S.01Accounting & CPA firms

Penetration testing for accounting firms and CPA practices.

An accounting firm aggregates the payroll, bank details and tax records of every client it serves, then runs on portals, hosted applications and remote desktops that peak exactly when staff are busiest. Darkmoon tests those systems the way an attacker would and proves which paths lead to client money or client data. Managed end to end by ASC-IT's security experts, with the legal framework included.

72 h
GDPR Art. 33 window to notify a personal-data breach (EU and UK clients)
48 %
of ransomware victims reported to ANSSI in 2025 were SMEs and mid-sized companies, the typical client base of a firm
€799
flat rate per managed engagement
50
specialist AI agents, 142 tools

S.03Professional services
Why accounting firms are attacked for their clients, not themselves.

The firm is the shortcut. Instead of breaching a hundred small companies, an attacker breaches the practice that keeps their books, runs their payroll and knows which supplier gets paid when.

New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Payroll runs are a money movement on a schedule

Every payroll cycle, a firm pushes direct-deposit files built from client employee records. A changed bank account in the payroll portal, submitted a day before the run, is paid out before anyone notices the pay slip went to the wrong account.

$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Invoice fraud rides on the firm's authority

Clients trust an email from their accountant. An attacker inside a bookkeeper's mailbox sends a supplier bank-detail change or an urgent payment instruction that the client approves because it came from the right address, on the right thread.

FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Filing deadlines are the attacker's calendar

Tax season means remote work, temporary staff, document portals full of returns and a team with no time to question a password-reset email. Phishing campaigns against tax preparers are timed to the filing calendar for that reason.

Attack surfaceexposure

Hosted apps and file-transfer tools are shared single points

Application-hosting providers, remote-desktop farms and managed file-transfer appliances serve many firms at once. In August 2025 the Cl0p group exploited a zero-day (CVE-2025-6182) in Oracle E-Business Suite to exfiltrate data from hundreds of companies worldwide, including in France.

S.04Attack surface
Six systems where a practice loses client money or client data.

Darkmoon starts from the identity of your staff and follows every application that trusts it: the portal, the tax software, the payroll run, the file drop.

Client portal
Document-collection and client portals

Where clients upload bank statements, W-2s and identity documents and sign engagement letters: authorization between client accounts, share links, password-reset flows and the e-signature integration.

Tax & e-file
Tax-preparation software and e-file credentials

Desktop or hosted tax-software families, the firm's e-file identifiers and the hosted desktops that run them. Stolen preparer credentials are what fraudulent-return rings look for first.

Payroll SaaS
Payroll platforms and pay-slip portals

Payroll SaaS used on behalf of clients, direct-deposit change workflows, employee self-service portals and the exports that feed banks: the systems that move money on a fixed date.

Email / M365
Email and identity tenant

Microsoft 365 or Google Workspace with MFA gaps, legacy protocols, forwarding rules and OAuth grants to third-party add-ins; the staging ground for invoice fraud.

Remote desktop / hosting
Remote desktops and application-hosting providers

RDS farms, virtual desktops and hosting partners that expose logins to the internet, often with single-factor authentication kept for an older application.

File transfer / bank feeds
File-transfer tools, bank feeds and cloud storage

Managed file-transfer appliances, SFTP drops, bookkeeping SaaS connected to client bank accounts, shared drives full of exports: the places where a single flaw leaks every client at once.

S.05Attack paths

From a tax-season phish to a client's payroll.

The chains we walk in an engagement, each step kept as evidence. Client names, hostnames and credentials are tokenized before anything reaches the model.

01
Portal phish to e-file credentials and client returns

A fake portal notification during filing season captures a preparer's password and a one-time code. The attacker downloads client returns from the portal and tries the same password on the hosted tax software. Darkmoon tests the reset flows, MFA coverage and credential reuse that make this chain work.

How the engine works

S.06What Darkmoon tests
What Darkmoon tests in an accounting-firm engagement.

