Intuit A.I CyberSecurity Scoring
Intuit
Company Information
Website:https://www.intuit.com/
Employees number:15,386
Number of followers:1,046,740
NAICS:5112
Industry Type:Software Development
Homepage:intuit.com
Intuit Risk Score (AI oriented)
Between 650 and 699
IntuitSoftware Development
Updated:
07/09/2026
07/09/2026
693/1000
Weak
B
Intuit Global Score (TPRM)
xxxx
IntuitSoftware Development
Score locked

IntuitWeak
Current Score
693B (WEAK)
01000
8 incidents
-12 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
702
Cyber Attack
07 Sep 2026 • Intuit
FedEx, Microsoft, Intuit QuickBooks and Google: Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials
Large-Scale Phishing Campaign Abuses Google Services to Bypass Security Controls
690
CRITICAL-12
MICINTFEDGOO1788783925
Large-Scale Phishing Campaign Abuses Google Services to Bypass Security Controls
A sophisticated phishing operation is leveraging trusted Google services including Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics to evade email security defenses and deliver highly personalized credential-harvesting pages. In some cases, the attack also deploys ScreenConnect, a legitimate remote-access tool, to establish persistent access to compromised systems.
### How the Attack Works
The campaign exploits Google’s redirect and tracking infrastructure to mask malicious URLs behind legitimate domains, delaying exposure of the final phishing destination until after initial security scans. Attackers use multiple URL permutations, such as:
- Google Meet’s `linkredirect` endpoint
- Google Search and DoubleClick click-tracking URLs
- Google Custom Search and regional Image Search domains
- Tag Manager debug functionality and Analytics parameters
Victims are lured with brand-impersonation emails mimicking DocuSign, Microsoft, OneDrive, FedEx, Intuit QuickBooks, and government services, exploiting routine business workflows. A key evasion tactic involves URL hash fragments containing the victim’s Base64-encoded email address, which remains hidden from server-side logs and many URL-scanning tools.
After navigating the redirect chain, victims land on attacker-controlled `.vu` domains, compromised sites, or Cloudflare Workers endpoints. Some pages display fake CAPTCHAs or interstitial messages to thwart automated analysis.
### Personalized Phishing Pages & Credential Theft
The phishing kit dynamically customizes pages using the victim’s email address, pulling:
- Company logos (via Clearbit or Google’s favicon service)
- Live screenshots of the target organization’s public website
- Localized interfaces in 16 languages
- Pre-filled email fields and browser tab titles matching the victim’s company
The kit also profiles victims by collecting:
- IP addresses & geolocation data
- Browser fingerprints & language settings
- MX records (to verify corporate email domains and filter out researchers/sandboxes)
### Two Monetization Paths
1. Credential Harvesting
- Fake Microsoft 365 or OneDrive portals capture passwords, with some variants forcing a second password submission before redirecting to the real corporate site.
- Stolen credentials, along with IP, location, and browser details, are exfiltrated to an attacker-controlled Telegram bot.
2. ScreenConnect Deployment
- Fake document-access or identity-verification prompts install ScreenConnect, granting attackers persistent remote access bypassing MFA and password resets.
### Targeted Sectors & Lures
The campaign focuses on manufacturing, government, finance, and non-profits, using lures such as:
- Expired credentials (Microsoft 365)
- FedEx delivery notifications
- QuickBooks payment alerts
- Social Security or voicemail messages
### Known Infrastructure & IOCs
Security researchers have identified multiple malicious domains and endpoints, including:
- `vazquezfleytas[.]com` (credential harvester)
- `zh-l-haixing[.]com` (credential harvester)
- `.vu` domains (e.g., `cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu`)
- Compromised sites (e.g., `odahlzr5lm[.]reliabilityinoperations[.]de`)
- Malicious Cloudflare Workers endpoints
The operation demonstrates how attackers abuse trusted cloud services to bypass security controls while delivering highly convincing, personalized phishing attacks.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
AUGUST 2026
705
JULY 2026
691
JUNE 2026
689
MAY 2026
703
APRIL 2026
704
MARCH 2026
704
FEBRUARY 2026
702
JANUARY 2026
699
DECEMBER 2025
697
NOVEMBER 2025
694
OCTOBER 2025
692
MAY 2025
711
Breach
09 May 2025 • Intuit
Intuit Inc.
