Back to Blog
high severity August 18, 2026 · 5 min read

Forrestall CPAs data breach: what we know and who it may affect

If you have an account with Forrestall CPAs, here’s what’s now in circulation.

An Atlanta-area accounting firm has confirmed that someone got into its systems in late December 2025 and copied files that included people's names and other personal information. Letters started going out in August 2026. The firm has not said how many people are involved or exactly what else was in those files.

Forrestall CPAs data breach: what we know and who it may affect

Forrestall CPAs LLC, an accounting firm in Sugar Hill, Georgia that serves the Buford and metro Atlanta area, confirmed that an unauthorized person got into some of its systems and both viewed and copied files between December 22 and December 30, 2025. The firm says it secured those systems, hired a cybersecurity company to investigate, and then reviewed the files that were taken.

Already exposed?
You can’t unleak a breach. You can take away what it’s worth.
Deep Sweep shows you every leak tied to you and exactly what to change. Then it strips your name, address and family off the look-up sites that turn a leaked record into somebody knocking on your door — $29 one-time, includes 30 days of Protection. We write to 582 companies. No subscription to start.
Scan free, then Deep Sweep — $29 →
Not ready yet? Run a free breach check on this email
We’ll check it against 13.1B+ leaked records right now — no account needed. Continuous monitoring & alerts are part of Protection.

Written notices to people who may be affected started going out on August 7, 2026. The company also filed a sample letter with the California attorney general, a step required when more than 500 California residents are involved. It is offering free identity monitoring through a company called Epiq. Forrestall says it has not seen evidence that anyone has used the files for fraud or identity theft. It has not released a total number of people, and it has not listed the exact types of information beyond a name plus other details.

What the calm wording is leaving out

Every public account of this incident follows the firm's script: the systems are locked down, there is no sign of fraud, and free monitoring is available. That is all true as far as it goes. It is also the least useful way to read what happened if you ever used this firm, worked for a business it handled, or had your records sitting in a spouse's or parent's file there.

This was not a store's customer list. It was an accounting firm's network. The only reason those files exist is that people sent in the documents needed to prepare taxes and keep books. After months of review, Forrestall will still only describe what left as a person's name and “other” information. It has not said Social Security numbers were included. It has not said they were not. It has not said whether tax returns, bank figures, or employer records were in the pile. That silence is not comfort. It is the company choosing not to tell you what the other person now holds.

Someone had more than a week on the network and took copies. The firm says the police did not ask it to wait before writing to people, so the gap from late December to August was investigation and file review. If a letter reaches you, that is the only official yes you will get. There is no public list of names, and no one can honestly look you up and tell you that you were or were not in this incident.

The line about “no reports of fraud” means the firm has not been told of any. Trouble from an accountant's files often does not show up as a strange charge on a card. It shows up later as a tax return you did not file, a refund that never arrived, or a loan you never applied for.

What to actually expect

  • If this firm ever had your information, watch the mail for a letter dated around or after August 7, 2026. No letter is not proof you were left out. They wrote only to people they could tie to the files they reviewed, and mail is uneven.
  • The letter is supposed to include a way to enroll in free monitoring with Epiq. Different state copies of the letter have described that coverage as one year in some places and two years in others. Use the dates and code printed in your own letter, not someone else's summary.
  • Do not wait for a follow-up that names the exact documents taken. The public notices stop at “name and other information,” and nothing so far suggests a more detailed inventory is coming.
  • In the coming tax season, a rejected electronic filing, an IRS notice you did not expect, or a return submitted in your name would be more in character for this kind of incident than a random store charge. The firm's “no fraud so far” statement does not cover what has not surfaced yet.

What you can and cannot fix

If your name and whatever else sat in those files were copied in December 2025, that copy is not coming back. It cannot be deleted from the person who took it, and no service can recall it. Monitoring does not put the file back. It only watches for some of the ways it might be used.

  • Enroll in the Epiq monitoring if a letter arrives. It is the one remedy the firm is paying for. Do it even if you distrust these offers. Free coverage you actually turn on is better than a code that expires unused.
  • Treat this as a tax-and-credit problem, not a card-fraud problem. Get your free credit reports. If you file U.S. taxes, set up or check an IRS online account and consider an IRS Identity Protection PIN so someone else cannot file a return in your name. A credit freeze at all three bureaus is free and blocks most new accounts; a “lock” sold by a bureau is not the same thing.
  • Assume the copy still exists a year from now. Identity theft from tax files is often slow. Keep the letter. Keep using the monitoring for the full term they gave you. Check back around filing season even if nothing has happened yet.
  • Shrink the public trail that makes a leaked record usable. A name and a few fields from an accountant's file become much more dangerous when they are stitched to people-search listings that already publish your relatives, phone numbers, employers, and old addresses. Those listings, unlike the stolen files, can actually be taken down. Removing them will not undo the breach. It will make it harder for whoever has the file to turn a bare record into a working impersonation.

What the free scan actually returns

Sample resultyou@email.comIllustrative — not a real person

Found on people-search siteswe remove these

These listings are live, public, and legal to remove. That’s what a Deep Sweep buys.

value redacted in this sampleage, relatives, address historySpokeo
value redacted in this samplephone, household, property recordsBeenVerified
value redacted in this sample582 companies checked

Found in breach recordsverifiedreported — unverified

Each record is labeled: confirmed breach data, or an attacker’s claim no one has verified.

verifiedvalue redacted in this samplepassword + phone · 2024telecom breach
unverifiedvalue redacted in this sampleclaimed in ransomware listing · 2026leak-site claim

Leaked data cannot be deleted from the internet — anyone claiming otherwise is lying. Broker listings can be removed. We do the second, and show you exactly what to fix from the first.

Check your exposure
Forrestall CPAs is one breach. Your email is probably in others.
We can’t confirm any single incident against the sources we search, so we won’t pretend to. What we can show you is your own exposure — your email against 13.1B+ leaked records and the sites that publish your address. About 15 seconds. No account, no card.

By running your scan you agree to the Terms and Conditions and the Privacy Policy, and to GalaxyWarden emailing you the results of this scan.

Report details & sourcing

Severity High
Disclosed August 18, 2026
Affected Unconfirmed
Data exposed Full namesunspecified additional personal data
Editorial & sourcing policy
GalaxyWarden is a breach-monitoring service and news aggregator. We do not exfiltrate, host, purchase, or redistribute stolen data. Breach information is compiled from publicly accessible sources and threat-intelligence platforms, and is reported as claims attributed to their source. We promptly correct or remove material shown to be inaccurate — see our content & takedown policy or write to support@galaxywarden.com.
Share this Post on X Reddit Email