The federal government has agreed to pay $8.7 million to settle a class-action lawsuit launched after tens of thousands of Canada Revenue Agency accounts were compromised in a 2020 cyberattack.
The settlement stems from a data breach during the COVID-19 pandemic, when many Canadians were using CRA online accounts to access emergency benefits and tax services. Cybercriminals used stolen usernames and passwords from unrelated data breaches to try to access government accounts where people had reused the same login information, in a tactic called “credential stuffing.”




