⚠️ H&R Backdoor

H&R Block Business 2025 installs a backdoor on your machine which allows anyone to snoop and manipulate your encrypted internet traffic.

If you can see this page without any warnings or error messages from your web browser, then you are vulnerable. Follow the instructions below to secure your machine.

How to Remove the Backdoor

To secure your computer, you must manually remove this certificate from the Local Machine certificate stores.

  1. Press the Windows Key + R to open the Run dialog.
  2. Type certlm.msc and press Enter. (Click "Yes" if prompted by User Account Control).
  3. In the left-hand pane, expand Trusted Root Certification Authorities and click on the Certificates folder.
  4. In the middle pane, locate WK ATX ServerHost 2024.
  5. Right-click the certificate, select Delete, and confirm the deletion.

FAQ

What is TLS?

TLS is the backbone of internet security. It is what protects your internet traffic from unscrupulous eyes. When you visit a website that begins with "HTTPS" and you see a pad-lock icon on your browser, the traffic is protected by TLS. When TLS is used correctly, the only people who can see your internet traffic is you and the website you are communicating with. However, when an untrusted "root certificate" is installed, anyone who has the private key to that certificate can silently re-direct that traffic and see what you are doing as well as manipulate the content you see. This includes but is not limited to your emails, online banking, social media, and private messages. See this page for more details.

What is this H&R Block backdoor?

H&R Block Business 2025 installs a root certificate named "WK ATX ServerHost 2024" into your computer's trusted root certificate store. This root certificate has a known private key that is included with the software package meaning anyone who can see your encrypted internet traffic is now able to decrypt it. Worse of all, when you normally uninstall the software, the root certificate does not get deleted so unless you follow the uninstall steps on this page, your computer will still be vulnerable. Currently, only H&R Block Business 2025 is known to be vulnerable and other editions and versions have not been tested.

Who is affected?

If you got a warning or error message from your web browser when visiting this page, then you are not vulnerable. Even if you are vulnerable, this does not automatically mean your data has been compromised. You should follow the instructions above and remove this back door as soon as possible. In order for an attacker to use this backdoor, they would need to be able to see your (normally encrypted) internet traffic. Common entities who may be able to use this backdoor include: anyone on a shared or public Wi-Fi that you are connected to, anyone in a shared building (apartment, business, etc), your landlord or boss or parent or guardian (if they installed monitoring software on the network), your internet service provider, your VPN provider, government entities, and other nation-states.

How do I tell if I have been compromised by this backdoor?

Unfortunately, there is no general way to tell. If you are a business who uses an endpoint security product, contact them about possible indicators of attacks based on network traffic. If your computer is vulnerable AND you suspect a website you visit (excluding this one) may be attacked, click on the pad-lock icon on your browser and check if the name "WK ATX ServerHost 2024" appears in the list of certificates. If it appears, then you are being attacked and you can assume all your internet traffic is being actively monitored or manipulated by a third party. If it does not appear, then either you are safe or the attack may not be active at that moment.

Timeline