Credential Stuffing Attacks Shut Down Canada's Revenues Service

Stu Sjouwerman | Aug 18, 2020

canada revenue agency cybersecurity scam covid-19The Canada Revenue Agency is investigating two online hacking incidents affecting the personal information of thousands of Canadians, according to CBC News.

The Canada Revenue Agency has temporarily shut down its online services, which means that anyone attempting to apply for emergency COVID-19 benefits, such as the Canada Emergency Response Benefit or the Canada Emergency Student Benefit, will be unable to do so until further notice. 

"The CRA quickly identified the impacted accounts and disabled access to these accounts to ensure the safety and security of the taxpayer's information," CRA spokesperson Christopher Doody wrote in an email. "The CRA is continuing to analyze both incidents. Law enforcement assistance has been requested from RCMP and an investigation has been initiated."

While the breaches have been contained, services connected to My Account, My Business Account and Represent a Client on the CRA website have been disabled as an additional safety measure. 

my account covid 19 CRA

Canadians attempting to log in to their Canada Revenue Agency accounts are met with a message informing them that they will not be able to access their accounts until further notice. 

Earlier this month, Canadians began reporting online that email addresses associated with their CRA accounts had been changed, that their direct deposit information was altered and that CERB payments had been issued in their name even though they had not applied for the COVID-19 benefit.

The incidents are a type of attack known as "credential stuffing," the Treasury Board's Office of the Chief Information Officer shared in a statement.

"These attacks, which used passwords and usernames collected from previous hacks of accounts worldwide, took advantage of the fact that many people reuse passwords and usernames across multiple accounts."

Cases such as this could be prevented through new-school security awareness training. Users can learn how to spot the warning signs as they continue to work in a remote environment. 

CBC News has the full story

Secure the Digital Workforce: Human + AI

KnowBe4 empowers the modern workforce to make smarter security decisions every day. Trusted by more than 70,000 organizations worldwide, KnowBe4 is the pioneer of digital workforce security, securing both AI agents and humans. The KnowBe4 Platform provides attack simulation and training, collaboration security, and agent security powered by AIDA (Artificial Intelligence Defense Agents) and a proprietary Risk Score. The platform leverages 15 years of behavioral data to combat advanced threats including social engineering, prompt injection, and shadow AI. By securing humans and agents, KnowBe4 leads the industry in workforce trust and defense.