2019 Wolters Kluwer — malware attack; CCH tax cloud outage; forensics cited no exfil evidence at June update (May–Jun)
Data compromised
Vendor-stated posture at June 2019 update: no confirmed theft from primary customer-information systems—availability impact dominated headlines
Technical writeup
On May 6, 2019, Wolters Kluwer disclosed a malware intrusion that forced a precautionary wide shutdown of customer-facing CCH and adjacent professional platforms (e.g., Axcess / SureTax family products) to contain spread. Krebs on Security and the Journal of Accountancy chronicled multiday tax-season disruption, while Wolters Kluwer’s June 7, 2019 public update cited external forensics not observing data exfiltration from the reviewed estate as of that checkpoint—themes echoed in IRS penalty-relief commentary for tardy filings tied to the outage.
Root cause
Destructive/credential malware incident requiring aggressive containment isolation (specific family debated in trade press as MegaCortex-class)