The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

CanadaCybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Horgan’s election call ‘nakedly opportunistic,’ political scientist says

Premier says campaign will ‘fully comply’ with public health directions

Dozens of Canadian venues to light up red in support of entertainment workers

Local facilities among dozens across Canada to participate in Light Up Live

Canada West Golf Championships cancelled due to COVID-19 travel restrictions

UBC, UBC-O, UFV and UVic athletes will not hit the links this year, Kelowna was set to host

PHOTOS: Inside Surrey’s new in-rink private school, which isn’t all about hockey

Glarea Elevated Learning school has opened at Excellent Ice

CRIME STOPPERS: ‘Most wanted’ for the week of Sept. 20

Crime Stoppers’ weekly list based on information provided by police investigators

B.C. reports 96 new COVID-19 cases, one hospital outbreak

61 people in hospital as summer ends with election

‘Unprecedented’ coalition demands end to B.C. salmon farms

First Nations, commercial fishermen among group calling for action on Cohen recommendations

Earthquake off coast of Washington recorded at 4.1 magnitude

The quake was recorded at a depth of 10 kilometres

B.C.’s top doctor says she’s received abuse, death threats during COVID-19 response

Henry has become a national figure during her time leading B.C.’s response to the COVID-19 pandemic

BC Liberals must change gears from election cynicism, focus on the issues: UBC professors

COVID-19 response and recovery is likely to dominate platforms

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

B.C. could be without a new leader for multiple weeks after Election Day: officials

More than 20K mail-in voting packages were requested within a day of B.C. election being called

Vancouver Island sailor stranded in U.S. hospital after suffering massive stroke at sea

Oak Bay man was attempting to circumnavigate the world solo

Majority needed to pass COVID-19 budget, B.C. premier says

John Horgan pushes urgent care centres in first campaign stop

Most Read