Canada Revenue Agency suspends online services after cyberattacks

Canada Revenue Agency suspends online services after cyberattacks

Many of the hacked CRA accounts were targeted as part of a broader ‘credential stuffing’ attack

The Canada Revenue Agency has temporarily suspended its online services after two cyberattacks in which hackers used thousands of stolen usernames and passwords to fraudulently obtain government services and compromise Canadians’ personal information.

A total of 5,500 CRA accounts were targeted in what the federal government described as two “credential stuffing” schemes, in which hackers use passwords and usernames from other websites to access Canadians’ accounts with the revenue agency.

The decision to suspend CRA’s online services comes at a time when many Canadians and businesses have been using the revenue agency’s website to apply for and access financial support related to the COVID-19 pandemic.

The government is hoping to reinstate online access for businesses on Monday, according to a senior government official. That is when companies struggling due to the pandemic can start to apply for the latest round of federal wage subsidies.

It wasn’t immediately clear what impact the suspension of services will have in terms of other federal benefits, however, including the Canada Child Benefit and Canada Emergency Response Benefit for those affected by COVID-19.

The revenue agency was also vague in terms of what victims of the attack will have to do to get their accounts reinstated after it disabled them to prevent further fraud, saying only that letters will be mailed to those who have been affected.

At least one victim says she has yet to hear anything from the government after someone hacked into her CRA account earlier this month and successfully applied for the $2,000-per-month Canada Emergency Response Benefit for COVID-19.

Leah Baverstock, a law clerk in Kitchener, Ont., says she first realized her account had been compromised and contacted the revenue agency herself when she received several emails from CRA on Aug. 7 saying she had successfully applied for the CERB.

“The lady I spoke to at CRA, she’s said: ‘This is a one-off,’” said Baverstock, who has continued to work through the pandemic and did not apply for the support payments.

“And she told me a senior officer would be calling me within 24 hours because my account was completely locked down. And I still haven’t heard from anybody.”

READ MORE: Thousands of CRA and government accounts disabled after cyberattack

Baverstock expressed frustration at the lack of contact, adding she still does not know how the hackers accessed her account. She has since contacted her bank and other financial institutions to stop the hackers from using her information to commit more fraud.

“I am quite concerned,” she said. “Somebody could be living under my name. Who knows. It’s scary. It’s really scary.”

Many of the hacked CRA accounts were targeted as part of a broader “credential stuffing” attack in which more than 9,000 accounts that Canadians use to apply for and access federal services were compromised.

Those hacked accounts were tied to GCKey, which is used by around 30 federal departments and allows Canadians to access various services such as employment insurance, veterans’ benefits and immigration applications.

“These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts,” the Treasury Board of Canada said in a statement.

One-third of those accounts successfully accessed services before all of the affected accounts were shut down, said the Treasury Board, which is responsible for managing the federal civil service as well as the public purse.

Officials are now trying to determine not only how many of those services were fraudulent while the RCMP and federal privacy commissioner have been called in to assess the scale and scope of personal information stolen.

The government warned Canadians to use unique passwords for all online accounts and to monitor them for suspicious activity.

The Canadian Anti-Fraud Centre says more than 13,000 Canadians have been victims of fraud totalling $51 million this year. There have been 1,729 victims of COVID-19 fraud worth $5.55 million.

Lee Berthiaume, The Canadian Press


Like us on Facebook and follow us on Twitter.

Want to support local journalism during the pandemic? Make a donation here.

Canadian Revenue AgencyCyberfraudfraudhackers

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Interior Health reported 91 new COVID-19 cases in the region Jan. 20, 2021 and three additional deaths. (Jennifer Smith - Morning Star)
95 new COVID-19 cases in Interior Health, two deaths

Another member of Vernon’s Noric House has passed

Voting is the number one, bare minimum way to have your voice heard by government. (File photo)
Jocelyn’s Jottings: Want to make change? Here are some suggestions

As a citizen you have a voice, you just have to know who to talk to

Amanda Parsons, a registered nurse on staff at the Northwood Care facility, administers a dose of the Moderna vaccine to Ann Hicks, 77, in Halifax on Monday, Jan. 11, 2021. THE CANADIAN PRESS/Andrew Vaughan-Pool
61 new COVID-19 cases, two more deaths in Interior Health

Twenty-nine people are in hospital, seven of whom are in intensive care

Community mental health workers are in high demand, and a new program at Selkirk College will provide opportunities in this field. File Photo
Selkirk College to train community mental health workers

Twelve students will complete two courses enabling them to work in health and human services

Toronto Public Health nurse Lalaine Agarin sets up for mass vaccination clinic in Toronto, Jan. 17, 2021. B.C. is set to to begin its large-scale immunization program for the general public starting in April. THE CANADIAN PRESS/Frank Gunn
B.C.’s COVID-19 mass vaccinations expected to start in April

Clinics to immunize four million people by September

Chief Public Health Officer Theresa Tam speaks during a daily briefing in Ottawa. (THE CANADIAN PRESS/Adrian Wyld)
31 cases of COVID-19 variants detected in Canada: Health officials

Dr. Theresa Tam made announces 13 more variant COVID-19 cases in Canada

Royal Inland Hospital in Kamloops. (Dave Eagles/Kamloops This Week file photo)
COVID-19 outbreak declared at Kamloops’ Royal Inland Hospital surgical unit

Despite 6 South being a surgical unit, RIH said surgeries are continuing at the hospital

Daily COVID-19 cases reported to each B.C. health region, to Jan. 20, 2021. Island Health in blue, Northern Health green, Interior Health orange, Vancouver Coastal in red and Fraser Health in purple. (B.C. Centre for Disease Control)
B.C.’s COVID-19 infection rate stays stable with 508 cases Friday

Vaccine delivered to more than 110,000 high-risk people

Volunteer firefighters from Grand Forks Fire/Rescue head towards the scene of fatal car crash near Gibbs Creek Road, below Highway 3, Thursday evening, Jan. 21. Photo: Laurie Tritschler
Motorist dies in Highway 3 crash west of Grand Forks

City first responders were called to the scene Thursday evening, Jan. 21

Vancouver Giants defenceman Bowen Byram could be playing for Colorado when the NHL resumes play. (Rik Fedyck/file)
Cranbrook product Bowen Byram makes NHL debut with Avalanche

Highly touted prospect marks first pro game following World Junior tournament in Alberta

The District of Saanich’s communications team decided to take part in a viral trend on Thursday and photoshopped U.S. Senator Bernie Sanders into a staff meeting photo. (District of Saanich/Twitter)
Bernie Sanders makes guest appearance municipal staff meeting in B.C.

Vancouver Island firefighters jump on viral trend of photoshopped U.S. senator

School District 57 headquarters in Prince George. (Mark Nielsen, Local Journalism Initiative Reporter)
Prince George school district settles with sexual abuse victim

Terms were part of an out-of-court settlement reached with Michael Bruneau, nearly four years after he filed a lawsuit

Surrey provincial court. (File photo: Tom Zytaruk)
New COVID-19 protocols set for provincial courthouses

The new rules were issued on Jan. 21, and took effect immediately

Most Read