The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

A health-care worker prepares a dose of the Pfizer-BioNTech COVID-19 vaccine at a UHN COVID-19 vaccine clinic January 7, 2021. THE CANADIAN PRESS/Nathan Denette
Employers might be able to require COVID-19 vaccination from employees: B.C. lawyer

‘An employer must make the case’ using expert science, explains lawyer David Mardiros

Provincial health officer Dr. Bonnie Henry updates B.C.’s COVID-19 situation at the legislature, Jan. 11, 2021. (B.C. government)
Vancouver Island smashes COVID-19 high: 47 new cases in a day

Blowing past previous records, Vancouver Island is not matching B.C.s downward trend

Stand up paddleboarder Christie Jamieson kneels as a pod of transient orcas put on a dramatic show on Jan. 19 in the Ucluelet Harbour. (Nora O’Malley photo)
UPDATED: Vancouver Island paddle boarder’s orca encounter brings joy and outrage

Woman’s ‘best day’ criticized for disturbing the whales

Tofino’s library is currently located in the basement of the Tofino Legion building but talks are underway to build a brand new facility. (Andrew Bailey photo)
Terrance Josephson of the Princeton Posse, at left, and Tyson Conroy of the Summerland Steam clash during a Junior B hockey game at the Summerland Arena in the early spring of 2020. (John Arendt - Summerland Review)
QUIZ: How much do you know about hockey?

Test your knowledge of Canada’s national winter sport

Nanaimo Regional General Hospital. (News Bulletin file photo)
COVID-19 outbreak declared at Nanaimo hospital

Two staff members and one patient have tested positive, all on the same floor

A long-term care worker receives the Pfizer vaccine at a clinic in Nanaimo earlier this month. (Island Health photo)
All Island seniors in long-term care will be vaccinated by the end of this weekend

Immunization of high-risk population will continue over the next two months

A 75-year-old aircraft has been languishing in a parking lot on the campus of the University of the Fraser Valley, but will soon be moved to the B.C. Aviation Museum. (Paul Henderson/ Chilliwack Progress)
Vintage military aircraft moving from Chilliwack to new home at B.C. Aviation Museum

The challenging move to Vancouver Island will be documented by Discovery Channel film crews

A video posted to social media by Chilliwack resident Rob Iezzi shows a teenager getting kicked in the face after being approached by three suspects on Friday, Jan. 22, 2021. (YouTube/Rob i)
VIDEO: Security cameras capture ‘just one more assault’ near B.C. high school

Third high-school related assault captured by Chilliwack resident’s cameras since beginning of 2021

FILE - In this Feb. 14, 2017, file photo, Oklahoma State Rep. Justin Humphrey prepares to speak at the State Capitol in Oklahoma City. A mythical, ape-like creature that has captured the imagination of adventurers for decades has now become the target of Rep. Justin Humphrey. Humphrey, a Republican House member has introduced a bill that would create a Bigfoot hunting season, He says issuing a state hunting license and tag could help boost tourism. (Steve Gooch/The Oklahoman via AP, File)
Oklahoma lawmaker proposes ‘Bigfoot’ hunting season

A Republican House member has introduced a bill that would create a Bigfoot hunting season

Economic Development and Official Languages Minister Melanie Joly responds to a question in the House of Commons Monday November 23, 2020 in Ottawa. THE CANADIAN PRESS/Adrian Wyld
Federal minister touts need for new B.C. economic development agency

Last December’s federal economic update promised a stimulus package of about $100 billion this year

FILE - In this Nov. 20, 2017, file photo, Larry King attends the 45th International Emmy Awards at the New York Hilton, in New York. Former CNN talk show host King has been hospitalized with COVID-19 for more than a week, the news channel reported Saturday, Jan. 2, 2021. CNN reported the 87-year-old King contracted the coronavirus and was undergoing treatment at Cedars-Sinai Medical Center in Los Angeles. (Photo by Andy Kropa/Invision/AP, File)
Larry King, broadcasting giant for half-century, dies at 87

King conducted an estimated 50,000 on-air interviews

Comox Valley RCMP are looking for witnesses after the theft of a generator worth thousands of dollars. Photo supplied
RCMP asking Vancouver Island residents to watch for stolen generator

Vehicle may have been travelling on Highway 19

Most Read