CRA loses taxpayer data to Heartbleed bug

Tax agency says 900 social insurance numbers compromised in online privacy breach

The Canada Revenue Agency says the social insurance numbers of 900 taxpayers were stolen last week by someone using the Heartbleed encryption vulnerability before the taxation agency shut down public access to its online services.

It happened over a six-hour period by someone exploiting the vulnerability in many supposedly secure websites that used an open-source encryption system.

The CRA said it will send registered letters to affected taxpayers and will not be emailing them because it doesn’t want fraudsters to use phishing schemes to further exploit the privacy breach.

“I want to express regret to Canadians for this service interruption,” CRA commissioner Andrew Treusch said. “I share the concern and dismay of those individuals whose privacy has been impacted by this malicious act.”

Other personal data and possibly businesses’ information may also have been lost.

“We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed,” Treusch said.

Taxpayers whose data was compromised will get bolstered CRA account protection and free access to credit protection services.

Canada’s Privacy Commissioner is also investigating.

Online services, including the E-file and Netfile online income tax portals, were patched and re-launched Sunday after what the CRA called a vigourous test to ensure they are safe and secure.

The CRA cut off access to those services April 8 as word spread that the Heartbleed bug had given hackers access to passwords, credit card numbers and other information at many websites.

People whose income tax filing was delayed by last week’s CRA interruption have been given until May 5 – beyond the usual April 30 filing deadline – to file returns without being penalized.

The Heartbleed vulnerability, which has existed for two years, compromised secure web browsing at some sites despite the display of a closed padlock that indicates an encrypted connection.

Just Posted

‘This was my baby’: Music teacher to retire after 29 years at Kent Elementary

Brenda Di Rezze will be saying goodbye to her music room at the end of this school year

LETTER: Harrison needs trees, not a new parking lot

Harrison resident Janne Perrin reminds council that trees are important too

UPDATE: Two young Chilliwack men facing at least five years jail for armed robbery

Darius Commodore and Jaimal Mclaren face 13 charges in Mission/Agassiz incident involving police dog

Harrison pay parking begins Saturday

Drivers will be charged an hourly rate for their parking spots from June 15 to Sept. 15

UPDATE: Two-year-old in critical condition after fall in Chilliwack pool

Two-year-old child was reported to not be breathing as air ambulance called out Thursday afternoon

VIDEO: Reading splashes into Agassiz’s Ferny Coombe Pool

The Agassiz Library held its annual Reading in the Pool event Friday, June 14

Teen stabbed after end-of-night limo dispute in downtown Vancouver

A young man, 19, is in serious condition following a dispute between two groups

B.C. bus driver loses case to get job back after texting while driving full bus

An arbitator ruled that Tim Wesman’s phone usage was a “a reckless disregard for public safety”

Revamped B.C. Lions set to battle veteran Winnipeg Blue Bombers

The Lions’ first test of the season will be a big one

No business case for Trans Mountain expansion, says former environment minister

Cabinet is expected to announce its decision on the expansion of the Alberta-to-B.C. pipeline by Tuesday

LETTER: British Columbia’s forest industry crisis being made worse

Andrew Wilkinson warns of regulatory overload by John Horgan’s NDP

Convicted B.C. child abductor Randall Hopley back in custody 6 months after release

Correctional Services Canada could not provide further details due to privacy concerns

Alleged driver of semi-truck in fatal Burnaby hit-and-run identified

No charges have been laid and police say the driver is cooperating with the investigation

Bears have killed 17 people in B.C. since 1986

Number of bear complaints and bears killed rose sharply during same period

Most Read