CRA data breach settlement opens claims: up to $5,280 available if you were exposed in 2020
Federal Court approved $8.7-million settlement from 2020 credential-stuffing attacks. Claims process began in August; deadline is February 3, 2027.
The day's top stories, food & events — every morning at 7. Unsubscribe anytime.
Canadians whose personal or financial information was exposed in 2020 credential-stuffing attacks on Government of Canada platforms can now file claims for compensation up to $5,280.
The Federal Court signed off on an $8.7-million settlement in May 2026, and the claims process opened in August. The portal, run by KPMG at breachsettlementcanada.kpmg.ca, remains open until February 3, 2027.
The 2020 attacks targeted CRA My Account, My Service Canada Account, and accounts accessed through GCKey. Personal and financial information was exposed between March 1 and December 31, 2020. Some stolen credentials were used to file fraudulent CERB claims under victims' names during the earliest months of the COVID-19 pandemic.
Compensation is tiered. Tier 1 offers up to $80 for time spent dealing with unauthorized account access. Tier 2 provides up to $200 for time spent untangling fraudulent use of information. Tier 3 offers up to $5,000 for documented out-of-pocket losses tied directly to the breach — such as credit monitoring fees or unreimbursed financial damage — but requires receipts or bank statements. The theoretical maximum is $5,280.
The class action is formally known as Sweet v. His Majesty the King. Eligible class members are those whose information in a Government of Canada online account was exposed to an unauthorized third party between March 1 and December 31, 2020. Payment eligibility applies only to information specifically accessed or accessed and misused during the credential-stuffing attacks between June 26 and August 18, 2020.
If approved claims outpace the settlement fund, individual payments could shrink. Any unclaimed funds are earmarked for the Privacy and Access Council of Canada to fund future privacy research. Treasury Board of Canada Secretariat stated in a release Tuesday that the settlement "has been found to be fair, reasonable, and in the best interests of the class members."
Fake texts and emails promising CRA data breach payouts are circulating, so verify any claim notifications against the official KPMG portal.
How many people have filed claims so far, and what is the average payout being awarded?
Why is the deadline February 3, 2027 — nearly two years after the settlement was approved?
We'll update this story as answers emerge.
By the numbers
What's the maximum compensation available in the CRA data breach settlement?
Up to $5,280 is available per eligible person, combining three tiers: $80 for time spent on unauthorized account access, $200 for resolving fraudulent use of information, and $5,000 for documented out-of-pocket losses with proof.
When does the claims process deadline end?
The deadline to file claims is February 3, 2027. The portal at breachsettlementcanada.kpmg.ca opened in August.
What accounts were targeted in the 2020 attacks?
The attacks targeted CRA My Account, My Service Canada Account, and accounts accessed through GCKey between March 1 and December 31, 2020.
How much did the Federal Court approve for the settlement?
The Federal Court approved an $8.7-million settlement in May 2026 for the credential-stuffing attacks on Government of Canada platforms.