TechNewsReel
Live

Canada reaches $8.7 million settlement over 2020 government data breach

Eligible Canadians can claim up to $5,000 in losses following unauthorized access to CRA and My Service Canada accounts.

TechNewsReel Newsroom · August 10, 2026

A $8.7-million class-action settlement has been reached to compensate Canadians affected by a 2020 data breach of federal government online accounts. The settlement provides a pathway for victims whose personal and financial data were exposed to recover losses and seek compensation for the time spent remediating identity theft.

Eligible class members include individuals whose personal or financial information within a Government of Canada online account—specifically CRA, My Service Canada, or GCKey accounts—was disclosed to an unauthorized third party between March 1 and December 31, 2020. KPMG has been appointed as the claims administrator to oversee the process. The deadline for eligible citizens to submit their claims is February 3, 2027.

The Breach and Its Fallout

The settlement stems from security failures during the COVID-19 pandemic. Hackers utilized "credential stuffing" attacks—a method where stolen passwords from other sites are tested against different accounts—to gain unauthorized access to government portals. This exposed sensitive data, including Social Insurance Numbers, home addresses, and banking details. In many instances, bad actors used this stolen information to fraudulently apply for government benefits in the names of the victims.

Compensation Tiers

Compensation is structured based on the level of impact experienced by the victim. Class members may receive up to $80 for time spent addressing the unauthorized access to their accounts and up to $200 for time spent dealing with the fraudulent use of their personal information. For those who suffered more severe consequences, the settlement allows for claims of up to $5,000 for unreimbursed fraud losses and identity theft costs, provided the information was accessed during the specific credential stuffing attacks that occurred between June 26 and August 18, 2020.

Industry Implications

This case underscores the vulnerability of centralized government digital infrastructure to automated attacks. The scale of the breach highlights the financial and personal toll of identity theft when sensitive identifiers like Social Insurance Numbers are compromised. By providing a mechanism for out-of-pocket recovery, the settlement acknowledges the administrative burden placed on citizens to fix errors caused by systemic security gaps.

Next Steps

While the settlement provides financial relief, the Government of Canada has stated that the agreement represents a compromise of disputed claims and is not an admission of wrongdoing. Affected individuals should verify their eligibility through the official claims process managed by KPMG. Observers will be watching whether this settlement prompts further security hardening across other federal digital services to prevent similar credential-based attacks in the future.

Sources

Get a notification when a big story breaks. A few a day at most — no spam.