TurboTax customer accounts affected by cyberattack

Security Key
(Image credit: Pixabay)

Financial software maker Intuit has notified users of its TurboTax platform that some of their personal and financial information was accessed by attackers in what appears to be a series of account takeover attacks.

"By accessing your account, the unauthorized party may have obtained information contained in a prior year's tax return or your current tax return in progress, such as your name, Social Security number, address(es), date of birth, driver's license number and financial information (e.g., salary and deductions), and information of other individuals contained in the tax return," explained Intuit in the breach notification letter sent to customers.

The company added that it has taken “various measures” to help protect its tax software customer accounts, adding that investigations suggest that the attack was not a "systemic data breach of Intuit."

Poor password hygiene

Intuit suggests that the accounts were compromised as part of an account takeover attack, where cybercriminals use users credentials gleaned from data breaches on other online services. These attacks are the result of users reusing the same login credentials on multiple online services.

The accounts breach came to light during a regular security review, leading to further investigations that revealed the attack had exposed various details about the customers.

As soon as the attack came to light, Intuit temporarily disabled the breached TurboTax accounts. Intuit has also provided a complimentary one year subscription to identity protection services to the affected customers.

Bleeping Computer further reports that TurboTax customers have been targeted in at least three other account takeover attacks in 2014/2015 and most recently in 2019.

Mayank Sharma

With almost two decades of writing and reporting on Linux, Mayank Sharma would like everyone to think he’s TechRadar Pro’s expert on the topic. Of course, he’s just as interested in other computing topics, particularly cybersecurity, cloud, containers, and coding.

Read more
Someone holding a passport with two boarding passes inside it
Top digital loan firm security slip-up puts data of 36 million users at risk
Avast cybersecurity
Zapier tells customers their data may have been accessed
An abstract image of padlocks overlaying a digital background.
BeyondTrust says hackers hit its remote support products
An abstract image of padlocks overlaying a digital background.
Thousands of Bitcoin ATM users may have personal data leaked after breach
Image depicting hands typing on a keyboard, with phishing hooks holding files, passwords and credit cards.
Thousands of Rhode Island citizens have data stolen after social services hit by cyberattack
Hands typing on a keyboard surrounded by security icons
Infostealers on the rise: the latest concern for organizational defenses
Latest in Security
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump
Ai tech, businessman show virtual graphic Global Internet connect Chatgpt Chat with AI, Artificial Intelligence.
Nation-state threats are targeting UK AI research
Scam alert
Fake jobs and phone calls: How Americans lost $12.5 bn to fraud in 2024
Application Security Testing Concept with Digital Magnifying Glass Scanning Applications to Detect Vulnerabilities - AST - Process of Making Apps Resistant to Security Threats - 3D Illustration
Google bug bounty payments hit nearly $12 million in 2024
Scam alert
A new SMS energy scam is using Elon Musk’s face to steal your money
Representational image of a cybercriminal
Allstate sued for exposing personal customer information in plaintext
Latest in News
Garmin Instinct 3 next to the Apple Watch Ultra 2
New figures claim the smartwatch market just shrunk for the first time ever, and the Apple Watch Ultra 3 is to blame
Hitman: World of Assassination on PSVR 2.
Hitman: World of Assassination hits PSVR 2 soon, finally giving you a reason to dust off your headset
A stressed employee looking over some graphs
UK workers are spending more than one day per week tracking down information
Vision Pro Metallica
Apple Vision Pro goes off to never never land with Metallica concert footage
Mufasa is joined by another lion, a monkey and a bird in this promotional image
Mufasa: The Lion King prowls onto Disney+ as it finally gets a streaming release date
An American flag flying outside the US Capitol building against a blue sky
Sean Plankey selected as CISA director by President Trump