Forrestall CPAs data breach: what we know and who it may affect
If you have an account with Forrestall CPAs, here’s what’s now in circulation.
An Atlanta-area accounting firm has confirmed that someone got into its systems in late December 2025 and copied files that included people's names and other personal information. Letters started going out in August 2026. The firm has not said how many people are involved or exactly what else was in those files.
Forrestall CPAs customer?
See what’s already exposed about you — free, 15sWe check your email against known public breach records and the sites that publish your address, then show you what to do about each one. We don’t hold this company’s data. No account, no card.
Forrestall CPAs LLC, an accounting firm in Sugar Hill, Georgia that serves the Buford and metro Atlanta area, confirmed that an unauthorized person got into some of its systems and both viewed and copied files between December 22 and December 30, 2025. The firm says it secured those systems, hired a cybersecurity company to investigate, and then reviewed the files that were taken.
Written notices to people who may be affected started going out on August 7, 2026. The company also filed a sample letter with the California attorney general, a step required when more than 500 California residents are involved. It is offering free identity monitoring through a company called Epiq. Forrestall says it has not seen evidence that anyone has used the files for fraud or identity theft. It has not released a total number of people, and it has not listed the exact types of information beyond a name plus other details.
What the calm wording is leaving out
Every public account of this incident follows the firm's script: the systems are locked down, there is no sign of fraud, and free monitoring is available. That is all true as far as it goes. It is also the least useful way to read what happened if you ever used this firm, worked for a business it handled, or had your records sitting in a spouse's or parent's file there.
This was not a store's customer list. It was an accounting firm's network. The only reason those files exist is that people sent in the documents needed to prepare taxes and keep books. After months of review, Forrestall will still only describe what left as a person's name and “other” information. It has not said Social Security numbers were included. It has not said they were not. It has not said whether tax returns, bank figures, or employer records were in the pile. That silence is not comfort. It is the company choosing not to tell you what the other person now holds.
Advertisement
BATECH StudioWe build it.We run it.Web apps, AI pipelines and internal tools — under your brand, not ours.Tell us what you need →
BATECH Studio and GalaxyWarden share common ownership.
Someone had more than a week on the network and took copies. The firm says the police did not ask it to wait before writing to people, so the gap from late December to August was investigation and file review. If a letter reaches you, that is the only official yes you will get. There is no public list of names, and no one can honestly look you up and tell you that you were or were not in this incident.
The line about “no reports of fraud” means the firm has not been told of any. Trouble from an accountant's files often does not show up as a strange charge on a card. It shows up later as a tax return you did not file, a refund that never arrived, or a loan you never applied for.
What to actually expect
- If this firm ever had your information, watch the mail for a letter dated around or after August 7, 2026. No letter is not proof you were left out. They wrote only to people they could tie to the files they reviewed, and mail is uneven.
- The letter is supposed to include a way to enroll in free monitoring with Epiq. Different state copies of the letter have described that coverage as one year in some places and two years in others. Use the dates and code printed in your own letter, not someone else's summary.
- Do not wait for a follow-up that names the exact documents taken. The public notices stop at “name and other information,” and nothing so far suggests a more detailed inventory is coming.
- In the coming tax season, a rejected electronic filing, an IRS notice you did not expect, or a return submitted in your name would be more in character for this kind of incident than a random store charge. The firm's “no fraud so far” statement does not cover what has not surfaced yet.
What you can and cannot fix
If your name and whatever else sat in those files were copied in December 2025, that copy is not coming back. It cannot be deleted from the person who took it, and no service can recall it. Monitoring does not put the file back. It only watches for some of the ways it might be used.
- Enroll in the Epiq monitoring if a letter arrives. It is the one remedy the firm is paying for. Do it even if you distrust these offers. Free coverage you actually turn on is better than a code that expires unused.
- Treat this as a tax-and-credit problem, not a card-fraud problem. Get your free credit reports. If you file U.S. taxes, set up or check an IRS online account and consider an IRS Identity Protection PIN so someone else cannot file a return in your name. A credit freeze at all three bureaus is free and blocks most new accounts; a “lock” sold by a bureau is not the same thing.
- Assume the copy still exists a year from now. Identity theft from tax files is often slow. Keep the letter. Keep using the monitoring for the full term they gave you. Check back around filing season even if nothing has happened yet.
- Shrink the public trail that makes a leaked record usable. A name and a few fields from an accountant's file become much more dangerous when they are stitched to people-search listings that already publish your relatives, phone numbers, employers, and old addresses. Those listings, unlike the stolen files, can actually be taken down. Removing them will not undo the breach. It will make it harder for whoever has the file to turn a bare record into a working impersonation.
What the free scan actually returns
Found on people-search siteswe remove these
These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.
Found in breach recordsverifiedreported — unverified
Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.
Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.
Report details & sourcing
Related breaches
Lennar Mortgage data breach 2026: What was exposed and what you should do
Lennar Mortgage has confirmed that an unauthorized party accessed some of its systems in late May 20…
Navia Benefits Administration Breach — March 2026
2.7 million individuals had names, SSNs, DOBs, contact information, and benefits administration data…
PayPal SSN Exposure Lasting Six Months — February 2026
A code change at PayPal allowed unauthorized access to Social Security Numbers and account details f…