The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

Unofficial holidays: Here’s what people are celebrating for the week of Sept. 27 to Oct. 3

World Farm Animals Day, Drink Beer Day and Virus Appreciation Day are all coming up this week

COVID-19 cases grow to 13 at B.C. First Nation near Fort St. James

“This is very serious,” says Nak’azdli Whut’en Chief

Cullen confirmed as B.C. NDP candidate for Stikine despite party’s equity policy

Former Tahltan Central Government President Annita McPhee said the process made her feel “abused”

Freeport — the camp site that was the region’s largest community

A story of the construction of the Grand Trunk Pacific Railway

Burns Lake to get a pedestrian-activated light

The blind turn at the RBC crossing to get safer

QUIZ: Do you know what’s on TV?

Fall is normally the time when new television shows are released

B.C. marriage annulled because husband was unable to have sex with wife

Husband did not disclose any sexual health concerns to his wife prior to marriage

White Rock’s namesake spray-painted with Black Lives Matter slogan

Vandalism occurred sometime between Friday and Saturday

B.C. VOTES 2020: B.C. Liberals vow to eliminate sales tax for a year

From 7% to zero, then back in at 3% to stimulate economy

Join Black Press Media and Do Some Good

Pay it Forward program supports local businesses in their community giving

The holiday everyone needs this year: Vote for your favourite in Fat Bear Week 2020

Voters will get to decide who gets to take home this year’s most coveted prize

Canadian ski resorts wrestle with pandemic-vs.-profit dilemma as COVID-19 persists

Few are actually restricting the total number of skiers they allow on the hill

Victoria-area RCMP locate high-risk sex offender thanks to help of taxi cab driver

Scott Jones wanted on a Canada-wide warrant, ‘a risk to women and girls,’ police say

Most Read