Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

COVID-19 test tube. (Contributed)
test tube with the blood test is on the table next to the documents. Positive test for coronavirus covid-19. The concept of fighting a dangerous Chinese disease.
Interior Health launches online booking for COVID-19 tests

Testing is available to anyone with cold, influenza or COVID-19-like symptoms

RCMP crest. (Black Press Media files)
RCMP cleared in fatal shooting of armed Lytton man in distress, police watchdog finds

IIO spoke to seven civillian witnesses and 11 police officers in coming to its decision

BC Liberal Party candidate Jackie Tegart says that her party has pledged a $2 million investment in developing the McAbee Fossil Beds east of Cache Creek. (Photo credit: Barbara Roden)
BC Liberals promise $2 million investment in McAbee Fossil beds

Site has potential as a centre for education, research, and tourism

NDP candidate Aaron Sumexheltza says that if re-elected, the BC NDP will commit to 24/7 emergency department service at the Ashcroft Hospital. (Photo credit: Barbara Roden)
Fraser-Nicola NDP candidate pledges 24/7 Ashcroft emergency department

Horgan government commits to round-the-clock emergency department at Ashcroft Hospital if re-elected

A health-care worker prepares to swab a man at a walk-in COVID-19 test clinic in Montreal North, Sunday, May 10, 2020, as the COVID-19 pandemic continues in Canada and around the world. (THE CANADIAN PRESS/Graham Hughes)
Interior Health records 21 new COVID-19 cases over the weekend

Thirty-six cases remain active; two people are in the hospital, one of whom is in intensive care

B.C. NDP Leader John Horgan arrives at Luxton Hall to cast their votes in advance polls for the provincial election in Langford, B.C., Monday, Oct. 19, 2020. THE CANADIAN PRESS/Chad Hipolito
Pandemic election prompts voter suppression claims by B.C. Liberals

‘These emergencies require in us a maturity that has been lacking in politics for so long’

UBC geoscientists discovered the wreckage of a decades-old crash during an expedition on a mountain near Harrison Lake. (Submitted photo)
Wreckage of possibly decades-old airplane crash discovered on mountain near Harrison Lake

A team of UBC geoscientists discovered the twisted metal embedded in a glacier

The official search to locate Jordan Naterer was suspended Saturday Oct. 17. Photo courtesy of VPD.
‘I am not leaving without my son,’ says mother of missing Manning Park hiker

Family and friends continue to search for Jordan Naterer, after official efforts suspended

A bear similar to this black bear is believed responsible for killing a llama in Saanich on Oct. 19. (Black Press Media file photo)
Bear kills llama on Vancouver Island, prompting concerns over livestock

Officers could not track the bear they feel may not fear humans

Bernard Trest and his son Max, 10, are concerned about B.C.’s plan for students in the classroom. He was one of two fathers who filed a court application in August to prevent schools from reopening if stricter COVID-19 protections weren’t in place. That application was dismissed last week. (Contributed photo)
B.C. dad pledges to appeal quashed call for mandatory masks, distancing in schools

Bernard Trest and Gary Shuster challenged health, education ministries’ return-to-school plan

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

A 34-year-old man was treated for a gunshot wound in Williams Lake Monday, Oct 19, 2020. (Angie Mindus photo - Williams Lake Tribune)
Williams Lake man treated for gunshot wound after accidental shooting: RCMP

Police are reminding residents to ensure firearms are not loaded when handling them

A injection kit is seen inside the newly opened Fraser Health supervised consumption site is pictured in Surrey, B.C., Tuesday, June 6, 2017. THE CANADIAN PRESS/Jonathan Hayward
B.C. records 127 fatal overdoses in September, roughly 4 each day

Vancouver, Surrey and Victoria continued to see the highest numbers of overdoses

Investigators work at the Sagmoen farm in Silver Creek. - Image credit: Observer file photo.
Sex workers allegedly called to farm of Okanagan man convicted of assault, RCMP investigating

Curtis Sagmoen, convicted in relation to assault of sex trade workers, is prohibited from soliciting escorts

Most Read