Canada Revenue Agency suspends online services after cyberattacks

Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Two of the heritage buildings from McLean Mill National Historic Site that have been restored at the Port Alberni tourist attraction. (SUSAN QUINN/ Alberni Valley News)
McLean Mill application breaks new ground for ALC

Process just another ‘misstep’ by city, says critic

Coulson Aviation’s newest Chinook helicopter, N43CU, takes to the air above the Alberni Valley Regional Airport following a complete airframe conversion into a helitanker, April 8, 2021. (PHOTO COURTESY BILL MCLEOD)
Coulson Aviation’s newest helitanker takes flight

Converted Chinook helitanker off to U.S. for new paint job

Dave Cusson, Community Policing Manager with the City of Port Alberni, offers some tips for pedestrian safety in a Community Policing video. (SCREENSHOT)
City of Port Alberni on way to dubious pedestrian safety record

Pedestrian crashes a growing concern in Port Alberni

Photo collage of loved ones lost to substance use and overdose. (Photo courtesy Moms Stop The Harm)
B.C. overdose deaths still rising 5 years after public health emergency declared

Moms Stop the Harm calls on B.C. to provide safe supply in response to deadly illicit drug use

The PAGo Grannies have a table set up at a farmer’s market to sell handcrafted items to raise funds for the Stephen Lewis Foundation’s Grandmothers to Grandmothers campaign. (SUBMITTED PHOTO)
PAGo Grannies promote nationwide concert for Stephen Lewis Foundation

Register online to watch Together in Concert starting April 15

A screenshot from a Nuu-chah-nulth healing song and performance created in collaboration between Hjalmer Wenstob and Timmy Masso. (Screenshot from YouTube)
WATCH: Tla-o-qui-aht First Nation brothers produce COVID-19 healing song

Hjalmer Wenstob and Timmy Masso share dance and inspiration.

Health Canada headquarters in Ottawa. (Sean Kilpatrick/The Canadian Press)
Health Canada releases guidelines for reducing COVID-19 transmission at home

Improve indoor air quality by opening up your windows and doors, among the encouraged ventilation measures

Flow Academy is not accepting membership applications from anybody who has received a dose of the vaccine, according to a password-protected membership application form. (Submitted image)
B.C. martial arts gym refusing patrons who have been vaccinated, wear masks

Interior Health has already issued a ticket to Flow Academy for non-compliance with public health orders

MP Todd Doherty took to Facebook after his family recently received threats. (Todd Doherty, MP Facebook photo)
‘I don’t run and I don’t hide’: Cariboo MP says RCMP probing threats made against family

Todd Doherty has also notified House of Commons Protective Services

Two men walk past a sign on Main Street in downtown Vancouver, B.C., Monday, April 5, 2021. THE CANADIAN PRESS/Jonathan Hayward
Calls for government transparency in COVID data continue as B.C.’s 3rd wave wears on

Social media, where both information and misinformation can spread like wildfire, has not helped

The music video for “Green and Blue” featured a Willington Care Centre in Burnaby as well as some of the volunteers and employees. (Screenshot/Todd Richard)
‘Green and Blue’: B.C. country musician releases tribute song for front-line workers

Richard’s new single has been viewed more than 3,000 times on his YouTube channel

An unidentified B.C. man said, in a human rights complaint, that he was refused a contract job after refusing to wear a mask when asked to by an on-site manager. (Unsplash)
Religious B.C. man lodges human rights complaint after fired for refusing to wear a mask

Worker’s claim that ‘to cover up our face infringes on our God-given ability to breathe’ dismissed by B.C. Human Rights Tribunal

Cannabis bought in British Columbia (Ashley Wadhwani/Black Press Media)
Is it time to start thinking about greener ways to package cannabis?

Packaging suppliers are still figuring eco-friendly and affordable packaging options that fit the mandates of Cannabis Regulations

Most Read