In the summer of 2020, most Canadians were busy taking care of their health and figuring out how to pay their rent. At the same time, hackers were sneaking thru government websites. They didn’t want to get state secrets. It was CERB money that they wanted, which was the pandemic aid that millions of Canadians were counting on. They were able to get it by going right thru people’s CRA accounts, at least for a short time.
Tens of thousands of Canadians’ personal and financial information was stolen in that breach. It is now the subject of a settled class-action lawsuit. This week, the claims window opened for eligible Canadians. They have until February 3, 2027, to send in their claim for their share of a $8.7 million settlement. The process is being run by KPMG, which was chosen by the Federal Court to be the settlement administrator.
The hackers used a technique known as “credential stuffing,” which means they kept entering stolen username and password combinations into government login pages until something worked. It’s a simple, blunt method, which is part of what makes the whole thing seem like it could have been avoided. Accounts on the Canada Revenue Agency portal, My Service Canada, and other GCKey-linked services were hacked between June 15, 2020, and August 13, 2020. Some people had their social insurance numbers, home addresses, and bank account information out in the open, while others used the same information to make false applications for CERB and the Canada Emergency Student Benefit.
The settlement was reached in December of last year and approved by the Federal Court in May. The Government of Canada did not admit fault in the settlement. It was called “a compromise of disputed claims” by the Treasury Board of Canada Secretariat. This is the kind of careful legal language that makes people angry who think the government abandoned them. It’s still not clear how many Canadians will actually file claims, but there are a lot of people who could.

The pay is split into three grades. For people whose information was hacked but not used fraudulently, you can get up to $80 for the time you spent dealing with the problems. People whose information was used to commit fraud can get up to $200. In addition, both groups can ask for up to $5,000 in documented out-of-pocket costs. These could be identity theft recovery costs, credit monitoring fees, or fraudulent charges they had to pay in the year after the breach. Keep in mind that payment amounts may go down depending on how many approved claims come in, so sending in your claim as soon as possible isn’t always the best idea. On the other hand, waiting too long means you might forget all about it.
Eligibility checks are easy to do. There is a tool on KPMG’s website that checks your eligibility. It needs your last name, email address, and the last three digits of your social security number. Some Canadians have already heard from KPMG, but getting a notice isn’t necessary to apply. Many people who are eligible may not have heard anything. During that time, anyone with a GCKey, CRA, or government online account should at least check.
Along with the money amounts, this settlement has a quiet but important meaning. It’s one of the most public admissions that, at least in 2020, the government’s digital infrastructure wasn’t built to protect people the way it should have been. People could file fake CERB applications in other people’s names and use public funds meant to help real people in crisis. This shows that there were problems that went beyond people’s password habits. Some people feel that the settlement, even tho it was necessary, doesn’t fully take into account the stress that those victims were under—the confusion, the calls to government lines, and the months they spent trying to prove they didn’t apply for benefits they never got.
Thru KPMG’s portal, Canadians who have claims that are eligible can apply online or by mail. Any settlement money that isn’t claimed will be given to the Privacy and Access Council of Canada for research on privacy. This is a small but important way of saying that this kind of breach shouldn’t happen again.

