Last updated: October 07 2026

CRA Data Breeches Put Taxpayer Information at Risk

Geoff Curruer

An important deadline is coming up, around the same time that Canadians get ready to file their 2026 tax returns at the start of tax season 2027. Since 2020, more than 42,000 data breaches have occurred at the CRA. A class action lawsuit was launched in 2020 and a $8.76 million settlement was reached.  Eligible Canadians affected by these security incidents can now submit claims through the KPMG Claims Portal until February 3, 2027.  

The Backdrop.  On May 7, 2026, the Office of the Privacy Commissioner released a special report on these breaches.  The report provides some alarming conclusions: 

  • CRA was not able to provide details of every confirmed breach due to limitations in its tracking systems, the overall volume of breaches, and the resources required.
  • CRA did not implement mandatory multi-factor authentication in a timely manner
  • Once in place those authentications did not consistently rely on the strongest methods considered to be industry best practices.
  • CRA could not adequately explain in all cases how attackers were successful in bypassing the authentication processes to gain unauthorized access personal information.
  • The report outlines a series of recommendations to fill the security gaps. 

The Opportunity.  If you have a client who was a victim of one of these hacks between March 1 and December 31 of 2020, there is compensation available.  However, as per the breach settlement details:

 Only those class members who were victims of unauthorized access by third parties to Class Members' personal information contained in Government of Canada Online Accounts during the Credential Stuffing Attacks directed at the Government of Canada Online Accounts between June 26 and August 18, 2020 (the "Credential Stuffing Attacks"), and whose personal information was accessed, or accessed and used for fraudulent purposes, are entitled to payments under the Settlement Agreement.

The individual can claim up to $80 for time spent addressing unauthorized access where no fraud was found. The amount goes up to $200 if the person’s information was found to have been used fraudulently and up to $5,000 for documented out of pocket identity theft expenses. 

Your affected clients will need to file their claims through the KPMG Claims Administration Portal.

The Bottom Line:

The Privacy Commissioner’s report reminds us that CRA and Service Canada systems are not immune to security threats. Reminding clients to create passwords that are difficult to compromise and to update them periodically is one way to help keep their financial information out of the hands of criminals.

The report is also an important reminder for tax professionals to ensure their own systems are secure and that their clients’ sensitive information is appropriately protected.

Additional Educational Resources: 

Invite your clients to listen to Real Tax News with Evelyn Jacks and Friends to understand their tax system better. Go to learn.knowledgebureau.com/courses/real-tax-news-podcast

For your continuing professional development please attend the next two virtual CE Summits