Sherr CPA, LLC, an accounting firm based in Boca Raton, Florida, has notified state regulators and affected individuals of a data security incident involving unauthorized access to a company email account. The exposed information included names, addresses, and Social Security numbers. Companies that handle sensitive financial and identifying information for their clients have a responsibility to safeguard that data from unauthorized access.
Sherr CPA, LLC’s Data Breach Investigation
According to a notice filed with the New Hampshire Attorney General’s Office, Sherr CPA, LLC became aware of suspicious activity involving a company email account on or about April 27, 2026. The firm took prompt steps to secure the affected email tenant and retained third-party forensic specialists to investigate the scope of the intrusion. That investigation determined that an unauthorized individual had accessed a single email account and viewed certain email messages during a roughly one-month window. Sherr then undertook a detailed review of the accessed messages to determine whose personal information was contained within them, a process the firm says was recently completed before notifications went out.
Accounting and tax-preparation firms are frequent targets for this type of attack precisely because their email systems and client files routinely contain some of the most sensitive categories of personal data that exist, including Social Security numbers, financial account details, and government-issued identification. A single compromised email inbox at a firm like Sherr CPA can expose months or years of accumulated client correspondence, tax documents, and identifying records all at once, which is part of what makes email-based intrusions at professional services firms so consequential even when only one account is compromised.
Notification laws like New Hampshire’s RSA 359-C:20 require companies to disclose these incidents to both regulators and affected residents once the scope of an intrusion is understood, and Sherr’s timeline, roughly three months between discovery and formal notice, falls within the range typical of incidents requiring a forensic email review before the specific individuals and data elements affected can be identified with confidence. Individuals whose Social Security numbers are exposed in incidents like this one face an elevated and often long-tailed risk of identity theft, since stolen SSNs can be used to open new lines of credit, file fraudulent tax returns, or impersonate victims in ways that surface months or years after the initial breach.
When Did This Breach Occur?
The unauthorized access to the Sherr CPA email account is reported to have occurred between March 24, 2026, and April 27, 2026. Sherr became aware of the suspicious activity on or about April 27, 2026, and began its forensic investigation immediately. Written notice to the New Hampshire Attorney General and to the affected New Hampshire resident was issued on July 14, 2026.
What Information Was Breached?
Sherr CPA’s notice indicates that the information that could have been subject to unauthorized access includes names, addresses, and Social Security numbers. The firm has not publicly disclosed a total number of individuals affected nationwide; its New Hampshire filing specifically identifies one New Hampshire resident as impacted by this incident.
What You Can Do
Sherr CPA is offering one year of complimentary credit monitoring services through Epiq to individuals whose information was potentially affected. If you received a notification letter from Sherr CPA, LLC, consider taking the following steps:
- Enroll in the complimentary credit monitoring services offered in your notification letter
- Place a fraud alert or credit freeze with Equifax, Experian, and TransUnion
- Request and review a free copy of your credit report from annualcreditreport.com
- Monitor your financial accounts and tax filings closely for unauthorized activity
- Report any suspected identity theft to the FTC and your state Attorney General
File a Data Breach Lawsuit Against Sherr CPA, LLC
If your personal information was exposed in the Sherr CPA, LLC data breach, you may have legal options available to you. Companies entrusted with sensitive financial and identifying information are expected to maintain reasonable safeguards to protect that data, and victims of a breach may be entitled to compensation.
Contact us at Class Action U, where we’ll connect you with a lawyer skilled in class action lawsuits. If you’ve been contacted about this breach, received notice, or discovered you were impacted, fill out our quick, easy, and secure form to sign up. There is no cost to reach out to our legal partner and no obligation after speaking with someone from our team.