The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Single-engine aircraft crashes near Telkwa

Two occupants of the plane sustained minor injuries and were transported to hospital

Search on for mushroom picker missing from near Kitwanga

Tommy Dennis was last seen Sept 16 wearing blue jeans, black cap, rubber boots, grey checked sweater

Northwest firefighters headed to Oregon to battle wildfires

Over 200 B.C. firefighting personnel will assist in the U.S.

Cullen announces bid for provincial NDP nomination for Stikine riding

Current MLA Donaldson not seeking re-election

Another Telkwa councillor calls it quits

Councillor Rick Fuerst is the second Telkwa council member to hang up his hat since the 2018 election

VIDEO: B.C. to launch mouth-rinse COVID-19 test for kids

Test involves swishing and gargling saline in mouth and no deep-nasal swab

Man sentenced to 7 years for gas-and-dash death of Alberta gas station owner

Ki Yun Jo was killed after Mitchell Sydlowski sped off in a stolen cube van without paying for $198 of fuel

70-year-old punched in the head in dispute over disability parking space in Nanaimo

Senior’s turban knocked off in incident at mall parking lot

CHARTS: Beyond Metro Vancouver, COVID-19 cases in B.C. haven’t increased much recently

COVID-19 case counts outside of Metro Vancouver have been level since July

Record-breaking 165 new COVID-19 cases diagnosed in B.C. in 24-hour period

Fifty-seven people are in hospital battling the novel coronavirus

B.C. teachers file Labour Relations Board application over COVID-19 classroom concerns

The application comes as B.C.’s second week of the new school year comes to a close

Young Canadians have curtailed vaping during pandemic, survey finds

The survey funded by Heart & Stroke also found the decrease in vaping frequency is most notable in British Columbia and Ontario

B.C.’s COVID-19 economic recovery plan: Top 5 things you need to know

Jobs training, tax incentives for employers to hire staff and more

March to protect old growth, stop industrial logging coming to B.C. Legislature

Organizers say they want to give frontline communities a bigger say in nearby logging

Most Read