place and what options people affected may have.
When Did This Breach Occur?
The notice says the unauthorized user accessed the employee’s email account on March 10, 2026, and the firm discovered it on March 11, 2026. The notice is dated September 28, 2026, after the investigation concluded.
The letter does not say when the unauthorized access ended. State laws generally require notice without unreasonable delay after an investigation confirms that personal information was involved, and the time between discovery and notice here was about six and a half months.
What Information Was Breached?
The firm says the information that was accessed may include date of birth, Social Security number, address, email address, phone number, financial account information, driver’s license number, state identification number, and other sensitive information that clients may have given the firm.
That combination is especially useful to identity thieves. A name, a Social Security number, and a date of birth are enough to apply for credit, and tax documents can be used to file false returns or to craft convincing phishing messages.
What You Can Do
If you received a notice from Platt, Miller & Jacobs, CPAs, LLP, consider these steps:
- Enroll in the free 18-month Kroll identity monitoring using the membership number on your letter, before the deadline stated in it.
- Place a free security freeze with Equifax, Experian, and TransUnion.
- Request an Identity Protection PIN from the IRS to help prevent a fraudulent tax return from being filed in your name.
- Watch bank and credit card statements closely and report anything you do not recognize.
- Do not click links or open attachments in unexpected emails that appear to come from the firm.
File a Data Breach Lawsuit Against Platt, Miller & Jacobs, CPAs, LLP
People whose Social Security numbers and financial details may have been exposed in a data breach can have legal options, including joining a class action against the company responsible. A class action lets many affected people pursue claims together, without each person paying to bring a case alone.
Attorneys are investigating whether Platt, Miller & Jacobs, CPAs, LLP failed to protect the information entrusted to it. If you got a notice letter, you may be eligible to take part.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.