• Home
  • CRA Breach Settlement: Who Qualifies for the $6 Million Fund and How to File by March 2026
CRA Breach Settlement: Who Qualifies for the $6 Million Fund and How to File by March 2026
By Erin Fraser profile image Erin Fraser
2 min read

CRA Breach Settlement: Who Qualifies for the $6 Million Fund and How to File by March 2026

The claims portal closes March 31, 2026, and if you had a CRA account between March and August 2020, you might be leaving $250 on the table, or several thousand if you can document actual losses.

The settlement stems from credential-stuffing attacks during the pandemic, when hackers used leaked passwords from other sites to gain unauthorized access to CRA and GCKey accounts. Between March 1 and August 14, 2020, roughly 12,700 accounts were compromised, many redirecting CERB payments to fraudsters. The Federal Court approved a $27-million settlement in 2024. That total fund covers the breach window of 2020 only, if your account was hit in 2022 or 2023, you're not eligible here.

Who qualifies and what you can claim

You're eligible if your CRA or GCKey account was accessed without your permission during that five-month window. The settlement splits payouts into two categories: base claims and out-of-pocket losses.

Base claims are for the time and hassle of dealing with the breach. No receipts required. If you qualify, you'll receive between $150 and $250. The exact amount depends on how many people file, the more claimants, the smaller the per-person share after legal fees and administration costs are deducted.

Out-of-pocket claims are where the real money sits, but they require documentation. If you paid for credit monitoring, hired a lawyer, filed a police report, or incurred other direct costs tied to the breach, you can claim those expenses up to several thousand dollars. The burden is on you to prove it: invoices, receipts, bank statements. Many victims no longer have records from 2020, which is why most claims will be base-only.

Why the payout is modest

A $27-million fund sounds large until you divide it. Legal fees, administration through RicePoint, and the sheer number of eligible accounts mean the average base payout is low. This isn't a windfall, it's symbolic compensation for what was fundamentally an exploitation of weak password hygiene across the public, not a failure of the CRA's internal database. The government has maintained that its systems weren't "hacked" in the traditional sense. Stolen credentials were used to walk through the front door.

How to file before the deadline

Claims go through RicePoint Administration, the court-appointed administrator. You'll need your SIN, proof that your account was affected (notification letters from the CRA work), and if you're claiming out-of-pocket losses, complete documentation.

Three things trip people up. First, the portal doesn't auto-populate your eligibility, you need to confirm the dates and provide evidence. Second, late claims are rejected outright. There's no extension, no grace period. Third, if you moved since 2020 and didn't update your address with the CRA, your notification letter may have gone to an old address. Check the RicePoint site directly rather than waiting for mail.

The CRA has since mandated multi-factor authentication and automated alerts for direct deposit changes. Those fixes came too late for the 2020 victims, but they're why this specific attack wouldn't work the same way today.

If you're unsure whether your account was compromised, log in to My Account and check your login history under security settings. Unfamiliar IP addresses or login locations during March to August 2020 are the tell. File even if you're uncertain, denied claims cost you nothing, but missing the March 31 cutoff costs you the entire amount.