CRA loses taxpayer data to Heartbleed bug

Tax agency says 900 social insurance numbers compromised in online privacy breach

The Canada Revenue Agency says the social insurance numbers of 900 taxpayers were stolen last week by someone using the Heartbleed encryption vulnerability before the taxation agency shut down public access to its online services.

It happened over a six-hour period by someone exploiting the vulnerability in many supposedly secure websites that used an open-source encryption system.

The CRA said it will send registered letters to affected taxpayers and will not be emailing them because it doesn’t want fraudsters to use phishing schemes to further exploit the privacy breach.

“I want to express regret to Canadians for this service interruption,” CRA commissioner Andrew Treusch said. “I share the concern and dismay of those individuals whose privacy has been impacted by this malicious act.”

Other personal data and possibly businesses’ information may also have been lost.

“We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed,” Treusch said.

Taxpayers whose data was compromised will get bolstered CRA account protection and free access to credit protection services.

Canada’s Privacy Commissioner is also investigating.

Online services, including the E-file and Netfile online income tax portals, were patched and re-launched Sunday after what the CRA called a vigourous test to ensure they are safe and secure.

The CRA cut off access to those services April 8 as word spread that the Heartbleed bug had given hackers access to passwords, credit card numbers and other information at many websites.

People whose income tax filing was delayed by last week’s CRA interruption have been given until May 5 – beyond the usual April 30 filing deadline – to file returns without being penalized.

The Heartbleed vulnerability, which has existed for two years, compromised secure web browsing at some sites despite the display of a closed padlock that indicates an encrypted connection.

Just Posted

Accident closes Hwy 22 near Castlegar

Highway not expected to reopen until 10:45 p.m.

Forestry workers set to begin job action in Kootenays

Operations in Castlegar, Cranbrook, Galloway, Elko, Radium, Golden may see job action this week.

Métis Flag flies in Trail on Louis Riel Day

Area students, officials and public attend flag raising at Trail City Hall

Early Trail borrowed a couple of names from the U.S.

Place Names: Connection between Trail and Butte, Montana

First Past the Post is the only option

Letter to the Editor by Dieter Bogs of Trail

Trudeau offers to help Pacific islands face climate change impact

Prime Minister Justin Trudeau met with the leaders from the Pacific island nations on Saturday during the APEC Summit in Papua New Guinea

Price makes 36 saves as Habs edge Canucks 3-2

Late goal lifts Montreal past Vancouver

BC Minister of Agriculture loses stepson to accidental overdose

Lana Popham announces death of her 23-year-old stepson, Dan Sealey

Canadian military’s template for perfect recruits outdated: Vance

Gen. Jonathan Vance, the chief of defence staff says that the military has to change because the very nature of warfare is changing, particularly when it comes to cyber-warfare

‘Toxic’ chosen as the Word of the Year by Oxford Dictionaries

Other top contenders for 2018 include ‘gaslighting’ and ‘techlash’

RCMP bust illegal B.C. cannabis lab

Marijuana may be legal but altering it using chemicals violates the Cannabis Act

Canada defeats Germany 29-10 in repechage, moves step closer to Rugby World Cup

Hong Kong needs a bonus-point win over Canada — scoring four or more tries — while denying the Canadians a bonus point

Avalanche Canada in desperate need of funding

The organization provides avalanche forecasting for an area larger than the United Kingdom

5 B.C. cities break temperature records

Parts of B.C. remain warm, at 10 C, while others feeling chilly

Most Read