HackingStolen CredentialsCustomer Data InvolvedIDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNTMediumContained
INTUIT INC.
bd_d864ffff97b97b62 · schema v1 · pii pii-v1
Full breach record for INTUIT INC. →Intuit Inc. notified the New Hampshire Attorney General on September 15, 2016, regarding unauthorized access to two New Hampshire customers' TurboTax accounts. The breach involved the use of legitimate login credentials stolen from non-Intuit sources (credential stuffing/reuse). Affected data included names, SSNs, addresses, DOB, driver's license numbers, and financial information. Intuit contained the incident by temporarily disabling accounts, notified law enforcement and the IRS, and provided one year of free credit monitoring.
Tracked as a single-filing incident — the only disclosure on record for this event so far.Confirmed2 affectedView incident
Source provenance
- Source URL
- https://mm.nh.gov/files/uploads/doj/remote-docs/intuit-20160915.pdf
DisclosureLens links to the originating regulator URL — full filing bodies are not redistributed from public surfaces (§4.5).
- Filed at
- Sep 15, 2016
- Raw hash
- 3a2ebf59e0798a7f2e269bf56a17a3bb885d2a1e2e4d33696feb913aca32424a
Reporting entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Victim entity
- Name
- INTUIT INC.norm: intuit
- Domain
- intuit.com
Incident
- Discovered
- Aug 22, 2016
- Materiality determined
- —
- Notification sent
- —
- Affected individuals
- 2
- Data types
- IDENTITY_GOVERNMENTIDENTITY_BASICFINANCIAL_ACCOUNT
- Attack vector
- Unauthorized Access
- MITRE ATT&CK
- T1078 Valid Accounts
- Threat actor
- ExternalFinancial
- Regulator citations
- Notified the IRS
- Initial access
- valid_credentials
Compliance
- Time to disclose
- 24 days(24 days from discovery to filing)
- Compliance flags
- — (clock not assessable for this source)
Extraction provenance
- Status
- No extraction artifact recorded for this disclosure.