Security & Fraud Awareness

‍ ‍

Chiang & Youngberg LLP

Security & Fraud Awareness

Protecting client information requires both appropriate safeguards and careful communication. Cybercriminals increasingly use phishing, impersonation, fraudulent payment instructions, and other deceptive techniques to target individuals and professional-services firms. The following guidance can help you communicate with Chiang & Youngberg LLP (“CYLLP,” “we,” “us,” “our,” “firm,” or “our firm”) more securely and recognize potentially suspicious activity.

Sending Sensitive Information

Please use our designated Secure Client Portal when transmitting tax documents or other sensitive client information electronically.

  • Submission Restrictions: Do not send sensitive information through our online inquiry form or ordinary email.

  • Sensitive Data Types: This includes Social Security numbers; tax returns, tax documentation; financial account information; passwords, authentication credentials; and credit card data or other payment-card information.

  • When in Doubt: If you are uncertain about how to transmit information to us, please call our office at +1 (408) 244-2002 before sending it.

Recognizing Communications from CYLLP

CYLLP uses email addresses associated with our official domain, (@youngbergcpa.com), for firm communications. However, an email address, display name, logo, signature, or other familiar-looking information should not by itself be treated as proof that a communication is authentic. Email accounts and identities can be impersonated or compromised.

Be cautious if a message claiming to be from CYLLP:

  • Contains unexpected payment or banking instructions.

  • Changes previously provided payment or wiring instructions.

  • Creates unusual urgency, pressure, or strict deadlines.

  • Asks you to provide sensitive information through an unfamiliar method.

  • Requests a password or one-time verification code.

  • Directs you to an unexpected website, attachment, or external login page.

  • Differs from what you normally expect when communicating with our firm.

When in doubt, verify the communication independently before acting on it.

STOP. VERIFY. THEN ACT.

If you receive unexpected or altered payment instructions claiming to be from CYLLP, do not send funds until you have independently verified the instructions by calling us directly at: +1(408) 244-2002.

Payment Fraud Prevention

Fraudulent payment instructions are a significant risk in email and other electronic communications.

  • Verify Unexpected Changes: If payment instructions appear unusual, have changed from instructions you previously received, or arrive unexpectedly, do not make the payment based solely on the message you received. Always verify with our office any unexpected or changed payment instructions before sending funds.

  • Independent Verification: Contact CYLLP independently at +1 (408) 244-2002, using the telephone number published on our official website, and verify the instructions with our office staff.

  • Do Not Trust In-Message Links: Do not use a telephone number, email address, or link contained only within the suspicious communication to perform your verification. For CYLLP’s currently authorized payment methods, please visit our Pay Your Invoice page.

Passwords and Verification Codes

Protect your passwords and multi-factor authentication (MFA) or verification codes.

  • No Disclosure Requests: CYLLP will not ask you to disclose the password to your email, financial, portal, or other personal accounts.

  • One-Time Codes: You should never provide a one-time authentication or verification code in response to an unexpected request. If you receive a message prompting you for an account credential or communication claiming to be from CYLLP that unexpectedly requests a password, or authentication code, do not provide it. Contact our office independently to verify the request.

Links and Attachments

Use extreme caution with unexpected links and attachments, even when a message appears to come from someone you recognize.

  • Check the URL: Before entering credentials into a website reached through an email or text message, verify that you are on our official, intended domain (@youngbergcpa.com).

  • Verification Before Opening: If a purported CYLLP communication contains an unexpected attachment, link, document request, or login prompt and you are uncertain whether it is legitimate, contact our office before clicking, opening it, or entering information.

Secure Client Portal Best Practices

Current clients must use our designated Secure Client Portal for the electronic transmission of tax documents and other sensitive financial files.

  • Access Safety: Access the portal directly through the official Secure Client Portal link hosted on our website (youngbergcpa.com) rather than through an unexpected link received in an unfamiliar communication.

  • Credential Confidentiality: Keep your portal credentials confidential and do not share your password or authentication codes with others.

If Something Doesn’t Look Right

If you receive a suspicious communication claiming to be from Chiang & Youngberg LLP, encounter unexpected payment instructions, or believe a communication or interaction involving our firm may have been compromised:

  1. Do not reply to the suspicious message.

  2. Do not send money or sensitive information.

  3. Do not use contact information supplied only within that suspicious communication.

Instead, contact us independently using our verified information: