Filed under: Cybersecurity — Phishing — July 2026

What happened

Security researchers at MailGuard caught a new phishing campaign impersonating Intuit QuickBooks, spotted July 29, 2026. The email looks like a routine payment confirmation — subject line “Payment Received — Invoice #INV-xxxx Has Been Paid” — complete with a fake transaction ID, payment date, and a “View Receipt” button. Clicking it leads to a convincing fake QuickBooks login page that harvests your email and password, then shows a fake “Please wait…” screen so you don’t immediately realize anything went wrong.

Why it matters to your business

QuickBooks (or similar accounting software) sits at the center of most small businesses’ financial life, so an email that looks like a payment notification is exactly the kind of thing a busy owner or bookkeeper clicks without a second thought. Once attackers have those login credentials, they can see real invoices and client billing details, redirect future payments, or use the account to send convincing follow-up scams to your customers or vendors. The senders behind this campaign are using rotating, randomized email addresses, so blocking one sender won’t stop the next wave.

What to do this week

Tell anyone who handles invoicing or bookkeeping: never click a “View Receipt” or “View Invoice” button in an email — instead, log into QuickBooks directly (typing the address yourself or using your saved bookmark) and check payment status there. Hover over any “payment received” link before clicking to see the real destination domain — legitimate QuickBooks emails link to intuit.com or quickbooks.com, not a random business or personal domain. If your accounting staff use QuickBooks Online, turn on multi-factor authentication for it now if it isn’t already on (Settings gear icon > Account and Settings > Security).

The bigger picture

Fake payment and invoice emails targeting small business finance staff are a recurring, evergreen scam because they work — the fix isn’t new software, it’s making “log in directly, don’t click the link” a habit for anyone touching money in your business. QuickBooks Payment Confirmation Phishing Campaign Targets Business Users

Want your bookkeeping team trained to spot these before they click? Book a free consult — https://micro1tech.com/contact/