The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

CanadaCybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Two dead in COVID-19 outbreak at Delta Hospital

Total of 10 patients and four staff in one unit have tested positive for COVID-19: Fraser Health

Father hopes journey to aviation-safety program inspires hope

Former South Surrey resident Greg Sewell hasn’t given up on quest to mandate older-plane retrofits

Virtual challenge to benefit Delta-based guide dogs charity

Funds raised to help BC Alberta Guide Dogs provide people with free guide dogs, autism and PTSD service dogs

Surrey youth protest throne speech as part of Global Day of Action

Group marched to Liberal MP Randeep Sarai’s constituency office

White Rock writer in running for $6,000 accolade

Joseph Kakwinokanasum to learn Oct. 1 if his story, Ray Says, wins CBC Nonfiction Prize

B.C. records 98 more COVID-19 cases, most in Lower Mainland

One new senior home outbreak, Surrey Memorial outbreak over

PHOTOS: 2nd calf in a month confirmed among Southern Resident killer whale pod

Center for Whale Research said they will eagerly await to observe the calf to evaluate its health

97 distressed horses, cats and dogs seized from farm in Princeton

RCMP assisted as BC SPCA executed search warrant

$250K reward offered as investigation continues into Sea to Sky Gondola vandalism

Police also asking for specific footage of Sea to Sky highway around time of incident

Trudeau ‘disappointed’ by RCMP treatment of Sikh officers over mask issue

World Sikh Organization of Canada said taking Sikh officers off the front lines constitutes discrimination

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

Liberals reach deal with NDP on COVID-19 aid bill, likely averting election

NDP and the Liberals have reached an agreement on COVID-19 sick-leave

VIDEO: Mounties looking to catch Chilliwack bike-riding teen groper

Man caught on video slapping the backside of girl near CSS riding a bicycle

Money laundering inquiry delayed over of B.C. election: commissioner

Austin Cullen says the hearings will start again on Oct. 26

Most Read