Larry C. Kent, C.P.A. Data Breach Exposes Client Personal Information

Published: 3 October 2026
Finance data breach illustration
Breach Discovery: Not Publicly DisclosedBreach Notification: October 2026

Larry C. Kent, C.P.A., a Tucson, Arizona accounting firm, began notifying clients in October 2026 about a data security incident that may have exposed personal information. The exact data types and number of people affected have not been publicly disclosed. Affected clients should enroll in the free IDX credit monitoring offered before January 1, 2027, and consider placing a credit freeze.

CompanyLarry C. Kent, C.P.A.
IndustryFinance
Data Types ExposedSocial Security Numbers, Bank Account and Routing Numbers, Income and Employment Records, Prior-Year Tax Returns, Dependent and Family Member Information, Names, Addresses, and Contact Details
People AffectedNot Publicly Disclosed
Attack MethodUnspecified/Unauthorized Access
Regulators NotifiedNot Publicly Disclosed

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

Larry C. Kent, C.P.A. is a Tucson, Arizona accounting and tax preparation firm. In October 2026, the practice began notifying clients about a data security incident involving their personal information. This Larry C. Kent CPA data breach has raised concern among current and former clients who trusted the firm with sensitive financial records.

According to the notice, the firm discovered the incident after what it describes as an extensive internal investigation. However, the filed version of the notice does not state when the intrusion began or when it was first detected. As a result, the exact timeline of this breach has not been publicly disclosed.

The notice was filed with the Massachusetts Attorney General’s office on October 1, 2026. Several sections of the filed document, including the description of compromised data and the length of monitoring services, were left blank. This suggests the firm may still be finalizing certain details even as it begins contacting affected individuals.

Because the practice has not released specifics about the cause of the incident, no one should assume a particular method of attack. Common causes at small professional firms include phishing attacks, compromised remote access credentials, and malware placed on employee workstations. None of these have been confirmed in this case.

The firm’s decision to notify clients, even with incomplete details filled in, suggests it determined that personal information was potentially accessed or exposed. Further information may become available as regulators or the firm release updates.

Who was affected?

The individuals affected by this breach are clients of Larry C. Kent, C.P.A. who used the firm for accounting or tax preparation services. Because the firm handles tax filings, the population could include individuals across multiple states, not just Arizona residents.

The exact number of people affected has not been publicly disclosed. Accounting firms often serve individuals, families, and small businesses, so both personal and business-related information could be involved. It is not yet known whether current clients, former clients, or both received notices.

There is also no public information confirming whether dependents or other family members listed on tax returns could be impacted. Because joint returns and dependent details are common in tax files, the scope of affected people may extend beyond the primary account holder.

What Information Was Potentially Exposed?

The specific categories of information involved in this incident have not been publicly released. The filed notice left this section blank, so the firm has not confirmed exactly which data types were affected.

However, accounting and tax practices typically store a range of sensitive client information. Based on the nature of the business, the following categories are commonly held by firms like this one, though it is not confirmed which applied here:

  • Social Security numbers
  • Bank account and routing numbers
  • Income and employment records
  • Prior-year tax returns
  • Dependent and family member information
  • Names, addresses, and contact details

If any of these categories were involved, affected individuals could face a heightened risk of identity theft. For example, Social Security numbers combined with income details can allow criminals to open new credit accounts or file fraudulent loan applications.

Tax-related fraud is a particular concern for accounting firm clients. Criminals with the right combination of personal details can file a fraudulent tax return and claim a refund before the real taxpayer does. Victims often only discover this when their legitimate return gets rejected by the IRS.

What is the company doing?

Larry C. Kent, C.P.A. began sending written notices to potentially affected clients on October 1, 2026. In the letter, the firm expresses regret over the incident and states that it learned of the issue through an internal investigation.

The firm filed formal notification of this incident with the Massachusetts Attorney General, consistent with state breach notification requirements.

As part of its response, the practice is offering complimentary single-bureau credit monitoring and identity theft protection through IDX. Clients have until January 1, 2027 to enroll using the code provided in their letter.

The firm also established a dedicated call center to answer questions about the incident. According to the notice, this call center will remain available for 90 days from the date of the letter, and a toll-free IDX number is included for client inquiries.

In addition, the notice encourages recipients to place a fraud alert or security freeze on their credit files. It also recommends requesting a free credit report and reviewing account statements regularly for unusual activity.

What Should Affected Individuals Do?

Enroll in Credit Monitoring Promptly

If you received a notice from Larry C. Kent, C.P.A., consider enrolling in the complimentary IDX credit monitoring and identity protection service right away. The enrollment deadline is January 1, 2027, so acting sooner avoids missing the window.

This service can help detect suspicious activity on your credit file before it causes serious damage. Because monitoring only flags activity after enrollment, delaying signup could mean missing early warning signs of fraud.

Place a Fraud Alert or Credit Freeze

Given that accounting firms often store Social Security numbers and financial account details, placing a fraud alert or credit freeze is a smart precaution. A freeze restricts new creditors from accessing your credit file, which makes it harder for criminals to open accounts in your name.

You can request a free credit report at annualcreditreport.com and contact Equifax, Experian, and TransUnion individually to place a freeze. This step is especially important if you believe any financial information was involved in this breach.

Watch for Signs of Tax-Related Identity Theft

Because this incident involves an accounting and tax practice, tax fraud is a specific risk worth watching for. If your tax return gets rejected because one was already filed in your name, that could be a sign your information was misused.

Consider requesting an IRS Identity Protection PIN, which adds an extra layer of verification to future tax filings. This step can help prevent someone else from filing a fraudulent return using your identity.

Monitor Financial Accounts and Watch for Phishing

Review your bank and credit card statements regularly for charges you do not recognize. In addition, be cautious of unexpected emails or calls that reference your accountant, tax documents, or this breach specifically.

Scammers often use real breach events to craft convincing phishing messages. Therefore, avoid clicking links or providing personal information in response to unsolicited messages, even if they appear to come from a trusted source.

Report Suspicious Activity and Seek Legal Guidance

If you notice signs of identity theft or fraud, report it to the Federal Trade Commission and your state Attorney General right away. Keeping records of any fraudulent activity can help support your case later.

Because firms that hold financial and tax records carry a responsibility to protect that data, affected clients may have legal options. Speaking with a data breach attorney can help you understand whether you qualify for compensation.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



Related Data Breaches

View the full list of tracked data breaches →