Forrestall CPAs LLC Data Breach Notice (California Attorney General)
If you are a customer of Forrestall CPAs LLC, here’s what’s now in circulation.
Forrestall CPAs LLC notified California residents of a data breach in a filing reported to the California Attorney General on August 17, 2026. The filing puts the incident itself on December 22, 2025.
If you received a breach notification from Forrestall CPAs LLC, your personal information was included in an incident the firm reported to the California Attorney General. The filing lists personal information as exposed but does not state how many people were affected. No passwords were exposed.
That single fact changes the picture. Because no credentials were part of the exposed data, this is not an account takeover incident. Your Forrestall account itself is not at immediate risk from this breach. What is at risk is the lifelong identity information that accountants routinely hold: names, addresses, Social Security numbers, and tax-related records. These details do not expire. They cannot be reissued like a credit card or password. Once they leave the company’s control, they remain valuable to identity thieves for years or decades.
What the Exposed Personal Information Actually Enables
When a tax preparer’s records are exposed, the combination of your name, address, SSN, and tax data becomes a high-quality identity kit. Fraudsters can use it to file fraudulent tax returns before you do, claim refunds in your name, open credit accounts, apply for government benefits, or create synthetic identities. Because tax data often includes prior-year income details, it can help attackers bypass knowledge-based authentication questions that many banks and agencies still rely on.
The absence of passwords in the exposed dataset is genuinely good news. You do not need to change your password with Forrestall CPAs because of this incident. That particular worry can be set aside. The permanent identifiers that matter most cannot be changed, which is why this exposure carries long-term consequences rather than short-term ones.
The Gap Between Incident and Notification
The California filing does not provide a specific incident date, only that the firm submitted a breach notification. When regulators receive these notices months after an event, it often reflects the time the company spent investigating, confirming what was taken, and preparing notifications. The record does not disclose whether the data was encrypted at rest or whether it was exfiltrated. Those uncertainties remain.
What is certain is that the people whose information was included will be notified directly by the firm, almost always by mail. If you have not received a letter from Forrestall CPAs, it is highly likely your information was not part of this incident. The letter is the definitive answer.
What This Incident Shows About Accounting Firm Data Practices
Tax and accounting firms hold some of the most sensitive personal information that exists: full tax returns, Social Security numbers, bank account details for direct deposit or payment, and sometimes driver’s license copies. Unlike retailers or social networks, these organizations cannot avoid collecting this data. Their business model requires it. Yet the same records that make their services possible also make them attractive targets.
This filing adds to a long pattern of CPA and tax-preparation firms appearing in breach notifications. When personal information leaves through unauthorized access, the root issue is rarely dramatic hacking techniques. It is usually that the data was accessible in the first place to someone who should not have had that level of access. The record itself does not establish how access occurred, only that it did.
Why SSN Exposure Remains Permanent Risk
A Social Security number cannot be replaced the way a compromised credit card can. Once it is public, it stays public. Credit freezes and fraud alerts help, but they are speed bumps, not barriers. Tax-related identity theft is particularly difficult to resolve because the IRS processes returns quickly and victims often discover the fraud only when their own legitimate return is rejected.
Having your tax data exposed alongside your SSN gives fraudsters the exact information needed to impersonate you convincingly to banks, credit agencies, and government offices. This is why the exposure matters more than a typical retail breach that might contain only a name and partial payment information.
The Value That Does Not Degrade
Unlike stolen credit card numbers that lose value within weeks as banks block them, the personal information listed in this filing retains its worth. Names, addresses, dates of birth, and SSNs form the foundation of identity theft schemes that can surface years later. A fraudster does not need to use the data immediately. They can wait until your vigilance has faded.
This is the core reality anyone affected by this breach must accept: the exposure creates a permanent increase in your identity risk profile. You cannot eliminate that risk, but you can manage it more aggressively than you might have before receiving the letter.
Concrete Measures That Match This Specific Exposure
- Place a freeze on your credit reports at Equifax, Experian, and TransUnion. This prevents new accounts from being opened in your name even if someone has all your personal details.
- File your taxes as early as possible each year. Early filers reduce the window during which someone else can submit a fraudulent return using your SSN.
- Review every Explanation of Benefits from health insurers and every tax transcript from the IRS. Unexpected activity is often the first sign that your information is being used.
- Monitor your bank and credit card accounts weekly rather than monthly. Small test charges are a common way thieves validate stolen identity data.
- Respond immediately to any IRS or state tax agency notice. Do not assume it is a mistake if it references returns you did not file.
The notification you received means Forrestall CPAs has confirmed your information was among the records involved. That confirmation is useful because it tells you exactly which risks are now elevated. The absence of password exposure means you can focus your attention on the identity-related consequences rather than account security at this firm.
Most people who read breach notices feel a wave of anxiety followed by uncertainty about what to do first. The clearest action is the credit freeze. It directly blocks the most damaging use of the exposed data. Everything else flows from there. You cannot undo the exposure, but you can make it significantly harder for someone to profit from it.
Report details & sourcing
Related breaches
First Commerce LLC Listed by Pear Ransomware Group
Privately held real estate investment and development company…
Trezor Shipping Data Breach — 13,689 Hardware Wallet Buyers, Home Addresses Included
ShipMonk, a logistics provider used by Trezor, was breached through a vulnerability in the third-par…
Match Group (Tinder, Hinge, OkCupid) Data Breach — January 2026
ShinyHunters claimed responsibility for stealing over 10 million Match Group user records in early 2…