HackingStolen CredentialsCustomer Data InvolvedTargetedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
INTUIT INC.
bd_7decbbe9513ed870 · schema v1 · pii pii-v1
Full breach record for INTUIT INC. →Intuit Inc. notified the New Hampshire Attorney General on April 13, 2016, regarding unauthorized access to five New Hampshire TurboTax customers' accounts between March 15 and March 18, 2016. Unknown actors used legitimate credentials obtained from external sources (phishing or other breaches) to access in-process or prior year tax returns containing PII, SSNs, and financial data. Intuit contained the accounts, notified law enforcement and the IRS, and offered one year of free credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed5 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/intuit-20160413.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Apr 13, 2016
- Raw hash
- 3b2db6fb6c8595e49394fc1c813d004328efac1351683275cff84d2a8441c882
Reporting entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Victim entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Incident
- Discovered
- Mar 15, 2016
- Materiality determined
- —
- Notification sent
- Apr 13, 2016
- Affected individuals
- 5
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid AccountsT1566.002 Spearphishing Link
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified New Hampshire Attorney General
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 29 days(29 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.