Skip to content

Canadian Government to Pay $8.7 Million in CRA Data Breach Settlement: Who Qualifies, Payment Amounts, Claim Process and Important Dates

canada revenue agency data breaches

CRA Data Breach Settlement, thousands of Canadians affected by the 2020 Canada Revenue Agency (CRA) cyberattack may soon receive compensation after the federal government agreed to an $8.7 million class-action settlement tied to hacked CRA and government accounts.

The settlement comes after hackers gained unauthorized access to online government accounts during the COVID-19 pandemic and used stolen information to fraudulently apply for benefits such as the Canadian Emergency Response Benefit (CERB) and the Canadian Emergency Student Benefit (CESB).

The agreement was approved by the Federal Court of Canada in May 2026 and could provide payments to tens of thousands of victims whose sensitive information was compromised.

What Happened in the CRA Data Breach?

The cyberattack occurred in 2020 during the height of the COVID-19 pandemic. Hackers targeted online government accounts connected to the CRA’s MyAccount portal and other federal systems.

Calculate Your 2026 COLA Increase →

Cybercriminals used a technique known as “credential stuffing,” where stolen usernames and passwords from other websites are reused to access government accounts. Because many users reused passwords across multiple platforms, hackers successfully entered thousands of accounts.

The attackers were reportedly able to bypass additional CRA security questions because of a software configuration issue within the CRA’s credential management system.

As a result, more than 47,000 Canadians had sensitive information exposed, including:

  • Social Insurance Numbers (SIN)
  • Banking details
  • Home addresses
  • Email addresses
  • Tax information
  • Direct deposit information

In many cases, hackers used the stolen identities to apply for CERB and CESB payments or redirect legitimate benefit payments into fraudulent bank accounts.

Why the Canadian Government Agreed to the Settlement

Victims filed a class-action lawsuit alleging the federal government and CRA failed to properly secure online systems and failed to detect the breach quickly enough.

The lawsuit argued that the government’s handling of the cyberattack exposed Canadians to identity theft, financial losses, emotional stress, and fraud risks.

Federal Court Justice Richard Southcott approved the settlement, stating that it was “fair, reasonable, and in the best interests” of affected Canadians.

Although some victims argued the compensation amounts are too low, the court noted the settlement is intended to provide broad compensation to the entire affected class rather than fully compensate every individual loss.

Who Qualifies for the CRA Data Breach Settlement Payment?

Many Canadians are now searching online for:

  • CRA settlement eligibility
  • Who qualifies for the CRA data breach payment
  • CERB hack compensation
  • CRA class action settlement payment requirements
  • Government cyberattack compensation Canada

To qualify for compensation under the settlement, individuals generally must meet specific criteria.

Basic Eligibility Requirements

You may qualify if:

  • Your CRA MyAccount or Government of Canada online account was accessed without authorization between June 26 and August 18, 2020.
  • Your personal information was compromised during the cyberattacks.
  • Hackers used your information to apply for CERB or CESB benefits fraudulently.
  • Legitimate benefit payments were redirected because of the breach.
  • You experienced out-of-pocket expenses linked to identity theft or fraud after the incident.

The settlement also includes people affected through:

  • CRA MyAccount
  • My Service Canada Account
  • GCKey-linked federal accounts

How Much Money Could Victims Receive?

The settlement divides compensation into several categories depending on how victims were affected.

1. Compensation for Lost Time and Inconvenience

Eligible claimants may receive:

  • $20 per hour
  • Up to four hours maximum
  • Maximum payout of $80

This compensation covers time spent dealing with account recovery, fraud monitoring, phone calls, password changes, and related inconvenience.

2. CERB or CESB Fraud Claims

If hackers used your identity to:

  • Apply for fraudulent CERB/CESB payments, or
  • Redirect legitimate payments,

you may claim compensation at:

  • $20 per hour
  • Up to 10 hours
  • Maximum payout of $200

3. Identity Theft and Financial Loss Expenses

Victims may also claim reimbursement for documented expenses related to the breach.

Eligible expenses may include:

  • Credit monitoring costs
  • Bank fees
  • Fraud recovery expenses
  • Unauthorized charges
  • Legal or administrative fees tied to identity theft

The maximum reimbursement for out-of-pocket costs is:

  • Up to $5,000 per claimant

CRA Settlement Payment Dates

One of the biggest questions Canadians are asking is:

“When will the CRA data breach settlement payments be sent?”

