The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

The Canada Revenue Agency (CRA) headquarters Connaught Building is pictured in Ottawa on Monday, Aug. 17, 2020. THE CANADIAN PRESS/Sean Kilpatrick

CRA resumes online services with new security features after cyberattacks

All individuals affected by the cybersecurity breaches will receive a letter from the CRA

The Canada Revenue Agency has resumed all online services after fraudsters used thousands of pilfered usernames and passwords to obtain government services.

The agency disabled the services Saturday after discovering more than 5,000 accounts had been the target of three cyberattacks.

Online access to “My Business Account” resumed Monday and all others were brought back online Wednesday evening.

The agency says it regrets the impacts on Canadians and has modified all its security systems to protect against future cyberattacks.

All individuals affected by the cybersecurity breaches will receive a letter from the CRA explaining how to confirm their identity in order to protect and restore access to their account.

The agency urges everyone using its online services to update their accounts with unique passwords they don’t use for any other purpose.

It also recommends all CRA “My Account” users enable email notifications as an additional measure of security.

They can also opt to use a new security feature that will allow them to set up a unique personal identification number to open an account.

About 5,600 CRA accounts were targeted in what the CRA has described as “credential stuffing” schemes, in which hackers used passwords and usernames from other websites to access Canadians’ CRA accounts.

The first of three attacks last week took aim at the GCKey service, which is used by about 30 federal departments and allows Canadians to access services like the My Service Canada account.

By using the previously stolen usernames and passwords, the perpetrators were able to fraudulently acquire about 9,000 of the some 12 million GCKey accounts.

Separately, CRA’s system was hit by credential stuffing attacks. The perpetrators were able to use previously hacked credentials to access the CRA portal. They were also able to exploit a vulnerability that allowed them to bypass the CRA security questions and get into thousands more accounts.

In addition, the CRA portal was directly targeted with a large amount of traffic trying to attack the services through credential stuffing.

The Canadian Press

Canadacybersecurity

Get local stories you won't find anywhere else right to your inbox.
Sign up here

Just Posted

.
SHARE: Stunning vistas of Pitt Meadows and Maple Ridge

Send us your photo showing how you view Maple Ridge or Pitt Meadows, and it could be featured soon.

City hall is asking for public input on its greenhouse gas reduction plans.
Maple Ridge wants citizen input on greenhouse gas targets

City hall to host an online webinar on Thursday

Pitt Meadows United Church has a new Expression Station, to create a record of people’s feelings during this stage of the COVID-19 pandemic. (Special to The News)
Closed by COVID-19, Pitt Meadows church offers Expression Station

Say what you need to say in this pandemic time, offers United Church

Police tape is shown in Toronto Tuesday, May 2, 2017. (Graeme Roy/The Canadian Press)
CRIME STOPPERS: ‘Most wanted’ for the week of Feb. 28

Crime Stoppers’ weekly list based on information provided by police investigators

On Monday, March 1, 2021, Maple Ridge is hosting an information session on Choose to Move, a fitness program for people 65 and older. (Maple Ridge image)
Maple Ridge seniors invited to information session on free fitness program

Learn about the program for those 65 and older on Monday, March 1

A health worker holds a vial of AstraZeneca vaccine to be administered to members of the police at a COVID-19 vaccination center in Mainz, Germany, Thursday, Feb. 25, 2021. The federal state of Rhineland-Palatinate, start with the vaccination of police officers in internal police vaccination centers. (Andreas Arnold/dpa via AP)
B.C. officials to unveil new details of COVID vaccination plan Monday

Seniors and health-care workers who haven’t gotten their shot are next on the list

An investigation is underway after a man was shot and killed by Tofino RCMP in Opitsaht. (Black Press Media file photo)
Man shot and killed by RCMP near Tofino, police watchdog investigating

Investigation underway by Independent Investigations Office of British Columbia.

B.C. Supreme Court in Vancouver on Tuesday December 11, 2018. THE CANADIAN PRESS/Darryl Dyck
B.C.’s compromise on in-person worship at three churches called ‘absolutely unacceptable’

Would allow outdoor services of 25 or less by Langley, Abbotsford and Chilliwack churches

Cannabis bought in British Columbia (Ashley Wadhwani/Black Press Media)
Is it time to start thinking about greener ways to package cannabis?

Packaging suppliers are still figuring eco-friendly and affordable packaging options that fit the mandates of Cannabis Regulations

Baldy Mountain Resort was shut down on Saturday after a fatal workplace accident. (Baldy Mountain picture)
Alina Durham, mother of Shaelene Bell, lights candles on behalf of Bell’s two sons during a vigil on Saturday, Feb. 27, 2021. (Jenna Hauck/ Chilliwack Progress)
VIDEO and PHOTOS: Candlelight vigil for missing Chilliwack woman sends message of hope

Small group of family, friends gathered to shine light for 23-year-old mother Shaelene Bell

Jasmine and Gwen Donaldson are part of the CAT team working to reduce stigma for marginalized groups in Campbell River. Photo by Marc Kitteringham, Campbell River Mirror
Jasmine’s story: Stigma can be the hardest hurdle for those overcoming addiction

Recovering B.C. addict says welcome, connection and community key for rebuilding after drug habit

A Vancouver restaurant owner was found guilty of violating B.C.’s Human Rights Code by discriminating against customers on the basis of their race. (Pixabay)
Vancouver restaurant owner ordered to pay $4,000 to customers after racist remark

Referring to patrons as ‘you Arabs’ constitutes discrimination under B.C.’s Human Rights Code, ruling deems

Most Read