Canada Revenue Agency suspends online services after cyberattacks

Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Friends Fraser O'Brien, Chris and Ben Reinhardt and Youngbin Kim enjoy a game of hockey on Okanagan Lake off Kin Beach Friday afternoon. (Jennifer Smith - Morning Star)
Synthetic ice an option for proposed outdoor rink in Vernon

Council to consider 3 options identified by staff regarding a new rink

Al Kowalko shows off the province's first electric school bus, running kids to three elementary and two secondary schools on the West Shore. (Zoe Ducklow/News Staff)
Okanagan schools shifting gears to electric buses

Vernon, Central Okanagan, Rocky Mountain and Okanagan-Skaha on board

Flooding around the entrance of Mission Creek into Okanagan Lake has been a reflection of the impact of climate change on the spring snowmelt across the Okanagan Valley watershed. (File photo)
B.C. water sustainability plan pitched to Okanagan stakeholders

Seeking resolution to water and land-use conflicts

Vernon Fire Rescue Services responded to a car fire on Anderson Way Friday, May 7, 2021. (Caitlin Clow - Morning Star)
Car fire snuffed in Vernon parking lot

The vehicle was fully engulfed upon crews’ arrival, according to Anderson Way Home Depot staff

Vernon North Okanagan RCMP reported to 287 mental health calls between Jan. 1, 2021, and May 1. (Black Press files)
Vernon Mounties respond to 287 mental health calls in 5 months

RCMP remind public to take care of mental health and well-being during national week

Protesters attempt to stop clear-cutting of old-growth trees in Fairy Creek near Port Renfrew. (Will O’Connell photo)
VIDEO: Workers, activists clash at site of Vancouver Island logging operation

Forest license holders asking for independent investigation into incident

Interior Health nurses administer Pfizer-BioNTech COVID-19 vaccines to seniors and care aids in Kelowna on Tuesday, March 16. (Phil McLachlan/Kelowna Capital News file)
People aged 30+ in Summerland, Rutland offered vaccine amid high transmission risk

Interior Health offers residents of Rutland and Summerland aged 30 and up chance at vaccine

Amazon is pausing its Prime Day marketing event in Canada this year amid ongoing COVID-19 outbreaks at its facilities in Ontario. THE CANADIAN PRESS/Nathan Denette
Amazon Prime Day halted in Canada due to COVID-19 outbreaks in warehouses

The postponement of the event was put in place to protect the health and safety of employees and customers, the company says

Ally Thomas, 12, seen in an undated family handout photo, died on April 14 from a suspected overdose. Her family says they are frustrated more public supports weren't available when they tried to get her help. THE CANADIAN PRESS
Minister says suspected overdose death of 12-year-old pushing B.C. to ‘do better’

Minister Sheila Malcolmson of Mental Health and Addictions says the government is working ‘as hard as we can’ to build a system of care for youths

At this Highway 3 check point, police officers will be asking for identification from drivers, documentation regarding the driver’s name and address, and the purpose for the driver’s travel. (RCMP)
No fines handed out at 1st COVID-19 roadblock as checks move across B.C.

Cpl. Chris Manseau says a total of 127 vehicles were stopped at a roadblock in the Manning Park area

A spectator looks on as the Olympic Caldron is relit in downtown Vancouver, Wednesday, February 12, 2020. THE CANADIAN PRESS/Jonathan Hayward
Small majority of B.C. residents in favour of a Vancouver 2030 Olympic bid: survey

A new survey shows a split over the possibility of public money being spent to organize and host the winter games

Alex Hegedus (left) with his wife and two young children. (Contributed/Kelowna RCMP)
Family offers reward for information about Peachland man’s suspicious 2018 death

Alex Hegedus died under suspicious circumstances in March 2018

Revelstoke’s Mayor Gary Sulz getting his COVID-19 vaccination on April 5. (Jocelyn Doll - Revelstoke Review)
Revelstoke is leading B.C.’s interior on vaccinations: Interior Health

Approximately 70% of the community has first dose of a COVID-19 vaccine

An unused fruit stand at Highway 97 and Road 1 went up in flames Thursday night. (Oliver Fire Department)
Abandoned South Okanagan fruit stand fire considered suspicious

The timing of the midnight fire is one reason the fire is suspicious

Most Read