Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

An electrical vehicle charging station on Fort St. across from the Hope Legion appears to have suffered extensive damage. (Emelie Peacock/Hope Standard)
Electric vehicle charging station in Hope vandalized

Cables were cut to all four charging stations at a soon-to-be-opened lot on Fort St.

Kastor Hansen gets the right timing on the double-Dutch ropes, cheered on by principal, Bruce Becker. For the past 10 years, Becker has been Silver Creek Elementary’s principal, he is now moving on to become principal at Coquihalla Elementary School. (Barry Stewart/Hope Standard)
Bruce Becker to be Coquihalla Elementary’s new principal, leaving role at Silver Creek open

Longtime SD78 educators Monique Gratrix and Peter Flynn are retiring

Google Maps screenshot taken at 7:56 a.m., Oct. 29.
TRAFFIC: Westbound Highway 1 crash between Chilliwack and Abbotsford

Left lane is blocked, traffic backed up to No. 3 Road

AdvantageHOPE is working with Boston Pizza to find a franchisee for a Hope location. (Facebook/AdvantageHOPE photo)
Boston Pizza eyeing Hope for new location

With over 395 locations Canada-wide, company is looking to expand to Hope

A woman holds a packet of contraceptive pills. (AP Photo/Tsvangirayi Mukwazhi)
Chilliwack women’s organization among those lobbying for free contraception

Ann Davis Society says while it’s a women’s issue, all of society would benefit from program

A woman wears a face mask and plastic gloves while browsing books as a sticker on the floor indicates a one-way direction of travel between shelves of books at the Vancouver Public Library’s central branch, after it and four other branches reopened with limited services, in Vancouver, on Tuesday, July 14, 2020. (THE CANADIAN PRESS/Darryl Dyck)
B.C. reports 234 new COVID cases, 1 death of senior who had attended small birthday party

Roughly 5,700 people are isolating due to being exposed to a confirmed case

Provincial Health Officer Dr. Bonnie Henry speaks Thursday (Oct. 29) during a news conference held at Fraser Health office, in video posted to Facebook. (Photo: Government of British Columbai/Facebook)
COVID-19 ‘disproportionately’ affecting Fraser Health: Henry

Health region has about 75 per cent of B.C.’s active cases

Burnaby RCMP responded to a dine-and-dash suspect who fell through a ceiling in March 2020. (RCMP handout)
VIDEO: Suspected dine-and-dasher falls through ceiling of Burnaby restaurant

A woman believed to be dashing on her restaurant bill fell through the kitchen ceiling

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

A can of Canada Dry Ginger Ale is shown in Toronto on Thursday Oct. 29, 2020. The maker of Canada Dry Ginger Ale has agreed to pay over $200,000 to settle a class-action lawsuit launched by a B.C. man who alleged he was misled by marketing suggesting the soda had medicinal benefits. THE CANADIAN PRESS/Joseph O’Connal
B.C. man’s lawsuit over marketing of Canada Dry ginger ale settled for $200K

Soda’s maker, Canada Dry Mott’s Inc., denied the allegations and any liability

Vancouver Island-based Wilson’s Transportation has expanded to fill some of the routes left unserviced by Greyhound as of Nov. 1, 2018. (Black Press files)
B.C. bus companies say they need help to survive COVID-19

Like airlines, motor coaches have lost most of their revenue

A deer was spotted in October 2020 in Prince Rupert, B.C., with a bright pink yoga ball stuck in its antlers. (Kayla Vickers/Chronicles Of Hammy The Deer Official Page)
Hammy 2.0? Prince Rupert deer spotted with bright pink yoga ball stuck in antlers

The BC Conservation Officer Service is aware of the deer roaming around the city

RCMP. (Phil McLachlan - Black Press Media)
Kelowna Mountie hit with 2nd lawsuit in 2 months for alleged assault

Const. Julius Prommer is accused of breaking a woman’s knee during while responding to a noise complaint

Hirdeypal Batth, 24, has been charged with sexual assault and forcible confinement in relation to an incident in August 2020. (VPD handout)
Man, 24, charged with sex assault after allegedly posing as Uber driver in Vancouver

Investigators believe there could be more victims outside of the Vancouver area

Most Read