Skip to content
HighOnCity Vancouver
BEYOND

Canadians can claim up to $5,280 from CRA data breach settlement — apply by February 3

A federal court approved an $8.76 million settlement for victims of 2020 credential-stuffing attacks on CRA and Service Canada accounts. The claims portal opened August 4.

· 3 min read · HOC Newsroom
Canadians can claim up to $5,280 from CRA data breach settlement — apply by February 3
★ FREE NEWSLETTER
Get the best of Metro Vancouver in your inbox

The day's top stories, food & events — every morning at 7. Unsubscribe anytime.

Between June and August 2020, hackers ran credential-stuffing attacks against Canada Revenue Agency federal login systems, compromising CRA My Account, My Service Canada Account and GCKey. Some victims had their information accessed. Others had their accounts used fraudulently, with criminals filing bogus CERB and CESB claims under their names.

The resulting class action, Sweet v. His Majesty the King, was settled for $8.76 million, a deal the Federal Court approved in May. The claims portal opened August 4 and stays open until February 3, 2027.

Two tiers of eligibility exist. Class members are anyone whose personal information was disclosed without authorization between March 1 and December 31, 2020. Compensation, however, is reserved for people whose accounts were specifically accessed, or accessed and used fraudulently, during the credential-stuffing window between June 15 and August 30, 2020.

Anyone already contacted directly by KPMG, the company handling claims, with a personal ID number is confirmed as eligible. Everyone else can check their eligibility on KPMG's settlement site using their last name, the last three digits of their SIN, and the email tied to their government account.

Payouts break down into three categories: up to $80 for time spent dealing with unauthorized account access; up to $200 for time spent untangling fraudulent use of personal information; and up to $5,000 from a special compensation fund covering out-of-pocket losses like fraud-related costs or identity theft expenses (this category requires receipts or documentation). The maximum possible payout is $5,280. Payouts could shrink if approved claims outpace the funds set aside. Whatever remains unclaimed goes to the Privacy and Access Council of Canada to support future privacy research.

To file, visit KPMG's website and click "Apply for Compensation." Register with an email address, then provide your name, phone number, address, SIN and personal ID number if issued. Document roughly how many hours you spent cleaning up the mess — time on calls with the CRA, law enforcement or credit agencies. Payment can be issued by e-transfer (faster) or cheque, and online submissions are processed quicker than mailed forms.

By the numbers

What's the maximum payout from the CRA data breach settlement?

$5,280 is the maximum possible payout, which combines up to $80 for time spent on unauthorized account access, up to $200 for time spent addressing fraudulent use, and up to $5,000 from a special fund for out-of-pocket losses like fraud-related costs or identity theft expenses.

When does the claims portal close?

The claims portal closes on February 3, 2027.

How do you check if you're eligible?

People already contacted by KPMG with a personal ID number are confirmed eligible. Everyone else can check eligibility on KPMG's settlement site using their last name, the last three digits of their SIN, and the email tied to their government account.

What was the total settlement amount?

The settlement in Sweet v. His Majesty the King was approved by Federal Court in May 2026 for $8.76 million.