Heartbleed breach puts 900 Canadian tax accounts at risk

April 14, 2014

Heartbleed SSL bugDespite shutting down its system completely for most of last week after the Heartbleed bug was revealed, the Canada Revenue Agency (CRA) says that the ID numbers of around 900 people were stolen.

The national tax agency reopened its computer systems Sunday, April 13, after applying a patch for Heartbleed. But before that was accomplished, the breach allowed the unauthorized access to the 900 CRA accounts.

CRA Commissioner Andrew Treusch today released a statement regarding the unauthorized access to the tax system:

"Regrettably, the CRA has been notified by the Government of Canada's lead security agencies of a malicious breach of taxpayer data that occurred over a six-hour period. Based on our analysis to date, Social Insurance Numbers (SIN) of approximately 900 taxpayers were removed from CRA systems by someone exploiting the Heartbleed vulnerability. We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed."

More info by mail: Treusch said CRA will send a registered letter to the 900 Canadian taxpayers who lost their ID numbers to hackers. The agency also has established a dedicated 1-800 number (which will be in the letter) where they can get further information.

"The CRA will also provide those who have been affected with access to credit protection services at no cost," said Treusch. "And we will apply additional protections to their CRA accounts to prevent any unauthorized activity."

Online systems OK: CRA says its systems that came back online over the weekend are secure.

Canada Maple Leaf"Thanks to the dedicated support of Shared Services Canada and our security partners, the Agency was able to contain the infiltration before the systems were restored yesterday," Treusch noted in the statement.

"Further, analysis to date indicates no other CRA infiltrations have occurred either before or after this breach."

Scam alert for all: Meanwhile, every Canadian taxpayers should be on alert for scams likely to emerge in the wake of the breach.

CRA notes that none of its employees will be calling or emailing individuals to inform them that they have been impacted. If you don't get a registered letter from national tax officials, your account information is fine.

So don't fall for any phishing schemes referencing Heartbleed. The attempts to get more tax ID numbers will no doubt be directed at all Canadian taxpayers in criminal hopes of exploiting the fear they might be among the 900 compromised accounts.

I also wouldn't be surprised to see crooks try to use the Canadian situation to their malicious advantage in the United States. That means taxpayers south of the 49th parallel also need to be on guard for Heartbleed tax scams.

You also might find these items of interest:

Share:

The More Tax Posts tab at the top of this page will take you to, well, more tax posts. You also can search below for a tax topic. 

Latest Posts
6 tax moves to consider this June

June 3, 2026

Definitely take a break this June. But taxes don’t take vacations. So, you also should…

Read More
Tax Season 2026 Continues!

We made it. Tax Day 2025 is finally over. For most of us. When the filing season started on Jan. 26, millions who were expecting refunds filed immediately. Most of us got our returns to the Internal Revenue Service by April 15. But plenty of taxpayers also got extensions. They are looking at an Oct. 15 filing deadline.

Those procrastinating filers aren’t a problem. In fact, the IRS appreciates taxpayers who take time to fill out their 1040 forms correctly. It also is grateful that tax submissions are spread out a bit, especially now that the IRS is a leaner agency. Processing returns is easier when they arrive throughout the year instead of in massive bunches.

But enough about Uncle Sam’s tax collection issues. The focus now is on all y’all who filed for extensions, giving you another six months to complete your return. Since your new mid-October due date will be here before you know it, let’s get started now on meeting it.

The ol’ blog is here to help you finish up your extended Form 1040. You can start with January’s tax tips page, which has links to the rest of the year’s tips by-month collections. You also can peruse various tax categories for more tailored advice by clicking on the More Tax Posts drop-down menu at the top of this (and every) page.

And to make sure you don’t miss your new filing deadline, the count-down clock below will let you know just how much time you to file by Oct. 15. At the latest.e. (Note: I’m in the Central Time Zone, so adjust accordingly for where you live.)

Comments