HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
INTUIT INC.
bd_5f9e0c0f54d89ed2 · schema v1 · pii pii-v1
Full breach record for INTUIT INC. →Intuit Inc. notified the New Hampshire Attorney General on November 13, 2020, of unauthorized access to a single TurboTax customer account. The unauthorized party accessed the account on or after June 14, 2020, using legitimate credentials obtained from non-Intuit sources. The affected individual's PII, including SSN and financial data, was potentially accessed. Intuit secured the account, notified the IRS, and provided one year of free credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed1 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/intuit-20201113.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Nov 13, 2020
- Raw hash
- 40a2e0e16e65e8caf19da80143aca1ed9926e61de7dfc2bdfd57bac53a77a42f
Reporting entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Victim entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Incident
- Discovered
- Oct 20, 2020
- Materiality determined
- —
- Notification sent
- Nov 13, 2020
- Affected individuals
- 1
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the IRS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.