
Special report to Parliament: Investigation of unauthorized disclosures and modifications of personal information held by Canada Revenue Agency and Employment and Social Development Canada resulting from cyber attacks
The Office of the Privacy Commissioner of Canada (OPC) conducted a special investigation into cyber attacks that led to unauthorized disclosures and modifications of personal information held by the Canada Revenue Agency (CRA) and Employment and Social Development Canada (ESDC). Attackers used credential stuffing and identity theft to access and alter sensitive financial, banking, and employment information of tens of thousands of Canadians through the CRA's sign-in portal and ESDC's GC Key service. The OPC found that both CRA and ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards. Key deficiencies included under-assessment of identity authentication levels, inadequately informed and accountable security decision-making, and a lack of effective monitoring. The OPC issued six recommendations to CRA and ESDC, covering improved authentication practices, coordinated security decision-making, and enhanced monitoring. Both departments accepted the recommendations, with ESDC's acceptance of one recommendation conditional on funding. The OPC concluded the matters for CRA and ESDC as well-founded and conditionally resolved, while other departments using GC Key had varying outcomes.
- 1Whether Canada Revenue Agency (CRA) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
- 2Whether Employment and Social Development Canada (ESDC) contravened section 8 of the Privacy Act by failing to prevent unauthorized disclosure of personal information.
- 3Whether CRA contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
- 4Whether ESDC contravened subsection 6(2) of the Privacy Act by failing to take all reasonable steps to ensure the accuracy of personal information.
- 5Whether CRA and ESDC adequately assessed the level of identity authentication warranted for their online services.
- 6Whether CRA and ESDC's identity assurance practices adequately protected against identity theft.
- 7Whether CRA and ESDC's credential assurance practices adequately protected against credential stuffing.
- 8Whether CRA and ESDC had adequately informed and accountable security decision-making processes.
- 9Whether interdepartmental information sharing and accountability systems were adequate to protect personal information.
- 10Whether CRA and ESDC conducted comprehensive vulnerability assessments and penetration testing.
- 11Whether CRA and ESDC had effective monitoring to detect and promptly contain the ongoing breach.
- 12Whether other federal departments using the GC Key service experienced fraudulent access or modification of personal information.
- Safeguards (CRA): CRA contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards
- Safeguards (ESDC): ESDC contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards
- Recommendations (CRA): CRA accepted all recommendations
- Recommendations (ESDC): ESDC accepted recommendations, one conditionally
- Complaint outcome (CRA): Matter concluded as well-founded and conditionally resolved
- Complaint outcome (ESDC): Matter concluded as well-founded and conditionally resolved
Well-founded and conditionally resolved for Canada Revenue Agency and Employment and Social Development Canada; well-founded and resolved for Health Canada and Transport Canada; not well-founded for other federal departments.
Canada Revenue Agency and Employment and Social Development Canada contravened sections 6(2) and 8 of the Privacy Act due to inadequate safeguards, under-assessment of authentication, poor decision-making, and ineffective monitoring, but committed to implementing recommendations.
The OPC recommended that CRA and ESDC alter their identity assurance practices to align with international standards, adopt multi-factor authentication for account recovery, develop clear processes for sharing threat information and security decision-making, conduct regular internal and external security assessments and penetration testing, and implement effective monitoring plans for quick response to detected attacks.
- s.6(2) Privacy Act
- s.8 Privacy Act
- s.39(1) Privacy Act
This summary is informational only and not legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro