The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

The Town of Sylvan Lake has launched a new contest to attract a new business. (File photo by Advocate staff)
Sylvan Lake offering rent-free storefront space to lure new businesses

Winning business proposal will get a storefront space rent-free for a year

Alberta reported an additional 399 cases of COVID-19 Thursday, on 9,217 tests, for a test positivity rate of 4.3 per cent. (Image courtesy CDC)
Red Deer down to 562 active COVID-19 cases

8 new COVID-19 deaths, 399 additional COVID-19 cases

Mike Ammeter (Photo by Rebecca Hadfield)
Sylvan Lake man elected chair of Canadian Canola Growers Association

Mike Ammeter is a local farmer located near the Town of Sylvan Lake

Students and staff at Gateway Christian School wore pink Wednesday in support of Pink Shirt Day, a worldwide anti-bullying initiative that was started in 2007. (Photo courtesy of Red Deer Public Schools)
Students, central Alberta community celebrate Pink Shirt Day

Mayor of Sylvan Lake Sean McIntyre supports anti-bullying cause

City of Red Deer has nearly doubled its active COVID-19 case count since Feb. 10 and has 75.6 per cent of the Central zone’s active cases. (File photo)
Another new high: Red Deer hits 574 active COVID-19 cases

Province reports 13 new COVID-19 deaths, 430 new cases

Bookings for COVID-19 vaccines for people age 75 or older start Wednesday. (File photo by THE CANADIAN PRESS)
Updated: Delays for seniors booking for vaccine appointments

By 9:20 a.m. Wednesday, 4,500 seniors had booked their appointments

Alberta premier Jason Kenney, right and Doug Schweitzer, Minister of Justice and Solicitor General, provide details about Bill 13, the Alberta Senate Election Act., in Edmonton Alta, on Wednesday June 26, 2019. THE CANADIAN PRESS/Jason Franson
Minister Doug Schweitzer talks on Enhanced COVID-19 Business Benefit

Provincial government rolling out new benefit this April to better help small businesses.

NDP leader Jagmeet Singh holds a press conference on Parliament Hill in Ottawa on Wednesday, Feb. 24, 2021. THE CANADIAN PRESS/Sean Kilpatrick
NDP will not trigger election as long as pandemic continues: Singh

‘“We will vote to keep the government going’

Minister Rick Wilson poses with Katie at the Boys and Girls Club of Wetaskiwin, both wearing her Pink Shirt Day design. Facebook/ Boys and Girls Club of Wetaskiwin.
Wetaskiwin Boys and Girls club Pink Shirt day design focuses on kindness

Katie with the Boys and Girls Club of Wetaskiwin created this year’s Pink Shirt Day design.

Black Press File Photo
Valentine’s Day shooting in Maskwacis leaves one male in hospital, one male in custody

19-year-old Francis Edward Nepoose from Maskwacis has been charged with attempted murder.

Sentencing delayed in the stabbing death of Samantha Sharpe, of Sunchild First Nation. (Red Deer Advocate file photo)
Central Alberta man not criminally responsible for killing his father in 2020: judge

Psychiatrist testified Nicholas Johnson was psychotic when he killed his father

The cover of “Hometown Asylum: A History and Memoir of Institutional Care.” (Submitted)
Ponoka-born author writes history of old mental hospital

“Hometown Asylum: A History and Memoir of Institutional Care” covers 1911 to 1971

Jacqueline Buffalo. (Photo submitted)
TikTok connects Indigenous women during pandemic

Maskwacis influencers share their stories

Most Read