Fifty specialist agents and 142 tools behind a build-enforced allow-list, on the scope you authorize. Every finding is qualified EXPLOITED, CONFIRMED or UNCONFIRMED with the request, payload or screenshot that proves it.

M365 / RDS
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Identity, email tenant and remote desktops

MFA coverage and bypass paths, legacy protocols, mailbox rules and OAuth grants, exposed remote-desktop and hosting logins, credential reuse between the tenant and hosted applications.

Web / API
$darkmoon run --scope identity
→AS-REP roast · 3 accounts
→Kerberoast · svc_sql cracked
→NTLM relay → DCSync
✓Domain Admin, proven

Client portals, payroll and tax web applications

Authorization between client accounts, document upload and download, password-reset and e-signature flows, payroll self-service portals and the APIs behind the portal and tax-software integrations.

MFT / cloud / AD
Attack surfaceexposure

File transfer, cloud storage and internal paths

Managed file-transfer appliances and SFTP drops, bank-feed and bookkeeping SaaS integrations, shared-drive permissions, Active Directory paths from a hosted desktop to the file server and backups.

S.07How an engagement works

From order to report, in five steps.

A process designed to be simple for the client and rigorous on the security side.

01
Describe your target

A guided form: target type, scope and objectives.

How the engine works

S.08Evidence & reporting
Concrete, actionable deliverables.

Not just an automated scan: a structured, validated and debriefed audit.

ranked
FindingsCVSS
SQL injection9.8
SSRF to metadata9.1
Broken access control8.7
JWT signature bypass7.5
Path traversal6.9

Detailed pentest report

Vulnerabilities ranked by severity, technical evidence, business impact and prioritized remediation guidance.

email + OTP
New engagement
Targetapp.acme.test
Scopeweb · API · cloud
Window5 business days
Flat rate€799

Secure client space

Access by email and OTP code. Contractual documents, report and exchanges centralized, available whenever you need them.

video call
Attack surfaceexposure

Debrief meeting

A video call with an expert to walk through the findings, answer questions and guide you on the fixes.

S.09Where your data goes
Your data stays on your side of the line.

The Privacy Gateway tokenizes every sensitive value (IPs, hostnames, URLs, emails, credentials, internal paths) on your machine before anything reaches the model, and rehydrates it locally. Self-host the whole engine with a local LLM, or let our experts run the managed engagement: in both cases the evidence stays in a space you control.

S.10Regulatory context
Not a NIS2 sector, bound by secrecy, safeguards and client contracts.

Accounting firms are not a sector listed in NIS2 Annex I or II. Their security duties come from professional secrecy, from data-protection and safeguards rules in the countries where they file, and from clients that are themselves regulated.

FTC Safeguards Rule for tax preparers (US)

Tax preparers and other non-bank financial institutions fall under the FTC Safeguards Rule (16 CFR Part 314). It requires a written information security program and, for information systems, either continuous monitoring or annual penetration testing plus vulnerability assessments at least every six months (§314.4(d)(2)). A documented test is a direct input to that program.

GDPR Articles 32 and 33 for EU and UK clients

Where the firm processes personal data of EU or UK residents, Article 32 requires appropriate technical and organisational measures and Article 33 requires breach notification within 72 hours. Payroll and shareholder data of client companies are squarely in scope.

Professional secrecy for French experts-comptables

In France, art. 21 of ordonnance n° 45-2138 binds chartered accountants to professional secrecy under the penalties of art. 226-13 of the Code pénal, alongside anti-money-laundering reporting duties to TRACFIN. Firms in other jurisdictions carry equivalent confidentiality duties under their professional codes.

Clients that are NIS2 entities

A firm serving an essential or important entity may receive supply-chain security requirements under NIS2 Article 21(2)(d): questionnaires, audit clauses, evidence of testing. The directive itself does not list accounting firms. Cyber insurers ask similar questions before quoting.

