Â鶹´«Ã½

Skip to main content

Inadequate security led to federal breach that compromised Canadians' info: watchdog

Privacy Commissioner of Canada Philippe Dufresne delivers the results of an investigation into Home Depot of Canada Inc.'s sharing of customer e-receipt information with Meta Platforms Inc., which operates Facebook, at a press conference in Ottawa, on Thursday, Jan. 26, 2023. THE CANADIAN PRESS/Spencer Colby Privacy Commissioner of Canada Philippe Dufresne delivers the results of an investigation into Home Depot of Canada Inc.'s sharing of customer e-receipt information with Meta Platforms Inc., which operates Facebook, at a press conference in Ottawa, on Thursday, Jan. 26, 2023. THE CANADIAN PRESS/Spencer Colby
Share

Government departments lacked adequate protections to fend off a "sophisticated and co-ordinated" cyberattack that compromised the sensitive information of tens of thousands of Canadians, the federal privacy watchdog has found.

In a report tabled Thursday, privacy commissioner Philippe Dufresne describes how the lapse at the Canada Revenue Agency and Employment and Social Development Canada in summer 2020 allowed hackers to fraudulently collect payments.

The report says the breach of financial, banking and employment data led to numerous cases of fraud and identity theft, including many illicit applications for COVID-19 emergency response benefits.

The investigation found the revenue and employment departments had underestimated the level of identity authentication needed for their online programs and services.

The commissioner also concluded the departments did not take the necessary steps to promptly detect and contain the breach.

Both organizations have agreed to implement recommendations aimed at ensuring efficient safeguards against attacks, rapid response to breaches and regular security assessments.

"Federal government departments and agencies are attractive targets for cyberattacks and must have robust safeguards to mitigate against breaches and protect the sensitive personal information and programs that they manage," Dufresne said in a statement.

"If a breach does occur, it is crucial that organizations act promptly to remedy the situation and prevent further damage to those affected."

The commissioner found that attackers used, among other things, the revenue agency's sign-in portal and ESDC's "GCKey" authentication service to get into their online services and access individuals' accounts using stolen login information and passwords obtained during previous breaches.

Attackers used a technique known as credential stuffing, allowing them to access, modify and create new online accounts in these stolen identities to fraudulently redirect government benefit payments to other bank accounts, the report says.

It also notes challenges the commissioner faced in the form of "delayed and missing breach reports and accessing information from departments during the investigation."

"Unnecessary delays can increase harms flowing from a breach and hinder the investigative process," the report says.

In addition, the commissioner's office is following up with the revenue agency on separate breaches regarding Canada Emergency Response Benefit fraud in 2020, which it learned about in the final stages of the initial investigation.

Preliminary information indicates 15,000 individuals may have been affected.

Notwithstanding these concerns, the office says it is encouraged by the commitment from both the revenue and employment departments to implement the recommendations.

"We will expect all government departments to consider the lessons from this report in reducing the probability of a future breach of this magnitude."

This report by The Canadian Press was first published Feb. 15, 2024. 

IN DEPTH

Opinion

opinion

opinion Don Martin: Gusher of Liberal spending won't put out the fire in this dumpster

A Hail Mary rehash of the greatest hits from the Trudeau government’s three-week travelling pony-show, the 2024 federal budget takes aim at reversing the party’s popularity plunge in the under-40 set, writes political columnist Don Martin. But will it work before the next election?

opinion

opinion Don Martin: How a beer break may have doomed the carbon tax hike

When the Liberal government chopped a planned beer excise tax hike to two per cent from 4.5 per cent and froze future increases until after the next election, says political columnist Don Martin, it almost guaranteed a similar carbon tax move in the offing.

CTVNews.ca Top Stories

A Brampton woman says she is devastated after she lost more than $200,000 — her life's savings — to a romance scam.

The principal of an Ottawa high school is apologizing to students, parents and guardians after an Arabic-language song was played during the school's Remembrance Day service.

Timmins-James Bay MP Charlie Angus was among approximately 120 people who gathered Sunday night for a candlelight vigil near the scene of a vicious attack against a 16-year-old in Cobalt.

Local Spotlight

For the second year in a row, the ‘Gift-a-Family’ campaign is hoping to make the holidays happier for children and families in need throughout Barrie.

Some of the most prolific photographers behind CTV Skywatch Pics of the Day use the medium for fun, therapy, and connection.

A young family from Codroy Valley, N.L., is happy to be on land and resting with their newborn daughter, Miley, after an overwhelming, yet exciting experience at sea.

As Connor Nijsse prepared to remove some old drywall during his garage renovation, he feared the worst.

A group of women in Chester, N.S., has been busy on the weekends making quilts – not for themselves, but for those in need.

A Vancouver artist whose streetside singing led to a chance encounter with one of the world's biggest musicians is encouraging aspiring performers to try their hand at busking.

Ten-thousand hand-knit poppies were taken from the Sanctuary Arts Centre and displayed on the fence surrounding the Dartmouth Cenotaph on Monday.

A Vancouver man is saying goodbye to his nine-to-five and embarking on a road trip from the Canadian Arctic to Antarctica.

Stay Connected