CRA loses taxpayer data to Heartbleed bug

Tax agency says 900 social insurance numbers compromised in online privacy breach

The Canada Revenue Agency says the social insurance numbers of 900 taxpayers were stolen last week by someone using the Heartbleed encryption vulnerability before the taxation agency shut down public access to its online services.

It happened over a six-hour period by someone exploiting the vulnerability in many supposedly secure websites that used an open-source encryption system.

The CRA said it will send registered letters to affected taxpayers and will not be emailing them because it doesn’t want fraudsters to use phishing schemes to further exploit the privacy breach.

“I want to express regret to Canadians for this service interruption,” CRA commissioner Andrew Treusch said. “I share the concern and dismay of those individuals whose privacy has been impacted by this malicious act.”

Other personal data and possibly businesses’ information may also have been lost.

“We are currently going through the painstaking process of analyzing other fragments of data, some that may relate to businesses, that were also removed,” Treusch said.

Taxpayers whose data was compromised will get bolstered CRA account protection and free access to credit protection services.

Canada’s Privacy Commissioner is also investigating.

Online services, including the E-file and Netfile online income tax portals, were patched and re-launched Sunday after what the CRA called a vigourous test to ensure they are safe and secure.

The CRA cut off access to those services April 8 as word spread that the Heartbleed bug had given hackers access to passwords, credit card numbers and other information at many websites.

People whose income tax filing was delayed by last week’s CRA interruption have been given until May 5 – beyond the usual April 30 filing deadline – to file returns without being penalized.

The Heartbleed vulnerability, which has existed for two years, compromised secure web browsing at some sites despite the display of a closed padlock that indicates an encrypted connection.

Just Posted

Kitimat resident is Conservative choice for fall election

Claire Rattée is a former Kitimat councillor

B.C. BUDGET: Surplus $374 million after bailouts of BC Hydro, ICBC

Growth projected stronger in 2020, Finance Minister Carole James says

Province announces $100-million grant funding for Northwest communities

The Northern Capital and Planning Grant will go to four regional districts and 22 municipalities

LNG Canada sponsors driver’s license training in Terrace, Kitimat

The $80,000 contribution is part of the company’s commitment to hire locally

Prince Rupert Gas Transmission project searches for partners

TransCanada is renewing permits for its natural gas pipeline project to North Coast.

VIDEO: Massive elk herd runs across Washington State highway

Elk have been making an appearance in the Pacific Northwest

Winter storm freezes U.S., halts air travel

Storm dumps snow or heavy rain, snarls travel in much of U.S.

Gwyneth Paltrow: Skier sued me to exploit my fame, wealth

The incident happened in Deer Valley Resort in Park City, Utah

B.C. Seniors Advocate questions labour shortage in care homes

Are there really no workers, or are care aide wages too low?

B.C. business groups worry about looming economic decline in wake of NDP budget

The party’s second government budget focused on plenty of spending, business advocates say

Missing Surrey snowshoer caught in avalanche found dead on Vancouver mountain

North Shore Rescue resumed its search today after efforts were temporarily halted Tuesday due to snowstorm

Man injured in police shooting near Nelson has died: B.C. police watchdog

The death follows an incident in Bonnington on Feb. 13

Experts urge caution after 10 human-triggered avalanches across B.C.

One man is still stuck after avalanche on south coast

‘It consumed my life’: Inside the world of gaming addiction

World Health Organization classifies gaming disorder as a mental health condition

Most Read