Rankiteo Logo
Rankiteo
Leader in Cyber Underwriting
Loading...
NEWRankiteo Cyber Underwriting Desktop - Score, price, and bind from your desktop
WindowsmacOSLinux
Download
Intuit

Intuit Vendor Cyber Rating & Cyber Score

intuit.com

Intuit is a global technology platform that helps our customers and communities overcome their most important financial challenges. Serving millions of customers worldwide with TurboTax, QuickBooks, Credit Karma and Mailchimp, we believe that everyone should have the opportunity to prosper and we work tirelessly to find new, innovative ways to deliver on this belief. We encourage conversations on this page and will not delete comments that follow our terms of use. In order to keep this a safe community, the below posts may be removed: Repeated posts of the same content, spam or posts from fake accounts or profiles, offensive language or material, threats to others in the community, posts deliberately aimed to have a negative effect on the


Intuit A.I CyberSecurity Scoring

Intuit
Company Information
Website:https://www.intuit.com/
Employees number:15,386
Number of followers:1,046,740
NAICS:5112
Industry Type:Software Development
Homepage:intuit.com
Intuit Risk Score (AI oriented)
Between 650 and 699
logo
IntuitSoftware Development
Updated:
07/09/2026
693/1000
Weak
B
AaaAaABaaBaBCaaCaC
Powered by our proprietary A.I cyber incident model
Insurance prefers TPRM score to calculate premium
Intuit Global Score (TPRM)
xxxx
logo
IntuitSoftware Development
•••
Score locked
Instant access to detailed risk factors
Vulnerabilities
Benchmark vs. industry & size peers
Findings

IntuitWeak
Current Score
693B (WEAK)
01000
8 incidents
-12 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
SEPTEMBER 2026
702Before Incident
Cyber Attack
07 Sep 2026Intuit
FedEx, Microsoft, Intuit QuickBooks and Google: Global Phishing Campaign Abuses Google Infrastructure to Evade Security and Steal Credentials

Large-Scale Phishing Campaign Abuses Google Services to Bypass Security Controls

690After Incident
CRITICAL-12
MICINTFEDGOO1788783925
Large-Scale Phishing Campaign Abuses Google Services to Bypass Security Controls A sophisticated phishing operation is leveraging trusted Google services including Google Meet, Search, DoubleClick, Custom Search, Image Search, Tag Manager, and Analytics to evade email security defenses and deliver highly personalized credential-harvesting pages. In some cases, the attack also deploys ScreenConnect, a legitimate remote-access tool, to establish persistent access to compromised systems. ### How the Attack Works The campaign exploits Google’s redirect and tracking infrastructure to mask malicious URLs behind legitimate domains, delaying exposure of the final phishing destination until after initial security scans. Attackers use multiple URL permutations, such as: - Google Meet’s `linkredirect` endpoint - Google Search and DoubleClick click-tracking URLs - Google Custom Search and regional Image Search domains - Tag Manager debug functionality and Analytics parameters Victims are lured with brand-impersonation emails mimicking DocuSign, Microsoft, OneDrive, FedEx, Intuit QuickBooks, and government services, exploiting routine business workflows. A key evasion tactic involves URL hash fragments containing the victim’s Base64-encoded email address, which remains hidden from server-side logs and many URL-scanning tools. After navigating the redirect chain, victims land on attacker-controlled `.vu` domains, compromised sites, or Cloudflare Workers endpoints. Some pages display fake CAPTCHAs or interstitial messages to thwart automated analysis. ### Personalized Phishing Pages & Credential Theft The phishing kit dynamically customizes pages using the victim’s email address, pulling: - Company logos (via Clearbit or Google’s favicon service) - Live screenshots of the target organization’s public website - Localized interfaces in 16 languages - Pre-filled email fields and browser tab titles matching the victim’s company The kit also profiles victims by collecting: - IP addresses & geolocation data - Browser fingerprints & language settings - MX records (to verify corporate email domains and filter out researchers/sandboxes) ### Two Monetization Paths 1. Credential Harvesting - Fake Microsoft 365 or OneDrive portals capture passwords, with some variants forcing a second password submission before redirecting to the real corporate site. - Stolen credentials, along with IP, location, and browser details, are exfiltrated to an attacker-controlled Telegram bot. 2. ScreenConnect Deployment - Fake document-access or identity-verification prompts install ScreenConnect, granting attackers persistent remote access bypassing MFA and password resets. ### Targeted Sectors & Lures The campaign focuses on manufacturing, government, finance, and non-profits, using lures such as: - Expired credentials (Microsoft 365) - FedEx delivery notifications - QuickBooks payment alerts - Social Security or voicemail messages ### Known Infrastructure & IOCs Security researchers have identified multiple malicious domains and endpoints, including: - `vazquezfleytas[.]com` (credential harvester) - `zh-l-haixing[.]com` (credential harvester) - `.vu` domains (e.g., `cloudbemismanufacturingcompanygroup[.]rydezyhrsysteminc[.]vu`) - Compromised sites (e.g., `odahlzr5lm[.]reliabilityinoperations[.]de`) - Malicious Cloudflare Workers endpoints The operation demonstrates how attackers abuse trusted cloud services to bypass security controls while delivering highly convincing, personalized phishing attacks.
INCIDENT DETAILS -
TYPE
Phishing
MOTIVATION
Credential harvesting, persistent remote access, financial gain
IMPACT
Data Compromised: Credentials, IP addresses, geolocation data, browser fingerprints, MX recordsSystems Affected: Compromised systems via ScreenConnect remote-access toolOperational Impact: Potential unauthorized access to corporate systems, data exfiltrationBrand Reputation Impact: Potential damage due to brand impersonation (DocuSign, Microsoft, FedEx, etc.)Identity Theft Risk: High (stolen credentials, PII)
DATA BREACH
CredentialsIP addressesGeolocation dataBrowser fingerprintsMX recordsSensitivity Of Data: High (Personally Identifiable Information, corporate credentials)Data Exfiltration: Yes (to attacker-controlled Telegram bot)Personally Identifiable Information: Yes (email addresses, corporate credentials)
AUGUST 2026
705Before Incident
JULY 2026
691Before Incident
JUNE 2026
689Before Incident
MAY 2026
703Before Incident
APRIL 2026
704Before Incident
MARCH 2026
704Before Incident
FEBRUARY 2026
702Before Incident
JANUARY 2026
699Before Incident
DECEMBER 2025
697Before Incident
NOVEMBER 2025
694Before Incident
OCTOBER 2025
692Before Incident
MAY 2025
711Before Incident
Breach
09 May 2025Intuit
Intuit Inc.

