Forrestall CPAs LLC Data Breach Exposes Personal and Financial Information

Published: 10 September 2026
Finance data breach illustration
Breach Discovery: December 2025Breach Notification: August 2026

Forrestall CPAs LLC discovered that an unauthorized individual accessed and viewed files on its network between December 22 and December 30, 2025, exposing client names along with other personal and financial information. The firm began notifying affected individuals in August 2026. Anyone who received a letter should enroll in the free Epiq identity monitoring service and consider a credit freeze right away.

CompanyForrestall CPAs LLC
IndustryFinance
Data Types ExposedFull Name, Financial Account Information, Tax-Related Information, Social Security Numbers, Other Personal Identifying Details
People AffectedNot Publicly Disclosed
Attack MethodUnauthorized Network Access
Regulators NotifiedCalifornia Attorney General

Were you affected by this breach?

You may be owed compensation.

Data breach victims can recover money for identity-theft losses, out-of-pocket costs, wasted time, and the ongoing risk of fraud — usually with no upfront cost, and no fee unless you win.

Check if you qualify — free review

What Happened in the Forrestall CPAs Data Breach?

Forrestall CPAs LLC has notified affected individuals about a data security incident that exposed personal information stored on its network. The accounting firm discovered that an unauthorized individual gained access to its systems and viewed certain files. This discovery led the company to launch a formal investigation into what happened and how far the intrusion reached.

According to the notification, unauthorized access to its network occurred in December 2025. The intruder viewed and obtained certain files during that window. Forrestall CPAs has not disclosed publicly how the attacker first got in, but the firm treated the event seriously enough to bring in outside help.

As a result, Forrestall CPAs engaged a cybersecurity firm to investigate the scope of the intrusion. The investigation aimed to determine exactly which files were accessed and whose information appeared in them. Once the review concluded, the company began notifying individuals whose data was involved, with notification letters going out in August 2026.

In addition, Forrestall CPAs reported the incident to law enforcement. The firm says it will continue cooperating with any further investigation into the breach. This kind of coordination is common after a confirmed data breach, since law enforcement agencies often track patterns across multiple incidents.

Who was affected?

The notification letters were sent to individuals whose personal information was found in the files the attacker accessed. Because Forrestall CPAs is an accounting firm, those affected are likely clients whose financial and tax-related records were stored on the company’s systems. Some employees may also be included, though the notice does not specify separate categories of affected people.

Forrestall CPAs has not publicly disclosed the total number of individuals affected by this breach. The notification letter was sent to specific individuals whose data appeared in the exposed files. Because accounting firms typically hold sensitive financial documents for a wide range of clients, the population affected could include individuals across different states, not just California residents.

It also remains unclear whether the exposed files included information belonging to minors or dependents, which sometimes appears in tax preparation records. Anyone who received a direct notification letter from Forrestall CPAs should treat it as confirmation that their data was involved. Those who did not receive a letter but were former or current clients during the relevant period may still want to reach out to the firm for clarification.

What Information Was Potentially Exposed?

The notification letter confirms that exposed files included each recipient’s name along with other personal data elements specific to that individual. Because the letter uses a placeholder for the exact data categories, the specific elements vary by recipient. However, given that Forrestall CPAs is an accounting practice, the type of information typically held includes sensitive financial and tax-related details.

  • Full name
  • Financial account information
  • Tax-related information
  • Social Security numbers (where applicable to the client’s file)
  • Other personal identifying details maintained in client records

Because tax and accounting records often contain highly sensitive data, this incident carries real risk for those affected. Social Security numbers combined with financial account details can allow criminals to open new credit lines, file fraudulent tax returns, or access existing accounts. This makes the exposed information more valuable to fraudsters than a simple email or password leak.

In addition, identity thieves often combine stolen personal data with other leaked information from separate breaches. This means the risk does not end once the initial incident is contained. Affected individuals may see fraud attempts months or even years later, which is why long-term vigilance matters as much as the immediate response.

