The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

There were six additional deaths across Alberta reported over the past 24 hours, bringing the death toll to 1,926 since the beginning of the pandemic. (File photo)
file photo
Wetaskiwin RCMP respond to break and enter and theft at a Wetaskiwin church

RCMP responded to a break and enter and theft at Jesus Cares Fellowship Church.

file photo
County of Wetaskiwin office to re-open Monday April 19, 2021

County of Wetaskiwin is re-opening their office and public works shops to the public on April 19

Dr. Wayne John Edwards, 66, died Tuesday at Chinook Regional Hospital. (Cornerstone Funeral Home)
Lethbridge doctor becomes 7th Alberta health-care worker to die from COVID-19

Dr. Wayne John Edwards, who was 66, died Tuesday at the Chinook Regional Hospital in the southern Alberta city

Pall Bearers carrying the coffin of the Duke of Edinburgh, followed by the Prince of Wales, left and Princess Anne, right, into St George’s Chapel for his funeral, at Windsor Castle, in Windsor, England, Saturday April 17, 2021. (Danny Lawson/Pool via AP)
Trudeau announces $200K donation to Duke of Edinburgh award as Prince Philip laid to rest

A tribute to the late prince’s ‘remarkable life and his selfless service,’ the Prime Minister said Saturday

A vial of some of the first 500,000 AstraZeneca COVID-19 vaccine doses that Canada secured. THE CANADIAN PRESS/Carlos Osorio
Canada’s 2nd blood clot confirmed in Alberta after AstraZeneca vaccine

The male patient, who is in his 60s, is said to be recovering

The funeral of Britain’s Prince Philip in Windsor, England, on Saturday, April 17, 2021. Philip died April 9 at the age of 99. (Kirsty Wigglesworth/AP)
PHOTOS: Prince Philip laid to rest Saturday as sombre queen sits alone

The entire royal procession and funeral took place out of public view within the grounds of Windsor Castle

Prime Minister Justin Trudeau looks on as Deputy Prime Minister and Finance Minister Chrystia Freeland responds to a question during a news conference on Parliament Hill in Ottawa, Tuesday, Aug. 18, 2020. THE CANADIAN PRESS/Adrian Wyld
Expectations high as Trudeau Liberals get ready to unveil first pandemic budget

The Liberals will look to thread an economic needle with Monday’s budget

Doses of the Moderna COVID‑19 vaccine in a freezer trailer, to be transported to Canada during the COVID-19 pandemic. THE CANADIAN PRESS/Nathan Denette
Pfizer to increase vaccine deliveries in Canada as Moderna supply slashed

Moderna plans to ship 650,000 doses of its vaccine to Canada by the end of the month, instead of the expected 1.2 million

A empty classroom is pictured at Eric Hamber Secondary school in Vancouver, B.C. Monday, March 23, 2020. The Alberta government says schools in Calgary will move to at-home learning starting Monday for students in grades 7 to 12.THE CANADIAN PRESS/Jonathan Hayward
Calgary schools to shift to at-home learning for grades 7 to 12 due to COVID-19

The change, due to COVID-19, is to last for two weeks

A man wears a protective face covering to help prevent the spread of COVID-19 as he walks past the emergency entrance of Vancouver General Hospital in Vancouver, B.C., Friday, April 9, 2021. THE CANADIAN PRESS/Jonathan Hayward
COVID-19 spike in B.C. could overwhelm B.C. hospitals: modelling group

There are 397 people are in hospital due to the virus, surpassing a previous high of 374 seen in December

Most Read