Unauthorized Access to TurboTax Account

676After Incident
MEDIUM-35
INT241072725
Intuit Inc. reported a potential unauthorized access to a TurboTax account on May 9, 2025. The breach involved an unauthorized party accessing the account using the user's credentials, potentially exposing sensitive information such as Social Security numbers and financial data. The number of individuals affected is currently unknown.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numbersFinancial data
DATA BREACH
Social Security numbersFinancial dataSensitivity Of Data: HighPersonally Identifiable Information: Yes
FEBRUARY 2025
740Before Incident
Breach
12 Feb 2025Intuit
Intuit Inc.

Unauthorized Login to TurboTax Account

704After Incident
CRITICAL-36
INT620072825
Intuit Inc. reported a potential unauthorized login to a TurboTax account on February 12, 2025. The unauthorized access may have exposed personal information, including names, Social Security numbers, and financial information, although the exact number of affected individuals is unknown. Intuit has secured the account and is offering one year of free identity protection services through Experian IdentityWorks.
INCIDENT DETAILS -
TYPE
Unauthorized Access
IMPACT
NamesSocial Security numbersFinancial informationIdentity Theft Risk: HighPayment Information Risk: High
DATA BREACH
Personal InformationFinancial InformationSensitivity Of Data: HighNamesSocial Security numbers
MARCH 2024
753Before Incident
Breach
05 Mar 2024Intuit
Intuit Inc.

Intuit Inc. Data Breach

718After Incident
LOW-35
INT411072925
On December 20, 2024, the Maine Office of the Attorney General reported a data breach involving Intuit Inc. that occurred on March 5, 2024. An unauthorized access incident involved one affected individual, with potential exposure of sensitive information from TurboTax accounts. Intuit offered a 12-month membership for Experian IdentityWorks for identity theft protection services.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Data Compromised: Sensitive InformationSystems Affected: TurboTax AccountsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Sensitive InformationSensitivity Of Data: High
DECEMBER 2023
784Before Incident
Breach
01 Dec 2023Intuit
Intuit Inc.

Data Breach at Intuit Inc.

