CRA loses taxpayer data to Heartbleed bug

Tax agency says 900 social insurance numbers compromised in online privacy breach

The Canada Revenue Agency says the social insurance numbers of 900 taxpayers were stolen last week by someone using the Heartbleed encryption vulnerability before the taxation agency shut down public access to its online services.

It happened over a six-hour period by someone exploiting the vulnerability in many supposedly secure websites that used an open-source encryption system.

The CRA said it will send registered letters to affected taxpayers and will not be emailing them because it doesn’t want fraudsters to use phishing schemes to further exploit the privacy breach.

“I want to express regret to Canadians for this service interruption,” CRA commissioner Andrew Treusch said. “I share the concern and dismay of those individuals whose privacy has been impacted by this malicious act.”

Other personal data and possibly businesses’ information may also have been lost.

“We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed,” Treusch said.

Taxpayers whose data was compromised will get bolstered CRA account protection and free access to credit protection services.

Canada’s Privacy Commissioner is also investigating.

Online services, including the E-file and Netfile online income tax portals, were patched and re-launched Sunday after what the CRA called a vigourous test to ensure they are safe and secure.

The CRA cut off access to those services April 8 as word spread that the Heartbleed bug had given hackers access to passwords, credit card numbers and other information at many websites.

People whose income tax filing was delayed by last week’s CRA interruption have been given until May 5 – beyond the usual April 30 filing deadline – to file returns without being penalized.

The Heartbleed vulnerability, which has existed for two years, compromised secure web browsing at some sites despite the display of a closed padlock that indicates an encrypted connection.

Just Posted

No home for Agassiz Community Garden on school district land

The garden is still homeless after SD78 said no to the society using the McCaffrey School property

Life rings, signs to improve safety on Harrison waterfront

Harrison council approved $125,000 in aquatic safety projects for the beach

PHOTOS: Harrison students take on the Bunny Run

Harrison Hot Springs Elementary students dressed up for the Easter event

No more mobile vendors on Harrison beach

The approval of an updated business licence bylaw means Nolan Irwin is without a cart

Chilliwack PEO: ‘We who are sisters’

International oganization celebrating 150 years of service

VIDEO: Agassiz, Harrison celebrate National Pet Day

From cats and dogs to lizards and chickens, residents showed off the animals that enrich their lives

Building a better learning environment for B.C. students

Minister’s message for Education Week, April 23-27

Seattle’s 4-20 ‘protestival’ enjoys tolerance, some support – and B.C. could do the same

Seattle’s Hempfest a large-scale occasions with vendors, prominent musical acts and thousands of attendees

B.C. mountain biker sent home from hospital twice, despite broken vertebrae

Released in Maple Ridge to go home with three fractured vertebrae

VIDEO: Giants draw first blood in Western Conference championships

In Game 1 of the best-of-seven series between Vancouver and Spokane, the G-Men emerged triumphant

Deck collapses in Langley during celebration, multiple people injured

Emergency responders rushed to the Langley home

B.C. RCMP receive application for Police Cat Services

RCMP announced the launch of the Police Cat Services unit as an April fools joke

Rats available for adoption in Vancouver

In a social media post the City of Vancouver says you can adopt a rat for $5.

Kirkland Signature veggie burgers recalled due to possible metal fragments

Recalled products came in 1.7 kg packages with a best before date of Apr. 23, 2019

Most Read