The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Willie Mitchell’s Fish for the Future catch-and-release derby nets $60,000 for wild salmon

“I liked releasing the fish because I know there are not that many salmon left.”

North Island All Candidates Meeting scheduled virtually for Oct. 14

‘our local candidates for the B.C. Provincial Election will be joining us’

Abandoned Neucel mill in Port Alice to cost at least $17 million to decommission

Removing hazardous waste and de-risking the site ratchet up bill to taxpayers

Growing food sovereignty at Klemtu

Greenhouse and grow boxes help create circular food economy for Kitasoo/Xai’xais First Nations

B.C. salmon farms challenge activists’ demands for site closures

News reporting also unfair, inaccurate and distorted

B.C. starts October with 82 more positive COVID-19 tests

10,899 tests a record for a single day, Bonnie Henry says

Missing mushroom picker in northern B.C. found dead

Witset elder found deceased in Price Creek area more than two weeks after he vanished

BC Greens focus on long-term care reform in first platform promise

Greens have promised to move away from the for-profit care home model

‘It’s a nightmare’: Northern B.C. family desperate after living in hotel for a year

Renae Podgorney says because of a lack of rentals, she’s now applying to rent a one-bedroom unit

Costs climb to more than $100K for BC SPCA to care for animals in B.C. farm seizure

Eight puppies, of the 97 animals seized have now died from parvovirus enteritis

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

B.C. VOTES 2020: Wilkinson to stop 24-hour camping in city parks

Ban on ‘unsafe roadside panhandling’ to be enforced

Be prepared and drive safely, say BC RCMP as winter draws closer

Police provide list of ways to stay safe while driving in winter conditions

Lessons from a pandemic: How to design a nursing home that’s safe and love-filled

A look at how one care home is battling the pandemic with the social needs of the elderly in their care

Most Read