Quickbooky

Accounting News

QuickBooks

Suspect Unauthorized Access to QuickBooks? Start With the Audit Log

When QuickBooks entries change and no one on your team admits to it, the audit log, user list, and connected apps reveal what really happened.

Suspect Unauthorized Access to QuickBooks? Start With the Audit Log

Every few weeks a post circulates from a small business owner convinced an unseen hand is editing their books. The details vary wildly, but QuickBooks is often the one concrete thing in the story. We cannot verify those claims, and we do not need to. QuickBooks Online keeps a record of nearly every change, and that record settles the question faster than any theory.

Here is where to look, in the order we would check ourselves.

Does the audit log show who changed what?

Yes. QuickBooks Online records each event with a date, a time, and the user who performed it. Open Settings, then Audit log. Filter by user, date, or event type, and select an entry to see the before and after values. Deleted and voided transactions appear there too.

QuickBooks Desktop keeps a similar record called the Audit Trail, found with the Accountant and Taxes reports. Read the entries before you fix anything. The log is your evidence, and cleanup edits on top of it only muddy the trail.

Which users still have access?

The same Settings area lists every user and their role: administrators, standard users, reports-only viewers, and invited accounting firms. People leave, projects end, and old invitations quietly survive. Remove anyone who should not still be inside, including a firm you no longer work with.

Shared logins are the other common culprit. If several people sign in as one admin, every log entry names that admin, and the trail stops there. Give each person their own login, and the question of who did what tends to answer itself.

Could a connected app be making the changes?

Apps, bank rules, and recurring templates can all write to your books without anyone opening them that day. A sync tool can post journal entries overnight. A bank rule can add transactions automatically. A recurring invoice template can fire on schedule. None of that is tampering, but it looks alarming if nobody remembers setting it up.

Review the apps listed under the Apps menu. Check what each one can touch, and disconnect anything you do not recognize or no longer use. Then scan bank rules and recurring templates for entries you did not create.

A damaged desktop company file can also produce strange behavior: corrupted lists, phantom entries, totals that refuse to agree. That is a repair problem rather than a security one, and our QuickBooks error code repair service covers exactly that kind of damage.

Is the login itself secure?

If you genuinely suspect an outsider, change the password before anything else, and make it long and unique. Keep multi-factor authentication switched on, and treat unexpected approval prompts as a warning sign rather than a nuisance.

Check the recovery email and phone number stored on the Intuit account as well. Whoever controls those can eventually control the login. We have no access to your Intuit account, so these steps are yours to run.

What order should you work through this?

  1. Export or back up the books as they stand, so you have a baseline to compare against.
  2. Change the Intuit account password and confirm multi-factor authentication is on.
  3. Read the audit log for at least the past ninety days, or further back if the changes are older.
  4. Remove users and disconnect apps you cannot account for.
  5. Reconcile the affected accounts against bank and card statements.

Ninety minutes of log reading beats a week of suspicion. In our experience the trail usually ends at a forgotten app, a departed employee, or a shared login, not an intruder.

← Back to News