Fall ResetAmazon USFall reset deals: check better picks before checkoutAmazon US: today's deals, useful picks and quick comparisons.Check DealsPC HealthRecommendedCrashes, freezes, slowdowns? Check your PC nowSpot repairable issues before they interrupt work.Check PCFall ResetAmazon USWork and home upgrades are worth comparing todayAmazon US: today's deals, useful picks and quick comparisons.See Picks×
Skip to content
Blog

Fake QuickBooks Google Ads Targeted Taxpayers: How the Phishing Scam Worked

By TheFinanceBase Team7 min read
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

A documented April 2025 campaign used paid Google Search ads to impersonate QuickBooks Online and direct users to lookalike login pages. The reported phishing operation sought usernames, passwords, and one-time passcodes, potentially allowing attackers to relay a victim’s current login session to the real service.

The campaign was reported by Malwarebytes on April 8, 2025, ahead of the U.S. tax-filing deadline. That evidence confirms the campaign and its method; it does not establish that the same domains or infrastructure remained active in August 2026.

The scam in brief

The reported attack followed this pattern:

  1. A taxpayer or business user searched Google for QuickBooks.
  2. A prominent sponsored result imitated QuickBooks or Intuit branding.
  3. The advertisement led to a deceptive, misspelled domain.
  4. A convincing QuickBooks-style login page collected the user’s credentials.
  5. The page requested a one-time passcode and reportedly relayed it to the attackers in real time.

Malwarebytes documented a lookalike domain, quicckboorks-acccounting[.]com, along with other typo-heavy domains. These are examples from the 2025 report, not a complete blacklist, and their status may have changed.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

This was not evidence that Google created or endorsed the websites. The reported method was criminals buying or abusing advertising placements. Google’s advertising policies prohibit phishing, fake login pages and deceptive impersonation, but policy enforcement does not guarantee that every malicious advertisement is blocked before someone sees it.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Read Malwarebytes’ report on the campaign.

Why a Google ad can still be dangerous

Search advertising benefits from a powerful trust shortcut: people see a familiar brand name, logo and prominent placement, then assume the result is official. During tax season, deadline pressure makes that shortcut even more effective.

A sponsored result is an advertisement, not a guarantee that the destination belongs to the brand shown in the ad. Criminals can use familiar branding, urgent wording and a professional-looking page to make a fraudulent site appear credible. A malicious page may also use HTTPS, so the padlock only indicates that the connection is encrypted; it does not prove that the website belongs to Intuit.

Google prohibits phishing and brand impersonation in ads. Its reporting process can be used for suspicious webpages and advertisements, but users should still inspect destinations and navigate through known official channels.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Google’s phishing and unacceptable-business-practices policy explains the rule. Suspicious pages or ads can be reported through Google’s reporting guidance.

How to tell whether a QuickBooks login is genuine

Intuit says official Intuit websites end in intuit.com and gives quickbooks.intuit.com as an example. Check the complete domain—not just the first word shown in a search result.

Rank #2
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
  • Look for misspellings, extra letters, substituted characters and unnecessary hyphens.
  • Be cautious about unusual subdomains or a domain that merely contains the word “QuickBooks.”
  • Do not treat HTTPS or a padlock as proof of authenticity.
  • Do not assume a “Sponsored” label means the advertiser is affiliated with QuickBooks.
  • Prefer the official QuickBooks app, a bookmark you created previously, or a known address typed manually.
  • Do not sign in through an unexpected email, text message, pop-up or support message.

Intuit also says it will not email users asking them to send sign-in or password information. If a message requests sensitive information, leave the message and open QuickBooks through a verified route instead.

Intuit’s guidance on suspicious activity, phishing and fraud provides its official-site and reporting advice.

Free tools Windows power users keep installed

One-click scans. No signup required.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Why a one-time code may not stop the attack

Two-factor authentication remains important, but it cannot make a counterfeit login page trustworthy.

In ordinary credential phishing, a criminal simply steals a username and password. In a real-time relay or adversary-in-the-middle attack, the phishing page forwards the information to the legitimate service as the victim enters it. If the legitimate service asks for a current one-time code, the fake page asks the victim for that code too and passes it along while it is still valid.

Rank #3
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified (Pack of 2)
  • The information below is per-pack only
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.

That is why the reported campaign’s collection of one-time passcodes mattered. The code may have helped an attacker attempt access to the real account, even though the victim had enabled code-based authentication.

The lesson is not that 2FA is useless. Passwords protected by an additional factor are safer than passwords alone, and authenticator apps are generally preferable to SMS in many situations. However, neither type of code protects a user who voluntarily enters the current code into a phishing relay.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Where an account supports them, passkeys or hardware security keys provide stronger phishing resistance because they are tied to the legitimate website’s origin. Availability and recovery options depend on the QuickBooks account, Intuit security settings and any identity provider used by an organization.

What to do if you interacted with the page

If you only opened the page

Close it and do not return. If you did not enter credentials or codes, download anything, install software or grant browser permissions, the risk is lower. Scan the device if a download, extension or unusual permission was involved.

