Credential Stuffing Attacks Target CRA and GCKey Accounts
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
In early August 2020, the Government of Canada faced credential stuffing attacks targeting the GCKey service and Canada Revenue Agency (CRA) accounts. Attackers exploited usernames and passwords from previous breaches of non-governmental entities to access some accounts. The CRA identified suspicious activities on approximately 48,500 out of over 14 million user accounts. The government revoked 9,300 GCKey credentials and implemented measures to prevent further unauthorized access. Affected users are being notified and offered credit protection services. The Royal Canadian Mounted Police (RCMP) is conducting an ongoing investigation into these incidents. The CRA has locked compromised accounts and is working to assist affected individuals. Additional security measures have been added to account sign-in processes to enhance protection.
Key Points: • Credential stuffing attacks targeted CRA and GCKey accounts using stolen credentials. • Approximately 48,500 CRA accounts showed suspicious activity, leading to account locks. • The government revoked 9,300 GCKey credentials and is offering credit protection to affected users.