Unauthorized Access to TurboTax Account
676
MEDIUM-35
INT241072725
Intuit Inc. reported a potential unauthorized access to a TurboTax account on May 9, 2025. The breach involved an unauthorized party accessing the account using the user's credentials, potentially exposing sensitive information such as Social Security numbers and financial data. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2025
740
Breach
12 Feb 2025 • Intuit
Intuit Inc.
Unauthorized Login to TurboTax Account
704
CRITICAL-36
INT620072825
Intuit Inc. reported a potential unauthorized login to a TurboTax account on February 12, 2025. The unauthorized access may have exposed personal information, including names, Social Security numbers, and financial information, although the exact number of affected individuals is unknown. Intuit has secured the account and is offering one year of free identity protection services through Experian IdentityWorks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
MARCH 2024
753
Breach
05 Mar 2024 • Intuit
Intuit Inc.
Intuit Inc. Data Breach
718
LOW-35
INT411072925
On December 20, 2024, the Maine Office of the Attorney General reported a data breach involving Intuit Inc. that occurred on March 5, 2024. An unauthorized access incident involved one affected individual, with potential exposure of sensitive information from TurboTax accounts. Intuit offered a 12-month membership for Experian IdentityWorks for identity theft protection services.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
DECEMBER 2023
784
Breach
01 Dec 2023 • Intuit
Intuit Inc.
Data Breach at Intuit Inc.
749
MEDIUM-35
INT228072625
On March 15, 2024, the Maine Office of the Attorney General reported a data breach involving Intuit Inc. The breach, which occurred between December 23, 2023, and February 21, 2024, involved unauthorized access to a TurboTax account, potentially compromising the individual's Social Security number. Affected individuals were provided with a 12-month membership to Experian IdentityWorks for identity theft protection.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
JANUARY 2023
809
Breach
01 Jan 2023 • Intuit
Intuit Inc.
Intuit Inc. Account Takeover Incident
774
LOW-35
INT145072725
On September 15, 2023, the Maine Office of the Attorney General reported that Intuit Inc. experienced an account takeover (ATO) incident affecting one individual. The breach occurred between January 2, 2023, and July 26, 2023, resulting in unauthorized access to a TurboTax account, potentially exposing personal information, including driver's license numbers.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2019
817
Breach
01 Feb 2019 • Intuit
Intuit
TurboTax Credential-Stuffing Attack
781
MEDIUM-36
INT41916223
Financial software company Intuit discovered that tax return info was accessed by an unauthorized party after an undisclosed number of TurboTax tax preparation software accounts were breached in a credential-stuffing attack.
Following the discovery of the security breach, Intuit decided to temporarily disable the TurboTax accounts which were breached in the credential stuffing attack.
The company also provides one year of free identity protection, credit monitoring, and Experian Identity Works identity restoration services to customers impacted by the data breach to further protect their TurboTax accounts.
The company stated that there was no data breach of Intuit’s systems or any third party accessing Intuit systems.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2014
825
Breach
01 Feb 2014 • Intuit
Intuit
Intuit TurboTax Unauthorized Account Access (2015)
793
CRITICAL-32
INT546091725
The California Office of the Attorney General disclosed a data breach affecting Intuit’s TurboTax platform in April 2015. Unauthorized actors gained access to user accounts between February 1, 2014, and February 27, 2015, potentially compromising prior-year tax return information. While the exact number of affected individuals remains undisclosed, the breach exposed sensitive financial data, including tax filings, which could enable identity theft, fraudulent tax submissions, or financial exploitation. The incident highlighted vulnerabilities in account security, raising concerns over the protection of user data within tax preparation services. Intuit did not confirm whether the breach resulted in direct financial losses for users, but the exposure of tax-related data poses significant risks to personal and financial security.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for Intuit ??
What was Intuit's A.I Rankiteo Cyber Score in August 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in July 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in June 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in May 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in April 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in March 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in February 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in January 2026 ??
What was Intuit's A.I Rankiteo Cyber Score in December 2025 ??
What was Intuit's A.I Rankiteo Cyber Score in November 2025 ??
What was Intuit's A.I Rankiteo Cyber Score in October 2025 ??
What is the average per-incident point impact on Intuit's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with Intuit ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view Intuit's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?