Canada Revenue Agency suspends online services after cyberattacks

Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

A rendering of the Lumina building proposed for 41-45 Haliburton St. in Nanaimo. (Matthew T. Hansen Architect image)
Next project proposed as part of a series of buildings on Nanaimo’s Haliburton Street

Five-storey building near Finlayson Street will include 38 residential units

Capt. Bryun Ashlie, left, and Lieut. Stu Kenning, of Nanaimo Fire Rescue, tackle fires burning in two shopping carts in St. George Ravine Park, Thursday afternoon. The cause of the fire, which destroyed both carts and their contents, is undetermined. (Chris Bush/News Bulletin)
Shopping carts found burning in Nanaimo park

Firefighters douse flaming carts and contents on asphalt pathway

Nanaimo RCMP are looking for a motorcyclist who refused to stop for police near the Nanaimo River Road and White Rapids Road intersection on April 10. (Photo submitted)
Nanaimo RCMP seek ‘stunting’ motorcyclist, who fled from police

Rider spotted near intersection of Nanaimo River Road and White Rapids Road April 10

Nanaimo RCMP say a man was injured while pouring gunpowder on a backyard fire in Harewood on Wednesday, April 21. (File photo)
Nanaimo man hospitalized after pouring gunpowder onto backyard fire

RCMP investigating explosion in Harewood also came across a still for making alcohol on the property

A B.C. Centre for Disease Control map shows new COVID-19 cases by local health area for the week of April 11-17. (BCCDC image)
Nanaimo sees fewest new COVID-19 cases since mid January

B.C. Centre for Disease Control reports 31 new COVID-19 cases in Greater Nanaimo from April 11-17

Canadian Prime Minister Justin Trudeau and United States President Joe Biden smile as they say farewell following a virtual joint statement in Ottawa, Tuesday, February 23, 2021. THE CANADIAN PRESS/Adrian Wyld
Trudeau pledges to cut emissions by 40% to 45% by 2030, short of U.S. goal

Trudeau announced target during a virtual climate summit convened by U.S. President Joe Biden

Richard Desautel with supporters outside the courthouse in Nelson, B.C., in 2016. Photo: Bill Metcalfe
BREAKING: Sinixt win historic decision at Supreme Court of Canada

The decision essentially reverses a 1956 declaration the Sinixt were extinct

MLA Shirley Bond, right, answers questions during a press conference at Legislature in Victoria, B.C., on February 19, 2019. THE CANADIAN PRESS/Chad Hipolito
Former B.C. gaming minister says she wasn’t told directly about dirty cash flowing to casinos

Shirley Bond said Thursday civil forfeiture, gang violence and gambling addiction were also major concerns in 2011

RCMP Constable Etsell speaks to tourists leaving the area at a police roadblock on Westside Road south of Fintry, B.C., Thursday, July 23, 2009. THE CANADIAN PRESS/ Yvonne Berg
B.C. police say they take ‘exception’ to conducting roadblocks limiting travel

Asking the police to enforce roadblocks exposes officers to further risk and possible COVID-19 infections, says federation president Brian Sauve

As part of the province’s strategy to combat the opioid overdose crisis, take-home naloxone kits have been distributed throughout the province. (Courtesy of Gaëlle Nicolussi)
Vancouver Island could be at its worst point of overdose crises yet: medical health officer

Island Health issued overdose advisories for Victoria, various communities in the last two weeks

The conservation service confirmed they do not relocate cougars from settled areas but that euthanasia is not necessarily the fate for an animal in the Fanny Bay area. The hope is that the animal will move on to wild areas. (File photo)
Woman hopes cat-stalking Fanny Bay cougar can avoid euthanization

Conservation officers do not relocate the animals from Vancouver Island

Tofino residents expressed frustration over a recent post by Long Beach Lodge owner Tim Hackett that falsely claimed all residents have been vaccinated. (Westerly file photo)
Resort owner apologizes for suggesting Tofino is safe to travel to

Long Beach Lodge owner Tim Hackett apologizes to community and visitors

BC Hydro released a survey Thursday, April 22. It found that many British Columbians are unintentionally contributing to climate change with their yard maintenance choices. (Pixabay)
Spend a lot of time doing yard work? It might be contributing to climate change

Recent BC Hydro survey finds 60% of homeowners still use gas-powered lawnmowers and yard equipment

Journal de Montreal is seen in Montreal, on Thursday, April 22, 2021. The daily newspaper uses a file picture of Prime Minister Justin Trudeau dressed in traditional Indian clothing during his trip to India to illustrate a story on the Indian variant of the coronavirus. Paul Chiasson/The Canadian Press
Montreal newspaper blasted for front-page photo of Trudeau in India

Trudeau is wearing traditional Indian clothes and holding his hands together in prayer beside a caption that reads, ‘The Indian variant has arrived’

Most Read