Fifteen-plus years of BC mortgage experience, distilled into practical writing on buying, renewing, refinancing, and building wealth through real estate.
CRA Breach Settlement: Who Qualifies for the $6 Million Fund and How to File by March 2026
The claims portal closes March 31, 2026, and if you had a CRA account between March and August 2020, you might be leaving $250 on the table, or several thousand if you can document actual losses.
The settlement stems from credential-stuffing attacks during the pandemic, when hackers used leaked passwords from other sites to gain unauthorized access to CRA and GCKey accounts. Between March 1 and August 14, 2020, roughly 12,700 accounts were compromised, many redirecting CERB payments to fraudsters. The Federal Court approved a $27-million settlement in 2024. That total fund covers the breach window of 2020 only, if your account was hit in 2022 or 2023, you're not eligible here.
Who qualifies and what you can claim
You're eligible if your CRA or GCKey account was accessed without your permission during that five-month window. The settlement splits payouts into two categories: base claims and out-of-pocket losses.
Base claims are for the time and hassle of dealing with the breach. No receipts required. If you qualify, you'll receive between $150 and $250. The exact amount depends on how many people file, the more claimants, the smaller the per-person share after legal fees and administration costs are deducted.
Out-of-pocket claims are where the real money sits, but they require documentation. If you paid for credit monitoring, hired a lawyer, filed a police report, or incurred other direct costs tied to the breach, you can claim those expenses up to several thousand dollars. The burden is on you to prove it: invoices, receipts, bank statements. Many victims no longer have records from 2020, which is why most claims will be base-only.
Why the payout is modest
A $27-million fund sounds large until you divide it. Legal fees, administration through RicePoint, and the sheer number of eligible accounts mean the average base payout is low. This isn't a windfall, it's symbolic compensation for what was fundamentally an exploitation of weak password hygiene across the public, not a failure of the CRA's internal database. The government has maintained that its systems weren't "hacked" in the traditional sense. Stolen credentials were used to walk through the front door.
How to file before the deadline
Claims go through RicePoint Administration, the court-appointed administrator. You'll need your SIN, proof that your account was affected (notification letters from the CRA work), and if you're claiming out-of-pocket losses, complete documentation.
Three things trip people up. First, the portal doesn't auto-populate your eligibility, you need to confirm the dates and provide evidence. Second, late claims are rejected outright. There's no extension, no grace period. Third, if you moved since 2020 and didn't update your address with the CRA, your notification letter may have gone to an old address. Check the RicePoint site directly rather than waiting for mail.
The CRA has since mandated multi-factor authentication and automated alerts for direct deposit changes. Those fixes came too late for the 2020 victims, but they're why this specific attack wouldn't work the same way today.
If you're unsure whether your account was compromised, log in to My Account and check your login history under security settings. Unfamiliar IP addresses or login locations during March to August 2020 are the tell. File even if you're uncertain, denied claims cost you nothing, but missing the March 31 cutoff costs you the entire amount.
The claims portal closes March 31, 2026, and if you had a CRA account between March and August 2020, you might be leaving $250 on the table, or several thousand if you can document actual losses.
The settlement stems from credential-stuffing attacks during the pandemic, when hackers used leaked passwords from other sites to gain unauthorized access to CRA and GCKey accounts. Between March 1 and August 14, 2020, roughly 12,700 accounts were compromised, many redirecting CERB payments to fraudsters. The Federal Court approved a $27-million settlement in 2024. That total fund covers the breach window of 2020 only, if your account was hit in 2022 or 2023, you're not eligible here.
Who qualifies and what you can claim
You're eligible if your CRA or GCKey account was accessed without your permission during that five-month window. The settlement splits payouts into two categories: base claims and out-of-pocket losses.
Base claims are for the time and hassle of dealing with the breach. No receipts required. If you qualify, you'll receive between $150 and $250. The exact amount depends on how many people file, the more claimants, the smaller the per-person share after legal fees and administration costs are deducted.
Out-of-pocket claims are where the real money sits, but they require documentation. If you paid for credit monitoring, hired a lawyer, filed a police report, or incurred other direct costs tied to the breach, you can claim those expenses up to several thousand dollars. The burden is on you to prove it: invoices, receipts, bank statements. Many victims no longer have records from 2020, which is why most claims will be base-only.
Why the payout is modest
A $27-million fund sounds large until you divide it. Legal fees, administration through RicePoint, and the sheer number of eligible accounts mean the average base payout is low. This isn't a windfall, it's symbolic compensation for what was fundamentally an exploitation of weak password hygiene across the public, not a failure of the CRA's internal database. The government has maintained that its systems weren't "hacked" in the traditional sense. Stolen credentials were used to walk through the front door.
How to file before the deadline
Claims go through RicePoint Administration, the court-appointed administrator. You'll need your SIN, proof that your account was affected (notification letters from the CRA work), and if you're claiming out-of-pocket losses, complete documentation.
Three things trip people up. First, the portal doesn't auto-populate your eligibility, you need to confirm the dates and provide evidence. Second, late claims are rejected outright. There's no extension, no grace period. Third, if you moved since 2020 and didn't update your address with the CRA, your notification letter may have gone to an old address. Check the RicePoint site directly rather than waiting for mail.
The CRA has since mandated multi-factor authentication and automated alerts for direct deposit changes. Those fixes came too late for the 2020 victims, but they're why this specific attack wouldn't work the same way today.
If you're unsure whether your account was compromised, log in to My Account and check your login history under security settings. Unfamiliar IP addresses or login locations during March to August 2020 are the tell. File even if you're uncertain, denied claims cost you nothing, but missing the March 31 cutoff costs you the entire amount.
Read Next
Canada Lost 55,000 People This Quarter, So Why Aren't Home Prices Following?
CRA's New Billion-Dollar Ruling Program: How to Lock in Tax Certainty Before You Build
Why Porting Your 2.7% Mortgage Could Cost You $47,000 More Than Breaking It
Why Your Mortgage Renewal Is Making Crypto Look Smart (And What That Tells You)