
Canada’s privacy commissioner opened an investigation into cyberattacks associated with more than 30,000 privacy breaches at the Canada Revenue Agency dating back to 2020. The inquiry was announced on October 29, 2024 after the Office of the Privacy Commissioner received a complaint.
What the investigation covered
The CRA reported the breaches to the commissioner’s office in May 2024. The privacy regulator said it had been engaging with the agency before deciding to investigate whether the CRA met its obligations under the federal Privacy Act, including requirements governing safeguards and breach reporting.
Opening an investigation did not amount to a final finding that the CRA had violated the law. It started a formal evidence-gathering process. Because the inquiry was active, the commissioner’s initial announcement did not identify every person affected, every type of information involved or a final cause for each incident.
How the numbers developed
The regulator later reported that a May 2024 disclosure from the CRA retroactively covered 31,393 incidents between May 2020 and November 2023. Additional CRA reports captured approximately 4,000 more incidents. Those later figures explain why subsequent official material may refer to about 35,000 incidents rather than the “more than 30,000” used when the inquiry was announced.
An incident count is not necessarily the same as the number of unique people, accounts or successful financial thefts. One individual can be connected to more than one event, and a reported privacy breach can have consequences that differ from another breach. The totals should not be converted into unsupported claims about losses.
What account holders can do
The privacy commissioner advised people to check their CRA accounts for suspicious activity and change their passwords. A password used for the CRA should be unique, because credentials stolen from another service can be tested automatically against government sign-in systems. Multi-factor authentication and current contact information add useful protection, although no single measure eliminates every risk.
Unexpected changes to direct-deposit information, addresses, benefit applications or tax filings should be reported through a verified CRA contact channel. People should type the government address themselves or use a saved bookmark rather than following a link in an unsolicited text or email. The CRA does not require payment through gift cards or cryptocurrency.
Potential victims should keep copies of notices, dates, account changes and conversations. If banking information or identity documents may have been exposed, contacting the financial institution and reviewing credit files can help limit further harm. Immediate financial fraud can also be reported to local police and the Canadian Anti-Fraud Centre.
Why the inquiry matters
Tax and benefit systems hold identity, employment, banking and income information, making them valuable targets. Federal institutions must continually reassess authentication, monitoring, containment and notification rather than treating a past security design as permanently adequate.
The commissioner’s probe was intended to determine what obligations applied and whether they were met. Until findings are published, the verified facts are the CRA’s breach reports, the complaint and the formal investigation—not speculation about a particular taxpayer’s file or the responsibility of an individual employee.



