Canada Revenue Agency suspends online services after cyberattacks

Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

RCMP. (Phil McLachlan - Black Press Media)
Blackfalds RCMP investigate fatal collision

Preliminary investigation revealed a south bound pickup truck collided with an eastbound car

SARS-CoV-2 virus particles, which causes COVID-19, emerge from the surface of cells isolated from a patient in the U.S. and cultured in a lab in a 2020 electron microscope image. THE CANADIAN PRESS/AP-HO, National Institute of Allergy and Infectious Diseases - Rocky Mountain Laboratories
Alberta adds 463 new COVID-19 cases on Sunday

The central zone has 818 active cases

As of Friday, Alberta has under 10,000 active COVID-19 cases. (Image courtesy CDC)
Alberta identifies 573 new COVID-19 cases, 13 deaths on Saturday

There are currently 9,727 active cases of the virus in the province

As of Friday, Alberta has under 10,000 active COVID-19 cases. (Image courtesy CDC)
Three new COVID-19 deaths in Central zone, Alberta under 10,000 active cases

The Central zone sits at 849 active cases, with 52 people in hospital and 10 in the ICU.

Alberta’s chief medical officer of health Dr. Deena Hinshaw announced 16 additional deaths Thursday. (Photo by Chris Schwarz/Government of Alberta)
No easing of Alberta’s COVID-19 measures Thursday, 678 new COVID-19 cases

The province also hit 1,500 COVID-19 deaths since the beginning of the pandemic

Terrance Josephson of the Princeton Posse, at left, and Tyson Conroy of the Summerland Steam clash during a Junior B hockey game at the Summerland Arena in the early spring of 2020. (John Arendt - Summerland Review)
QUIZ: How much do you know about hockey?

Test your knowledge of Canada’s national winter sport

A woman injects herself with crack cocaine at a supervised consumption site Friday, Jan. 22, 2021 in Ottawa. THE CANADIAN PRESS/Adrian Wyld
Drug users at greater risk of dying as services scale back in second wave of COVID-19

It pins the blame largely on a lack of supports, a corrupted drug supply

Jennifer Cochrane, a Public Health Nurse with Prairie Mountain Health in Virden, administers the COVID-19 vaccine to Robert Farquhar with Westman Regional Laboratory, during the first day of immunizations at the Brandon COVID-19 vaccination supersite in Brandon, Man., on Monday, January 18, 2021. THE CANADIAN PRESS/Tim Smith - POOL
Top doctor urges Canadians to keep up with COVID measures, even as vaccines roll out

More than 776,606 vaccines have been administered so far

Dr. Jerome Leis and Dr. Lynfa Stroud are pictured at Sunnybrook Hospital in Toronto on Thursday, January 21, 2021.THE CANADIAN PRESS/Frank Gunn
‘It wasn’t called COVID at the time:’ One year since Canada’s first COVID-19 case

The 56-year-old man was admitted to Toronto’s Sunnybrook Health Sciences Centre

FILE - In this Feb. 14, 2017, file photo, Oklahoma State Rep. Justin Humphrey prepares to speak at the State Capitol in Oklahoma City. A mythical, ape-like creature that has captured the imagination of adventurers for decades has now become the target of Rep. Justin Humphrey. Humphrey, a Republican House member has introduced a bill that would create a Bigfoot hunting season, He says issuing a state hunting license and tag could help boost tourism. (Steve Gooch/The Oklahoman via AP, File)
Oklahoma lawmaker proposes ‘Bigfoot’ hunting season

A Republican House member has introduced a bill that would create a Bigfoot hunting season

FILE - In this Nov. 20, 2017, file photo, Larry King attends the 45th International Emmy Awards at the New York Hilton, in New York. Former CNN talk show host King has been hospitalized with COVID-19 for more than a week, the news channel reported Saturday, Jan. 2, 2021. CNN reported the 87-year-old King contracted the coronavirus and was undergoing treatment at Cedars-Sinai Medical Center in Los Angeles. (Photo by Andy Kropa/Invision/AP, File)
Larry King, broadcasting giant for half-century, dies at 87

King conducted an estimated 50,000 on-air interviews

Black Press File Photo
Maskwacis RCMP lay charges for attempted murder, kidnapping, and flight from police

Female victim remains in hospital in serious condition.

In this Dec. 18, 2020 photo, pipes to be used for the Keystone XL pipeline are stored in a field near Dorchester, Neb.  THE CANADIAN PRESS/AP-Chris Machian /Omaha World-Herald via AP
‘Gut punch’: Alberta Premier Jason Kenney blasts Biden on revoked Keystone XL permit

Kenney said he was upset the U.S. wouldn’t consult with Canada first before acting

Joe Biden, then the U.S. vice-president, and Prime Minister Justin Trudeau take their seats at the start of the First Ministers and National Indigenous Leaders meeting in Ottawa, Friday, Dec. 9, 2016. THE CANADIAN PRESS/Adrian Wyld
Trudeau, Biden to talk today as death of Keystone XL reverberates in Canada

President Joe Biden opposed the Keystone XL expansion as vice-president under Barack Obama

Most Read