749After Incident
MEDIUM-35
INT228072625
On March 15, 2024, the Maine Office of the Attorney General reported a data breach involving Intuit Inc. The breach, which occurred between December 23, 2023, and February 21, 2024, involved unauthorized access to a TurboTax account, potentially compromising the individual's Social Security number. Affected individuals were provided with a 12-month membership to Experian IdentityWorks for identity theft protection.
INCIDENT DETAILS -
TYPE
Data Breach
IMPACT
Social Security numberTurboTax accountIdentity Theft Risk: High
DATA BREACH
Social Security numberSensitivity Of Data: HighPersonally Identifiable Information: Yes
JANUARY 2023
809Before Incident
Breach
01 Jan 2023Intuit
Intuit Inc.

Intuit Inc. Account Takeover Incident

774After Incident
LOW-35
INT145072725
On September 15, 2023, the Maine Office of the Attorney General reported that Intuit Inc. experienced an account takeover (ATO) incident affecting one individual. The breach occurred between January 2, 2023, and July 26, 2023, resulting in unauthorized access to a TurboTax account, potentially exposing personal information, including driver's license numbers.
INCIDENT DETAILS -
TYPE
Account Takeover (ATO)
IMPACT
Personal InformationDriver's License NumbersTurboTax Account
DATA BREACH
Personal InformationDriver's License NumbersSensitivity Of Data: High
FEBRUARY 2019
817Before Incident
Breach
01 Feb 2019Intuit
Intuit

TurboTax Credential-Stuffing Attack

781After Incident
MEDIUM-36
INT41916223
Financial software company Intuit discovered that tax return info was accessed by an unauthorized party after an undisclosed number of TurboTax tax preparation software accounts were breached in a credential-stuffing attack. Following the discovery of the security breach, Intuit decided to temporarily disable the TurboTax accounts which were breached in the credential stuffing attack. The company also provides one year of free identity protection, credit monitoring, and Experian Identity Works identity restoration services to customers impacted by the data breach to further protect their TurboTax accounts. The company stated that there was no data breach of Intuit’s systems or any third party accessing Intuit systems.
INCIDENT DETAILS -
TYPE
Credential-Stuffing Attack
MOTIVATION
Unauthorized access to sensitive tax return information
IMPACT
Data Compromised: Tax return informationSystems Affected: TurboTax accountsIdentity Theft Risk: High
DATA BREACH
Type Of Data Compromised: Tax return informationSensitivity Of Data: High
FEBRUARY 2014
825Before Incident
Breach
01 Feb 2014Intuit
Intuit

Intuit TurboTax Unauthorized Account Access (2015)

793After Incident
CRITICAL-32
INT546091725
The California Office of the Attorney General disclosed a data breach affecting Intuit’s TurboTax platform in April 2015. Unauthorized actors gained access to user accounts between February 1, 2014, and February 27, 2015, potentially compromising prior-year tax return information. While the exact number of affected individuals remains undisclosed, the breach exposed sensitive financial data, including tax filings, which could enable identity theft, fraudulent tax submissions, or financial exploitation. The incident highlighted vulnerabilities in account security, raising concerns over the protection of user data within tax preparation services. Intuit did not confirm whether the breach resulted in direct financial losses for users, but the exposure of tax-related data poses significant risks to personal and financial security.
INCIDENT DETAILS -
TYPE
Data Breach / Unauthorized Access
IMPACT
prior year tax returnsTurboTax accounts
DATA BREACH
tax return informationNumber Of Records Exposed: UnknownSensitivity Of Data: High (tax-related personal data)

Frequently Asked Questions

?
What is the current A.I Rankiteo Cyber Score for Intuit ?
?
What was Intuit's A.I Rankiteo Cyber Score in August 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in July 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in June 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in May 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in April 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in March 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in February 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in January 2026 ?
?
What was Intuit's A.I Rankiteo Cyber Score in December 2025 ?
?
What was Intuit's A.I Rankiteo Cyber Score in November 2025 ?
?
What was Intuit's A.I Rankiteo Cyber Score in October 2025 ?
?
What is the average per-incident point impact on Intuit's A.I Rankiteo Cyber Score over the past 12 months ?
?
Where can I access detailed records of all cyber incidents associated with Intuit ?
?
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ?
?
Where can I view Intuit's profile page on Rankiteo ?
?
How accurate is the A.I Rankiteo Risk Scoring methodology ?
Intuit Cyber Scoring History | Rankiteo