INTUIT INC.
bd_2f24be44c14a5cef · schema v1 · pii pii-v1
Full breach record for INTUIT INC. →Intuit Inc. notified the New Hampshire Attorney General on March 17, 2017, of a security incident involving unauthorized access to 10 New Hampshire customers' TurboTax accounts. The unauthorized access occurred between February 28, 2017, and March 6, 2017, using legitimate credentials stolen from non-Intuit sources. Affected data included names, Social Security numbers, addresses, dates of birth, driver's license numbers, and financial information. Intuit secured the accounts, notified the IRS, and offered one year of free credit monitoring and identity protection services to affected customers.
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/intuit-20170317.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Mar 17, 2017
- Raw hash
- c69dc134dc0b878b52609f945a121222f03a7e1e8a66a492f8d1c1793b8efb6d
Reporting entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Victim entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Incident
- Discovered
- Mar 6, 2017
- Materiality determined
- —
- Notification sent
- Mar 17, 2017
- Affected individuals
- 10
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified Attorney General Joseph A. Foster of New HampshireNotified the IRS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 11 days(11 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.