HackingTechnologyFinancial ServicesInformationStolen CredentialsCustomer Data InvolvedData ExfiltratedCREDENTIALSPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNTMediumContained
Taxact, Inc.
bd_0ce5abb02c7ee516 · schema v1 · pii pii-v1
Full breach record for Taxact, Inc. →TaxAct (operated by Blucora, Inc.) experienced unauthorized account access between November 10 and December 4, 2015, in which an external third party used stolen credential combinations sourced outside TaxAct's systems to access user accounts. Affected accounts may have had tax returns opened or printed, potentially exposing names, SSNs, addresses, driver's license numbers, and bank account information. Accounts were disabled and credit monitoring was offered.
Tracked as a single-filing incident — the only disclosure on record for this event so far.ConfirmedView incident
Source provenance
- Source URL
- https://oag.ca.gov/ecrime/databreach/reports/sb24-59569
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Jan 12, 2016
- Raw hash
- 5f0cfe60ae00f8bdb098e5ce048a0c146ba5c628a6732429878009d4dda32597
Reporting entity
- Name
- Blucora, Inc. (TaxAct)norm: blucora inc taxact
Victim entity
- Name
- Taxact, Inc.norm: taxact
- Industry
- TechnologyllmFinancial Servicesllm
Incident
- Discovered
- —
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- Not disclosed
- Data types
- CREDENTIALSPIIIDENTITY_BASICIDENTITY_GOVERNMENTFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1110.004 Credential Stuffing
- Threat actor
- ExternalFinancial
- Regulator citations
- Working with the IRS and state regulators to identify new security measuresNotified California Attorney General
- Initial access
- valid_credentials
Compliance
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.