What is the company doing?

After discovering the incident, Forrestall CPAs took immediate steps to secure its systems and stop any further unauthorized access. The firm also brought in a cybersecurity firm to determine the scope of the intrusion and confirm which files were involved. This response reflects a standard forensic process used to contain and evaluate a security incident.

Forrestall CPAs also filed a formal notification with the California Attorney General, as required under state breach notification law. This filing is part of the company’s broader effort to comply with legal notification requirements across the states where affected individuals reside.

To help affected individuals protect themselves, Forrestall CPAs is offering a complimentary one-year membership to identity monitoring services through Epiq’s Privacy Solutions ID program. This service includes three-bureau credit monitoring, dark web monitoring, and identity theft insurance coverage. Enrollment requires an activation code provided in each individual’s letter.

The firm has stated that enrolling in these services will not affect anyone’s credit score. Forrestall CPAs also says it has taken additional measures to strengthen the security of its systems going forward. These steps are meant to reduce the chance of a similar incident happening again.

What Should Affected Individuals Do?

Enroll in the Free Identity Monitoring Service

Affected individuals should take advantage of the complimentary identity monitoring membership offered through Epiq’s Privacy Solutions ID. This service includes credit monitoring, dark web scanning, and identity theft insurance up to $1 million. Because it is free for one year, there is little downside to signing up quickly.

To enroll, individuals need the activation code included in their notification letter. The enrollment window has a deadline, so it helps to act promptly rather than setting the letter aside. Anyone who loses their letter or has enrollment questions can call Epiq’s support line for assistance.

Place a Fraud Alert or Credit Freeze

Because financial and potentially Social Security information was involved, affected individuals should consider placing a fraud alert or credit freeze with the three major credit bureaus. A fraud alert requires lenders to verify identity before opening new credit in your name. A credit freeze goes further by blocking access to your credit file entirely, which can stop most new account fraud before it starts.

Both options are free to set up and can be lifted later when needed, such as when applying for a loan. Given that tax and accounting data may have been exposed, this step provides an extra layer of protection beyond the monitoring service alone. Consumers can request these protections directly through Equifax, Experian, and TransUnion.

Monitor Financial and Tax Accounts Closely

Affected individuals should regularly check bank statements, credit card activity, and any online financial accounts for unfamiliar charges. This is especially important given the accounting-related nature of the exposed data. Because tax records were likely involved, individuals should also watch for signs of tax-related identity theft, such as rejected electronic tax filings.

If a tax return is rejected because one has apparently already been filed under your name, contact the IRS immediately. This can indicate that someone used your stolen information to file a fraudulent return. Reporting it quickly can help limit the financial damage and speed up resolution with tax authorities.

Stay Alert for Phishing Attempts

Scammers often use information from data breaches to craft convincing phishing emails or phone calls. As a result, affected individuals should be cautious of any unexpected messages claiming to be from Forrestall CPAs, Epiq, or financial institutions asking for personal details. Legitimate companies will not ask you to confirm sensitive information through unsolicited emails or texts.

Before clicking any links or providing information, verify the sender through official contact channels. If a message seems urgent or threatening, that is often a sign of a scam. Taking a moment to confirm legitimacy can prevent falling victim to a secondary attack that builds on this breach.

Consider Consulting a Data Breach Attorney

Individuals who received a notification letter may want to speak with an attorney who focuses on data breach cases. An attorney can help explain your rights and whether you may qualify for compensation. Many offer free initial consultations, so there is generally no upfront cost to learn more.

Because breach notification laws vary by state, an attorney can also clarify any deadlines that may apply to your situation. This is especially useful if you experience financial losses connected to this incident. Acting sooner rather than later can help preserve your options.

Get a Free Case Review

Tell us how this breach affected you. A data breach attorney will review your situation at no cost and with no obligation — it takes about two minutes.



More Information

Official data breach notification from California Attorney General

Related Data Breaches

Check other recent data breach notifications →