Newsletter

QuickBooks Online Security: Four Things Every Business Should Do Right Now

QuickBooks Online is easy to think of as “just accounting software.” That is a mistake.

For many businesses, QuickBooks Online contains some of the most sensitive information in the company: financial reports, vendor records, customer information, payroll details, bank connections, tax data, payment workflows, and user access controls. That also makes it valuable to attackers.

Attackers are heavily targeting cloud accounts by taking advantage of reused passwords, weak MFA methods, and busy professionals who can be fooled on a bad day. Intuit specifically warns users to watch for phishing scams and suspicious activity involving the Intuit brand, and compromised credentials remain one of the most common ways attackers gain initial access.

The important point is this: attackers do not always “hack” their way into an account. Sometimes they log in with a password that was reused somewhere else. They then trick the user into approving a login or sharing an MFA code.

This could expose sensitive financial information. For an accounting firm, the stakes may be even higher because one compromised QuickBooks Online Accountant user could potentially have visibility into hundreds of client files.

Here are four things every business should do right now.

1. Do not use a QuickBooks password you have ever used anywhere else

Your QuickBooks Online password should be completely unique. Not “kind of unique.” Not “the same password with QuickBooks added to the end.” Not “the same pattern I use everywhere, but slightly changed.”

The safest approach is simple: use a password manager to create a long, random password for QuickBooks Online, and never use that password anywhere else.

This matters because if your QuickBooks password is reused, that only leaves one more step to compromise you, and MFA becomes your last and only defense.

2. Turn on app-based MFA for every QuickBooks Online user

Multi-factor authentication is essential, but the type of MFA matters. Whenever possible, QuickBooks Online users should use an authenticator app instead of relying on text messages, voice calls, or email codes.

Text messages are better than nothing, but app-based MFA is stronger and, for most people, gives them the pause they need to consider their actions before turning over the key to social engineering.

Every QuickBooks Online user should enable app-based MFA. For accounting firms, this should be treated as a non-negotiable security standard.

3. Never share login codes or approve unexpected login prompts

No one should ever read back a login code, authorization code, or MFA code to someone who contacted them by phone, email, or text. Many verification messages tell you not to share the code, but people are consistently talked into it, and that code may be the final step an attacker needs to access the account.

If someone claims to be from Intuit or QuickBooks and asks for a code, stop the conversation immediately and hang up.

4. Review users, admin rights, bank connections, and connected apps

QuickBooks Online access should not be “set it and forget it.” Businesses should regularly review who has access.

For accounting firms, this review should go even further. Firms should know which employees have access to which client files. When someone leaves the firm or changes roles, QuickBooks Online access should be reviewed immediately.

QuickBooks Online Accountant access should be treated as privileged access because the potential impact is larger than a single company file.

The bigger point

QuickBooks Online is not just accounting software. It is a cloud-based financial system that may contain some of the most sensitive information your business has, and it deserves stronger protection than an ordinary website login.

The good news is that the most important steps are not complicated:

  1. Use a completely unique password.
  2. Turn on app-based MFA.
  3. Never share login codes.
  4. Review access regularly.

Those four steps can significantly reduce risk and help protect the financial heart of your business. If you have questions about cybersecurity or want help identifying practical ways to reduce risk, we would be happy to help.

 

Frankel Technology
info@frankel.technology / 402-963-4375

 

 

 

 

About Frankel

Our mission is to offer forward-thinking and innovative accounting, tax, and advisory solutions to our clients. We strive to help them overcome their obstacles and leverage opportunities for their financial prosperity and growth. Our clients’ objectives are our objectives, and we measure our success by their achievements.

Contact us today to learn more about how we can support your business.