The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

CH-149 Cormorant helicopters may be part of night training exercises in the Chilcotin this month. (Canadian Armed Forces photo)
442 Transport and Rescue Squadron to hold night training in the Chilcotin

The public may see flares and search and rescue technicians parachuting to the ground

Snow is in the forecast for Williams Lake Friday, Oct. 23, which has already been falling in areas of the Chilcotin as seen here at Nimpo Lake. (Harriet Hird photo)
Ice, snow, chilly temperatures in forecast for Williams Lake area

Temperatures will dip down to -11C on Friday evening

COVID-19. (Courtesy of CDC).
Interior Health reports 12 additional COVID-19 cases

The total number of cases in the region is now at 644

100 Mile Conservation officer Joel Kline gingerly holds an injured but very much alive bald eagle after extracting him from a motorist’s minivan. (Photo submitted)
Motorist pulls into B.C. RCMP detachment after roadkill eagle comes back to life in minivan

The driver believed the bird to be dead and not unconscious as it turned out to be

Actor Ryan Reynolds surprised a Shuswap family with a special birthday message to their son who was worried he’d be alone on his 9th birthday on Nov. 24. (Tiffanie Trudell/Facebook)
Ryan Reynolds text almost gives away Shuswap boy’s birthday surprise

Deadpool actor helps remind eight-year-old Canoe resident he’s not alone

Vancouver police reactivated the search for Jordan Naterer Thursday Oct. 22. Photo courtesy of VPD.
Mom of missing Manning Park hiker believes her son is waiting to come home

‘He’s going to come out of a helicopter and say ‘what took you so long?”

Is it time to start thinking about greener ways to package cannabis?

Packaging suppliers are still figuring eco-friendly and affordable packaging options that fit the mandates of Cannabis Regulations

Environment Minister George Heyman, Premier John Horgan and Energy Minister Michelle Mungall announce that B.C. Hydro is proceeding with construction of the Site C dam, Dec. 11, 2017. (Tom Fletcher/Black Press)
Site C actions, costs won’t be known until after B.C. election, Horgan says

Peace River diverted for construction of reinforced dam base

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

One of the squirrels who ended up having their tails amputated after getting them stuck together with tree sap. (Facebook/Wild ARC)
Squirrels recovering from tail amputation after sap situation near Victoria

BC SPCA Wild ARC says squirrels will be released back into wild, fifth sibling was euthanized

More and more electric cars are on the road, but one Chevy Bolt owner was shocked to see how much his BC Hydro bill skyrocketed once he started charging the vehicle. (Black Press file photo)
Lower Mainland man sees significant spike in BC Hydro bill after buying electrical vehicle

An increase should be expected, but Brian Chwiendacz experienced a 200-plus per cent hike

Most Read