Rank #4
Sale
Thetis FIDO2 Security Key (USB-A, 2-Pack) - Hardware MFA & Passkey Access for Business, School ERP & Employee Accounts | Compatible with Windows, Google Workspace, Apple ID, Coinbase, Salesforce
  • FIDO2 & Passkey Ready: Business-ready and FIDO2 L1 certified. This key is supported by major management suites and is ideal for both individual and enterprise deployment. Works seamlessly with Gmail, Facebook, GitHub, Dropbox, Coinbase, and more.
  • Universal Connectivity (USB-A ): Features a built-in USB-A connector—simply unfold the key and plug it into your compatible PC or laptop for seamless authentication on the go.
  • Dedicated Manager App: Use the Thetis Manager App for the initial hardware PIN setup. Setting the PIN on the device first ensures a smooth registration process. Once the PIN is configured, you can begin registering the key across your favorite FIDO2-compatible online services.
  • Ultra-Durable & Portable: Featuring a rotating metal cover, this key is water, crush, and tamper-resistant. It fits easily on a keychain and requires no batteries or network connectivity.
  • Check FIDO2 compatibility before purchase - Known limitations: ID Austria is not supported (requires FIDO2 Level 2). Windows Hello login only works with Windows Enterprise editions that support Entra ID, and NFC is NOT supported.

If you entered a password

  1. Open QuickBooks through the official app or a verified Intuit address—not through the advertisement or phishing page.
  2. Change the QuickBooks password immediately.
  3. Change it anywhere else it was reused. Every important account should have a unique password.
  4. Review recent activity, connected users, administrator access, banking connections, invoices, vendor details, payroll settings and payment information.
  5. Check the associated email account separately. Look for unfamiliar recovery addresses, new devices, authentication changes and forwarding rules.
  6. Contact Intuit through its official support and security resources.

If you entered a one-time passcode

Treat the account as potentially compromised even if the page displayed an error or nothing obviously changed.

  • Change the password from a verified device.
  • Terminate unfamiliar sessions if the account provides that option.
  • Reset multifactor authentication and remove unknown authentication methods.
  • Review connected applications, users, administrators and account changes.
  • Contact Intuit and, where appropriate, the business’s bank or payroll provider.
  • Preserve the evidence: screenshots, the full URL, advertisement text, timestamps, browser history and account alerts.

If you downloaded or installed something

Disconnect the device from sensitive accounts if practical, run a reputable malware scan and seek qualified technical help. Change passwords from a separate, trusted device after addressing possible malware. Security software cannot undo credentials already submitted to a phishing page, so account recovery is still necessary.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If tax, payroll or financial information was exposed

Business records, bank details, payroll data, tax-identification information, employee information and Social Security numbers can create risks beyond the QuickBooks login itself.

Contact affected banks, card issuers, payroll processors and payment providers using a number from an official statement or app. If identity information was disclosed, consider credit monitoring or a credit freeze based on what was exposed. Do not assume every victim needs every possible service.

Best Value
FIDO2 U2F Security Key Passkey Two-Factor Authentication (2FA) USB Key PIN+Touch (Non-Biometric) USB-A Type TrustKey T110
  • Security Key : Protect your online accounts against unauthorized access by using FIDO2 and U2F authentication with T110. It's the world's most protective security key that works with windows, Mac OS, Linux as well as Chrome, Firefox, Edge and many other major browsers.
  • Certified with the new FIDO2 standard, T110 provides the benefit of fast login and strong protection against phishing, account takeover as well as many other online attactks.
  • Works with : Bank of America, Github, Google, Microsoft, DUO, Twitter, Facebook, Dropbox, Apple, ebay, BINANCE, mor and more.
  • Fits USB-A port : Insert the T110 security key into the USB-A port of each service and log in conveniently with one touch
  • For the driver download and user guide, please visit TrustKey Solutions Home support page.

The IRS says it does not initiate contact by email, text, telephone or social media to request or verify passwords, PINs or financial-account information. For potential tax-related identity theft, use IRS Identity Theft Central and Publication 547, rather than replying to the suspicious message.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Business users need a wider review

For a company, QuickBooks compromise may affect more than one person’s login. An owner or administrator should involve the bookkeeper, accountant, IT provider and relevant financial institutions as appropriate.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Review payroll settings, employee tax information, bank feeds, vendor payment details, customer invoices, accountant access, administrator accounts and recently added applications. Confirm vendor or employee payment changes through a separate, known phone number before sending money. A stolen session or administrator account can enable payment fraud even when no malware was installed.

Where to report the incident

  • Intuit: Use the security and suspicious-activity resources in Intuit’s phishing guidance.
  • Google: Report the suspicious advertisement or webpage through Google Ads’ reporting process.
  • IRS: Follow the official reporting guidance for tax-related phishing and identity theft, including IRS tax-scam guidance.
  • Financial institutions: Contact banks, card issuers, payroll processors or payment providers through official channels.
  • Law enforcement: Consider reporting substantial financial loss or identity theft to the appropriate U.S. authorities. A report does not guarantee recovery.

What is confirmed—and what is not

Confirmed by the available report: Malwarebytes published its findings on April 8, 2025; criminals reportedly used prominent Google Search ads impersonating QuickBooks Online; lookalike domains were involved; and the pages sought credentials and one-time passcodes.

Not established by that evidence: the number of victims, total losses, the full size of the campaign, Google’s response to the specific advertisements, or whether the listed domains remained active in August 2026. The campaign should be understood as a documented example of a reusable phishing pattern, not proof that the same infrastructure is currently operating.

Bottom line

Use QuickBooks through a known official route, not simply because an advertisement appears at the top of Google. Verify that the full domain ends in intuit.com, and remember that branding, HTTPS and a one-time code do not prove a login page is genuine. If you submitted a password or code, act immediately: secure the account, protect the associated email, review business and financial changes, preserve evidence and report the incident through official channels.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Written by TheFinanceBase Team

The Team behind TheFinanceBase.

Add your note

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Recommended PC Tool
Recommended PC Tool
PC Slower Than It Used to Be?Free scan - under a minute
Crashes, No Sound, or Screen Glitches?Free driver scan

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.