This section describes the legal context as of October 2026 and is not legal advice: confirm your obligations with counsel and your professional body. Darkmoon does not certify compliance; it produces documented, reproducible findings you can present to partners, insurers, clients or an examiner as part of your evidence base.

S.11Use case
A regional CPA firm preparing its written information security program.

Before the filing season, a CPA firm needs testing evidence for its Safeguards Rule program and an answer for a client that asked about supplier security. It orders a managed engagement on its client portal, the hosted desktop farm that runs its tax software, the payroll platform accounts and the Microsoft 365 tenant. Darkmoon finds a portal that lets any logged-in client enumerate other clients' documents, a hosted-desktop login reachable without a second factor, and a shared mailbox with a forwarding rule nobody created on purpose.

Outcome

Exploited findings with evidence, a debriefed report in the secure client space, a prioritized fix list for the hosting provider, and testing evidence the firm can file with its information security program.

Pentest on Demand
€799/ engagement
  • Full penetration test on the defined scope
  • Legal framework and authorizations included
  • Detailed report with evidence and recommendations
  • Secure client space with OTP access
  • Video debrief meeting with an expert
  • Personalized scoping by our team
S.12Pricing

A clear flat rate, shown upfront.

The price is known before payment. No quote, no surprise. Indicative price, adjusted to the final scope. If the scoping call changes the scope and the price, you are told before anything starts.

Legal framework & authorizations included

S.13Frequently asked
What a CPA firm's managing partner asks first.

Does the FTC Safeguards Rule require a penetration test?

The Safeguards Rule (16 CFR Part 314) requires a written information security program and, for information systems, either continuous monitoring or annual penetration testing plus vulnerability assessments at least every six months (§314.4(d)(2)). A documented engagement with evidence covers the testing side; it does not replace the written program, risk assessment or staff training the rule also expects.

Does NIS2 apply to our accounting firm?

Accounting firms are not a sector listed in NIS2 Annex I or II. The directive reaches a firm indirectly when a client is an essential or important entity and passes supply-chain requirements down under Article 21(2)(d). Your direct duties come from secrecy rules, GDPR Article 32 where it applies and, in the US, the Safeguards Rule.

Can you test during tax season without disrupting the firm?

Yes, within the intervention window agreed at scoping. Most firms schedule the engagement before the peak; when that is not possible, the scope excludes production payroll runs and e-file windows, and the test is read-only on live client data.

Our tax software and desktops are hosted by a provider. What can you test?

What the firm controls: the hosted-desktop logins exposed to the internet and their second factor, the accounts, roles and credential reuse between your email tenant and the hosted tax software, the protection of the e-file identifiers and the exports that leave the hosting environment. The provider's shared infrastructure stays outside the scope unless the provider authorizes it; the scoping call settles who authorizes what.

How much does it cost and how long does it take?

The Pentest on Demand flat rate is €799 per engagement, shown upfront and adjusted to the final scope after the scoping call. The timeline is set in the contractual framework and typically runs a few business days after scoping.

What do we need to provide?

A written authorization for the targets in scope (the legal framework you sign at order time), the URLs, hostnames or network ranges to test, test accounts where authenticated testing matters, and a contact for the scoping call. Our experts confirm the scope and the constraints with you before the engagement starts.

Can we share the report with our insurer, clients or auditors?

Yes. The report is yours. It documents each finding with its evidence, severity and remediation guidance, so it can be handed to a cyber-insurer, a client's procurement team or an auditor as a dated, factual description of what was found. It is evidence, not a certification.

What happens after the report?

You get a prioritised fix list with the evidence for each finding, a debrief call to walk through it, and the option to retest once the fixes are in. Teams that self-host can schedule recurring campaigns (Pro) so the same checks run after each change; the Pro remediation agent can also open sandbox-validated fix pull requests for your developers to review.

S.14Related
Go deeper

S.15Next
Test the firm before the filing season does.

Order a managed engagement on your portal, payroll accounts and hosted desktops, or talk to the team about the scope first.