Dailya

CRA Profile Hack Settlement

· news

A $8.7M Patch on a Much Deeper Wound

The recent announcement of an $8.7 million settlement claim for Canadians whose sensitive information was compromised in 2020 is a stark reminder that personal data remains woefully unprotected in this digital age. The class-action lawsuit, years in the making, offers a small consolation to those who saw their lives turned upside down by hackers targeting government websites, including the Canada Revenue Agency (CRA) portal.

The breach’s scale was staggering: tens of thousands of Canadians had their personal and financial information compromised that summer alone, from social insurance numbers and home addresses to details of bank accounts. The hackers’ modus operandi was predictable: they targeted government accounts over several months in 2020 primarily for applying for financial aid in the victims’ names during the early stages of the COVID-19 pandemic.

The Canadian government’s response has been criticized as inadequate, with many arguing that more should have been done to prevent such a massive breach. The Treasury Board of Canada Secretariat claims that the settlement is “fair, reasonable, and in the best interests” of those affected, but this assertion seems like a cop-out given the government’s denial of any wrongdoing.

The compensation offered to claimants has sparked debate: those whose personal information was accessed (but not used fraudulently) are eligible for up to $80 for time spent addressing issues related to unauthorized access. Those whose information was accessed and used fraudulently can claim up to $200, plus up to $5,000 for out-of-pocket costs they might have paid in the year after the hack due to identity theft.

This issue is not just about numbers; it’s about trust. When personal data is compromised, individuals face a loss of control over their lives, with long-lasting consequences including ruined credit scores and strained relationships. The government’s response, often slow or inadequate, exacerbates these problems.

For Canadians, this breach serves as a reminder to be vigilant about online security. It means being aware of the risks involved in sharing personal data and taking steps to protect ourselves. Moreover, it requires holding our leaders accountable for their failures. The government’s denial of wrongdoing is a slap in the face to those affected by this breach.

As the claims process opens, Canadians can submit applications online or by mail until February 3, 2027. However, the real question is: will this settlement be enough to prevent similar breaches in the future? Or will it merely be a Band-Aid on a much deeper wound?

We need to do better when it comes to protecting personal data. Stronger cybersecurity measures, more transparency from our leaders, and a greater sense of urgency around these issues are essential. Anything less would be a disservice to those affected by this breach – and to ourselves as citizens of this country.

The excess funds from the settlement will be donated to the Privacy and Access Council of Canada to fund privacy research. This development highlights that we’re still far from having a comprehensive solution to these issues, underscoring the need for continued efforts towards change.

Reader Views

  • EK
    Editor K. Wells · editor

    The $8.7 million settlement is a Band-Aid on a wound that's still festering. While the compensation offered to affected Canadians might provide some relief, it's essential to question what this settlement really accomplishes in terms of preventing similar breaches in the future. The Treasury Board's assertion that the government did nothing wrong only adds insult to injury. What's missing from this conversation is a critical examination of why the CRA portal remained so vulnerable to hackers, despite years of warnings and expert advice. Until we address the systemic issues driving these breaches, we'll continue to see similar headlines pop up with alarming regularity.

  • RJ
    Reporter J. Avery · staff reporter

    The $8.7 million settlement is a Band-Aid on a festering wound of government incompetence. What's alarming is that many Canadians who suffered from identity theft may not even be eligible for the meager compensation offered. The fine print suggests that only those whose info was accessed and used fraudulently – a relatively small fraction – will receive substantial payouts. Meanwhile, those who've been left to deal with the long-term consequences of compromised data, like credit score damage or tax audit woes, are stuck with subpar support.

  • CS
    Correspondent S. Tan · field correspondent

    This settlement is just a Band-Aid on a festering wound of incompetence and neglect. The fact that the government is downplaying its role in this mess, citing only "unauthorized access" to justify paltry payouts, raises more questions than answers. How can a single $80 payout be justified for individuals whose financial lives were put at risk? What about those who are still dealing with identity theft months or years later? The real issue here is systemic: Canada's digital security has been grossly inadequate for far too long, and it's not just the CRA that's at fault.

Related articles

More from Dailya

View as Web Story →