• Home
  • CRA Breach Settlement: 9 Million Canadians May Be Owed Compensation, Here's How to Claim Yours
CRA Breach Settlement: 9 Million Canadians May Be Owed Compensation, Here's How to Claim Yours
By Dana Jerlo profile image Dana Jerlo
2 min read

CRA Breach Settlement: 9 Million Canadians May Be Owed Compensation, Here's How to Claim Yours

Between March and July 2020, hackers used stolen passwords from other websites to access 12,700 CRA My Account portals while millions of Canadians were logging in to apply for CERB. Four years later, the Federal Court has approved a $13.17 million settlement, and the claims window is open until November 27, 2024.

Who qualifies and what you need to prove

You are eligible if an unauthorized third party accessed your CRA My Account, My Service Canada, or GCKey account during the 2020 breach window. The CRA suspended over 800,000 accounts as a precaution, but only those with confirmed unauthorized access qualify. Log into your My Account and check your account activity history for the March-July 2020 period. If you see logins from IP addresses or locations you don't recognize, screenshot them. That is your proof.

The base payment is $150 per person, subject to pro-rata adjustment if total claims exceed the settlement pool. If you suffered documented identity theft or financial loss because of the breach, you can claim up to $2,500 for extraordinary impact. The $2,500 tier requires receipts, credit monitoring invoices, time logs for dealing with fraudulent tax filings, or bank statements showing unauthorized transactions tied to the compromised account. Without that paper trail, you get the base amount.

What credential stuffing actually means for your payout

This was not a hack of the CRA's database. The breach occurred because hackers used automated bots to test username-password combinations stolen from other sites (data breaches at LinkedIn, Adobe, and Yahoo in prior years supplied billions of credentials). The CRA's multi-factor authentication was optional at the time, and the login system didn't throttle repeated failed attempts effectively. The government is paying because the security infrastructure failed to stop an attack method that was already well-documented in 2020.

The legal phrasing matters: you do not need to prove the CRA leaked your password. You need to prove your account was accessed without authorization using credentials that originated elsewhere. The distinction is why roughly 9 million Canadians who had CRA accounts in 2020 are potentially eligible, even though only 12,700 accounts were confirmed breached. If you reused a password from a compromised site and your account was accessed, you qualify.

How to file and what happens to the money

RicePoint Administration Inc. is handling distribution. The claim form is available at the settlement website and requires your Social Insurance Number, the email or username associated with your CRA account in 2020, and a description of the unauthorized access. Upload the screenshots or CRA correspondence showing the breach. If you are claiming the higher tier, attach invoices and receipts showing costs incurred.

Legal fees and administration costs come off the top of the $13.17 million, which leaves roughly $11 million for claimants. If 100,000 people file, the base payout stays near $150. If 500,000 file, it drops to around $30. The settlement administrator will not tell you how many claims are in the system until after the deadline.

One detail that catches people: the settlement is for distress and inconvenience, not reimbursement of stolen CERB payments. If fraudsters filed a CERB claim in your name, that is a separate issue handled through CRA's regular dispute process. This settlement compensates you for the account breach itself, not the downstream fraud.

Set a calendar reminder for November 20. File early. The portal does not send confirmation emails reliably.