How to Spot and Report Phishing Emails Targeting QuickBooks Users
Phishing scams impersonating Intuit and QuickBooks remain a persistent threat. Here is how to identify suspicious emails, secure your account, and report fraudulent messages safely.

Phishing campaigns targeting QuickBooks users continue to circulate, with fraudulent emails designed to mimic official Intuit communications. These scams attempt to trick accounting professionals, business owners, and employees into handing over login credentials, financial data, or access to company files. Recognizing the warning signs and knowing exactly how to respond is critical for protecting sensitive accounting data.
How to Verify Legitimate Intuit Communications
Distinguishing a genuine message from a spoofed email comes down to checking the sender’s email address and any embedded links. Legitimate communications from Intuit will always originate from an email address that ends in @intuit.com — such as @account.intuit.com. Similarly, any links contained within official emails will direct you to a web address that ends in intuit.com. Legitimate Intuit websites include addresses like quickbooks.intuit.com, e3.intuit.com, and click.notifications.intuit.com.
If you hover over a link and the destination URL looks altered, unfamiliar, or points to a completely different domain, treat the email with suspicion.
Common Red Flags in Phishing Emails
Attackers rely on urgency and deception to bypass a user’s better judgment. You can generally spot a phishing attempt by watching for a few standard red flags:
- Misspelled or altered sender addresses: Scammers often use domains that look correct at a glance but contain slight typos or unusual characters.
- Generic greetings: Phishing emails frequently open with vague salutations like “Dear Customer” rather than addressing you by the name associated with your account.
- Urgent or alarming language: Messages claiming “Immediate action required” or threatening account suspension are designed to make you panic and click without thinking.
- Unexpected attachments: Be highly suspicious of unsolicited attachments, especially those claiming to be “software updates” or “software downloads.” Intuit does not distribute software updates this way.
- Requests for sensitive information: You will never be asked for your password, verification codes, banking details, or confidential employee information via email. Any message requesting this data is fraudulent.
- Poor grammar and odd formatting: Official corporate communications are typically proofread. Clunky phrasing, spelling errors, and strange formatting are strong indicators of a scam.
What to Do If You Receive a Suspicious Email
If an email exhibits any of the warning signs above, the safest approach is to do nothing with its contents. Do not click any links, and do not open any attachments. Instead, forward the suspicious message to [email protected]. Once you have forwarded it, delete the email from your inbox and empty your trash folder. If you want to take additional action, you can visit the Intuit Online Security Center to find further guidance on reporting security issues.
Steps to Take If You Already Clicked
Mistakes happen. If you clicked a link, opened an attachment, or entered your password on a site you later realized was fake, you need to act quickly to secure your QuickBooks account and your device.
First, change your password immediately. Doing so cuts off access for anyone who may have captured your old credentials. Next, enable Multi-Factor Authentication (MFA) or set up a Passkey if you have not already. Adding a second verification step is one of the most effective ways to prevent unauthorized access, even if an attacker has your password.
After securing your login, review your account activity. Sign in directly through the official website — do not use any links from the suspicious email. Check your account for unfamiliar transactions, changes to your profile or settings, or the addition of new users.
Because some phishing links install malware capable of stealing passwords or hijacking active sessions, you should run a full scan with your antivirus or security software. If malware is detected, or if you strongly suspect your device has been compromised, consider re-imaging the machine or restoring it to factory settings. Some advanced malware can maintain access to your accounts even after a password change. If you are unsure how to safely wipe a device, consult a trusted IT professional.
General Security Best Practices
Maintaining strong baseline security habits reduces the risk posed by phishing attempts. Use strong, unique passwords for your computer and sensitive files, and never share them. Keep your operating system, browser, and antivirus software updated to protect against known vulnerabilities. Finally, adopt a default stance of caution: do not open attachments unless you know the sender and are specifically expecting the file, and never respond to emails asking for account details, passwords, or banking information.