• Home
  • The CRA Breach Settlement Is Paying Out Now, Here's How to Claim Yours
By Alan Gilman profile image Alan Gilman
2 min read

The CRA Breach Settlement Is Paying Out Now, Here's How to Claim Yours

Deloitte is currently processing claims for $13.17 million. The deadline is November 27, 2024, and if you had your Government of Canada account compromised between March and August 2020, you need to file now, the window closes in less than three months.

Who qualifies for the base $150 payment

You're in the settlement class if hackers accessed your CRA or My Service Canada account during the 2020 credential-stuffing attacks. The breach wasn't a failure of government encryption. It was simpler: fraudsters took usernames and passwords leaked from other sites and tried them on CRA login pages. Thousands worked.

The Federal Court approved the Todd Sweet v. His Majesty the King settlement in 2024. Roughly 12,700 individuals are estimated to be part of the class. If the CRA notified you in 2020 that your account had been accessed without authorization, you're likely eligible. But you still need to file, this is an opt-out settlement, meaning you're included automatically but payment requires an active claim.

The base payout for inconvenience sits around $150 per person. That number drops if more people claim than expected, since the $13.17 million fund must also cover legal fees and administration costs before it's split. If you were one of the people who spent hours on hold with CRA agents in 2020 trying to reverse fraudulent CERB applications, $150 may feel absurdly low. It is. But it's also guaranteed money if you file.

The $2,500 upper limit requires receipts

The real money is in the documented-damages tier. If you can prove time lost or financial harm, legal fees, accounting costs, loan application rejections due to the breach, you can claim up to $2,500. The burden of proof is high. You need phone logs, dated correspondence, receipts for professional advice, or credit reports showing fraudulent activity traced to the 2020 breach.

Most people won't clear that bar. Identity theft from a 2020 breach can surface years later when a fraudulent line of credit appears on your file, but proving causation to Deloitte's satisfaction requires documentation most Canadians don't keep. If you paid a lawyer or accountant to help unwind the mess in 2020, find those invoices. If you tracked your time spent on hold, submit that log. Without it, you get the $150.

What the settlement actually buys

The government denied liability. The settlement avoids a trial over whether the CRA had adequate two-factor authentication in place when the attacks happened. It didn't. MFA wasn't mandatory until after the breach. The settlement is structured as "inconvenience" compensation, not an admission of negligence, which is why the dollar figures are modest.

Since 2020, the CRA has mandated multi-factor authentication and introduced email notifications whenever direct deposit details change. These are meaningful upgrades, but they came after 12,700 people had their Social Insurance Numbers and tax data used to fraudulently claim COVID-19 relief benefits.

How to file before November 27

The claim form is on Deloitte's settlement portal. You'll need your SIN, the approximate date you were notified of the breach, and any supporting documents if you're claiming beyond the base amount. The form takes under 10 minutes if you're filing for the $150 only. It takes significantly longer if you're assembling a documented-damages claim.

Set a calendar reminder for November 20. The CRA will not call you. The second-round notification was a single PDF that looked like routine mail, and many people missed it entirely. If you were part of the 2020 breach and you don't file, you forfeit the payment. The fund gets split among whoever shows up.

The $150 won't cover what the breach actually cost you. But it's real money, and it requires 10 minutes of your time before the end of November.