ThreatCluster

Credential Stuffing Attacks Target CRA and GCKey Accounts

First seen 8 Aug 2026, 20:35 UTC www.canada.ca 78% similarity 52

Article Content

Browse articles
ThreatCluster

In early August 2020, the Government of Canada faced credential stuffing attacks targeting the GCKey service and Canada Revenue Agency (CRA) accounts. Attackers exploited usernames and passwords from previous breaches of non-governmental entities to access some accounts. The CRA identified suspicious activities on approximately 48,500 out of over 14 million user accounts. The government revoked 9,300 GCKey credentials and implemented measures to prevent further unauthorized access. Affected users are being notified and offered credit protection services. The Royal Canadian Mounted Police (RCMP) is conducting an ongoing investigation into these incidents. The CRA has locked compromised accounts and is working to assist affected individuals. Additional security measures have been added to account sign-in processes to enhance protection.

Key Points: • Credential stuffing attacks targeted CRA and GCKey accounts using stolen credentials. • Approximately 48,500 CRA accounts showed suspicious activity, leading to account locks. • The government revoked 9,300 GCKey credentials and is offering credit protection to affected users.

ThreatCluster AI How this analysis works

Timeline

2020-08-01
Credential stuffing attacks initiated
Attackers used stolen credentials from third-party breaches to access GCKey and CRA accounts.
Article 2
2020-08-15
CRA identifies suspicious activities
The CRA reported suspicious activities on approximately 48,500 accounts, prompting immediate action.
Article 1
2020-09-17
Government revokes GCKey credentials
The government revoked 9,300 GCKey credentials to mitigate further unauthorized access.
Article 2
Date unknown
RCMP investigation ongoing
The Royal Canadian Mounted Police is investigating the cyber incidents affecting CRA and GCKey accounts.
Article 2

Community

Browse all →