A dastardly new phishing scam is targeting tax software users

Person Doing Taxes
(Image credit: Shutterstock) (Image credit: Shutterstock)

QuickBooks users are being attacked by an unknown threat actor phishing for sensitive personal information, the software’s maker has warned. 

According to a BleepingComputer report, a number of users reached out to Intuit, the maker of the tax software, and alerted the company to a phishing email campaign that tries to scare people into giving away sensitive information. Subsequently, Intuit issued a warning to all users, detailing the campaign.

Apparently, victims will receive an email pretending to be from Intuit, which warns that the company has conducted an account review has not been able to verify some important information.

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022end of this survey

Share your thoughts on Cybersecurity and get a free copy of the Hacker's Manual 2022. Help us find how businesses are preparing for the post-Covid world and the implications of these activities on their cybersecurity plans. Enter your email at the end of this survey to get the bookazine, worth $10.99/£10.99.

For that reason, the email claims, the account has been put on hold until the information can be verified. As you might expect, the email comes with a “Complete Verification” button, which appears to serve up a data verification form.

Defending from phishing

In reality, the button likely redirects the victim to a phishing landing page, where any and all data submitted is transferred directly to the attackers.

As usual, QuickBooks users are advised not to open any links or run any email attachments coming from unverified sources. Any such emails that they receive should be deleted immediately, while those that have already opened up the emails should delete any files they might have downloaded, scan their systems with antivirus software and change their QuickBooks passwords.

Phishing attacks are a common occurrence, but can usually be spotted relatively easily. The domain from which the email is sent is usually not the same domain the legitimate company uses, and sometimes, the company’s name is misspelled or features a substitute character (a zero instead of the letter o, for example). 

Given that people are often reckless, overworked or hasty, phishing campaigns are regularly quite successful.

Via BleepingComputer

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
Smartphone with new logo X twitter app background. Application twitter old blue bird change X black and white new.
Phishing campaign targets prominent X users, accounts at risk
Fraude en ligne phishing
What is phishing and how dangerous is it?
Representational image of a hacker
Email scams vs Phishing - is there a difference?
A fish hook is lying across a computer keyboard, representing a phishing attack on a computer system
Everything you need to know about phishing
Fraude en ligne phishing
Google forced to step up phishing defenses following ‘most sophisticated attack’ it has ever seen
unblock facebook with vpn
A new Facebook phishing campaign looks to trick you with emails sent from Salesforce
Latest in Security
healthcare
Software bug meant NHS information was potentially “vulnerable to hackers”
A hacker wearing a hoodie sitting at a computer, his face hidden.
Experts warn this critical PHP vulnerability could be set to become a global problem
botnet
YouTubers targeted by blackmail campaign to promote malware on their channels
A close-up of a phone screen showing the Telegram, Signal and WhatsApp apps
Agentic AI has “profound” issues with security and privacy, Signal President says
botnet
Another top security camera maker is seeing devices hijacked into botnet
Bluetooth
Top Bluetooth chip security flaw could put a billion devices at risk worldwide
Latest in News
Homepage of Manus, a new Chinese artificial intelligence agent capable of handling complex, real-world tasks, is seen on the screen of an iPhone.
Manus AI may be the new DeepSeek, but initial users report problems
Google Maps
Nightmare Google Maps glitch is deleting timelines, and there isn't a fix yet
Twitter social media application change logo to X. Elon Musk CEO of twitter rebranded Twitter to 'X'. Social media application technology concept.
X is down again – Elon Musk confirms 'massive cyberattack' as former Twitter site hit by fourth outage today
Joe Goldberg and Kate Lockwood sitting at a table and looking at the camera in You season 5.
Netflix releases a killer new trailer for You season 5 but my favorite character is missing from Joe's final chapter
Person using Dyson V8 vacuum
Dyson vacuums have one big problem and I don't understand why
A laptop on a desk with the Windows 11 background on its screen.
Microsoft is adding image editing and compression to its Windows Share feature - and I couldn't be happier