A threat actor has claimed to have exfiltrated a database containing 450,000 TaxAct user account records, alleging that an exposed backend table allowed unauthenticated access to customer account information.
The listing appeared on August 15, 2026, with the seller claiming the data originated from a “user-account” table exported from TaxAct’s backend infrastructure. According to the post, the dataset contains contact and account management information rather than tax returns, Social Security numbers, passwords, or financial records.
Dataset allegedly contains 450,000 account records
The seller claims the database consists of a 115MB JSON export containing exactly 450,000 records with a uniform 10-field schema.
According to the claims, the dataset includes:
- Email addresses
- Phone numbers
- Usernames
- Last sign-in timestamps
- Internal
camp_ididentifiers - Email verification status
- Phone verification status
- Account enabled status
- Account status flags
- Dummy phone indicators
The threat actor alleges the dump contains:
- 449,996 unique email addresses
- 450,000 unique usernames
- 347,293 unique U.S. phone numbers
- 357,221 records containing both an email address and phone number
- 302,307 email-verified accounts
- 287,517 phone-verified accounts
- 198,039 accounts where both email and phone were reportedly verified
The post specifically claims that passwords, tax returns, Social Security numbers, payment information, and tax documents are not included in the alleged dataset.
Threat actor alleges exposed account provisioning backend
According to the seller, the database originated from an allegedly exposed account provisioning system rather than TaxAct’s tax filing platform itself.
The post claims the exported records all contain a last_signed_in value of 0001-01-01T00:00:00, suggesting the records may represent provisioned accounts rather than actively used customer profiles.
The seller also alleges that approximately 146,651 usernames were automatically generated from customer email addresses using an obfuscated naming convention, while more than 102,000 records were marked as containing dummy phone numbers.
Another claim centers on an internal camp_id identifier ranging from roughly 1 million to more than 34 million. The seller argues this suggests the underlying source table could contain tens of millions of account records, although only a 450,000-record subset was allegedly exported.
Phishing risks could outweigh the lack of financial data
Although the alleged database does not appear to contain tax returns or authentication credentials, the combination of verified email addresses, phone numbers, usernames, and account status information could still present meaningful security risks if authentic.
Tax preparation services are frequent targets for phishing campaigns impersonating the IRS, tax refund notifications, identity verification requests, and account security alerts. A dataset linking verified contact information to a recognizable tax preparation platform could allow attackers to craft highly convincing phishing, SMS, or voice-based social engineering campaigns.
The seller repeatedly frames the dataset as valuable for large-scale phishing rather than direct account compromise.
Latest claim tied to “CredHarvest V6”
The forum post attributes the alleged acquisition to what the seller calls the CredHarvest V6 pipeline, claiming it has already been used to obtain databases from numerous organizations. No technical evidence was provided to substantiate those claims, and the seller did not publish proof demonstrating how the alleged access was obtained.
The same post also advertises penetration testing services and claims additional database releases from the purported pipeline are forthcoming.
No public confirmation from TaxAct
At the time of publication, TaxAct had not issued any public statement regarding the alleged database. BreachNews has also not independently verified the authenticity of the records or confirmed that TaxAct systems were compromised.
The company has previously faced privacy-related litigation over allegations that certain customer information was shared with third-party advertising platforms, resulting in a class action settlement. TaxAct denied wrongdoing in that matter. The current forum post, however, alleges a separate incident involving customer account records rather than advertising-related data sharing.












