Some Canadians who logged into their Canada Revenue Agency (CRA) account in the summer of 2020 found someone had beaten them to it — with passwords changed, direct deposit details switched and unfamiliar benefit claims filed in their name. “No red flags went off at the CRA,” exclaimed one frustrated user on discussion forum Redflagdeals.com, after discovering fraudulent Canada Emergency Response Benefit (CERB) claims had gone through their hacked account.
Now, six years after this CRA data hack, there’s a price tag attached to the collective frustration and anger experienced by Canadian taxpayers. Eligible Canadians have until Feb. 3, 2027, to apply for a piece of the $8.7-million class-action settlement.
Don’t Miss
What triggered the class-action lawsuit against the CRA?
During 2020, hackers used stolen or guessed login credentials to break into Government of Canada online accounts, including the CRA My Account and My Service Canada Account portals; it was a process known as a credential stuffing attack.
Once inside, some attackers changed direct deposit information and applied for pandemic benefits — CERB or the Canada Emergency Student Benefit — using victims’ own identities.
Tens of thousands of Canadians had personal information exposed, from social insurance numbers to banking details. As a result, a class action lawsuit, Sweet v. His Majesty the King, was certified in 2022; a settlement was reached last December, and the class action won Federal Court approval in May 2026.
Who actually qualifies for the CRA data hack payout?
Not everyone whose account was touched will see a cheque.
Technically, anyone whose personal or financial information in a CRA, My Service Canada or other GCKey-linked account was disclosed without authorization between March 1 and Dec. 31, 2020, qualifies as a member of the class action lawsuit. But payment is limited to accounts breached within a specific period of time. According to court records, the breach period is between June 26 and Aug. 18, 2020. However, claims administrator KPMG lists a different period of time for eligibility — between June 15 and August 30, 2020.
There is another breach period: Anyone whose information was accessed through a Represent a Client account between Oct. 8 and Nov. 25, 2020, also qualifies for a portion of the settlement.
Click Here For The Original Source.
