For two weeks, attackers had access to a third-party support ticket system containing customer tax information.