The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Here’s the latest on the proposed inland port development process

Council to discuss proposal Sept. 28, public hearing to be held approximately one month later

Cullen confirmed as B.C. NDP candidate for Stikine despite party’s equity policy

Former Tahltan Central Government President Annita McPhee said the process made her feel “abused”

Financial fallback plan in place for Mills Memorial replacement

That’s in case province rejects first submission

Local Skeena candidates for the Oct. 24 snap election

Current BC Liberal MLA Ellis Ross will be running again, as will Nicole Halbauer for BC NDP

B.C. reports 91 new cases as officials remain worried over ‘clusters of COVID-19

There have now been a total of 8,395 cases in B.C. since the pandemic began

Canada’s active COVID-19 cases top 10,000 as daily new cases triple over the past month

Dr. Tam repeated her warning to young people, who have made up the majority of recent cases

First 8 months of fatal overdoses in B.C. have now exceeded 2019 death toll

Nine people died every two days in August, BC Coroners Service data shows

Liberal effort to reset policy agenda panned by rivals as too much talk, not action

Trudeau said it’s ‘all too likely’ families won’t be able to gather for Thanksgiving next month

‘Show us the money’ for cannabis, local governments tell B.C.

Municipal tax, transit revenues falling as costs rise

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

‘It’s a boy’: Southern Resident killer whale calf born to J Pod is healthy, researchers say

J35 had previously done a ‘Tour of Grief,’ carrying her dead calf for 17 days

People ‘disgusted’ by COVID-19 election call, B.C. Liberal leader says

Andrew Wilkinson speaks to municipal leaders from Victoria

Horgan blasts B.C. Greens for refusing youth overdose detention

Lack of support key to B.C. election call, NDP leader says

Most Read