At the time of the court approval, exact payment dates had not yet been officially announced.

However, because the settlement has now been approved by the Federal Court, the next steps typically include:

  1. Final claims administration
  2. Claim verification
  3. Processing of eligible claims
  4. Distribution of settlement payments

KPMG has been appointed as the settlement administrator and will oversee the payment process.

Canadians should monitor the official settlement website for:

  • Claim submission deadlines
  • Payment timelines
  • Status updates
  • Required documentation
  • Appeal or opt-out deadlines

How Will the Settlement Payments Be Sent?

The settlement administrator is expected to provide multiple payment methods.

Possible payment options may include:

  • Direct deposit
  • Electronic funds transfer (EFT)
  • Mailed cheque payments

Claimants will likely need to provide updated banking or mailing information when submitting claims.

To avoid delays, affected Canadians should ensure their contact information is current.

How to File a Claim for the CRA Settlement

Eligible individuals will generally need to:

  1. Visit the official settlement website managed by KPMG
  2. Complete a claim form
  3. Provide supporting documents if claiming financial losses
  4. Submit the claim before the deadline

Documentation may include:

  • Bank statements
  • Fraud reports
  • Identity theft records
  • Receipts for expenses
  • CRA correspondence
  • Credit monitoring invoices

What Is Credential Stuffing?

The CRA breach highlighted growing concerns about credential stuffing attacks.

Credential stuffing happens when hackers use:

  • Previously leaked usernames
  • Stolen passwords
  • Automated login tools

to test login combinations across different websites.

If users reuse the same password on multiple sites, hackers can gain access to important accounts quickly.

Cybersecurity experts strongly recommend:

  • Using unique passwords for every account
  • Enabling multi-factor authentication (MFA)
  • Monitoring financial accounts regularly
  • Updating passwords frequently
  • Avoiding reused credentials

Why This Settlement Matters

The CRA class-action settlement is one of the most significant Canadian government cybersecurity compensation cases in recent years.

The case raised serious concerns about:

  • Government cybersecurity readiness
  • Protection of taxpayer information
  • Digital identity security
  • Emergency benefit fraud
  • Online government account vulnerabilities

The breach also occurred during a period when millions of Canadians depended on emergency financial support programs during the pandemic.

Some Victims Still Believe Compensation Is Too Low

Although the court approved the settlement, some affected Canadians remain dissatisfied.

According to court documents:

  • 29 individuals objected to the settlement
  • Most argued the compensation was insufficient
  • Some victims reported severe financial and emotional harm

Justice Southcott acknowledged that some people may feel the settlement is inadequate, especially those who experienced major identity theft consequences.

However, he concluded that the agreement still provides a reasonable overall resolution for the broader class.

What Happens to Unclaimed Settlement Money?

An unusual aspect of the settlement is that leftover funds will not return to the federal government.

Instead, any remaining or unclaimed money will reportedly go to the Privacy and Access Council of Canada to support:

  • Privacy protection initiatives
  • Cybersecurity awareness
  • Research into digital privacy rights

CRA Says Cybersecurity Remains a Priority

In response to the settlement, the CRA stated that protecting Canadians’ personal information remains a priority.

The agency emphasized that no organization is fully immune from cyber threats and said it has implemented stronger systems to:

  • Detect suspicious activity
  • Monitor unauthorized access
  • Investigate cyber incidents
  • Respond more quickly to attacks

The $8.7 million CRA data breach settlement marks the conclusion of a years-long legal battle involving one of Canada’s most high-profile pandemic-era cyberattacks.

For affected Canadians, the settlement offers at least partial compensation for the disruption, fraud risks, and financial headaches caused by the breach.

Individuals who believe they may qualify should pay close attention to upcoming announcements regarding:

  • Claim deadlines
  • Settlement payment dates
  • Eligibility verification
  • Required documents
  • Approved payment methods

With cyberattacks becoming increasingly common worldwide, the case also serves as a reminder of the importance of strong passwords, account monitoring, and online security awareness.

Informer News Team

Informer News staff coverage of official tax, benefits, pension, and legal-settlement news for readers in the United States, United Kingdom, and Canada.