Independent writing on tax-smart planning, mortgage strategy, and retirement building. For Canadian professionals who want the whole picture, not just a piece of it.
The CRA breach settlement is paying claims now: eligibility and amounts explained
The federal government set aside $15.5 million in 2024 to compensate Canadians whose My Account or GCKey login credentials were stolen during a five-month window in 2020. The deadline to file is November 27, 2024. Most eligible people will receive $150.00, but the process is stricter than many claimants expect.
The breach ran from March 1 to August 14, 2020, a period when CERB and CESB applications surged and the CRA's online portals became prime targets for fraud. Hackers used credential stuffing, passwords leaked from unrelated websites, to gain access to government accounts. If your account was compromised during that window and you received a formal "Notice of Personal Information Breach" letter from the CRA or another federal department, you qualify. Being targeted by CRA scam calls or receiving generic phishing emails does not count.
Who gets paid and how much
The settlement divides compensation into two categories. The first is a baseline payment of $150.00 for "Identity Theft," which covers non-pecuniary damages, emotional distress, inconvenience, the general violation of having your tax information accessed without permission. This amount is standard for every verified claimant. You do not need to prove financial loss to receive it.
The second category reimburses actual documented losses, capped at $5,000 per person. This is where the burden of proof rises sharply. To claim more than the baseline, you need receipts. Credit monitoring subscriptions, legal fees, lost wages from time spent resolving the breach, identity theft insurance, all require dated invoices or pay stubs. The administrator, RicePoint Administration Inc., treats these claims like an audit. A vague description of "time spent on the phone" will be rejected. A timestamped log paired with proof of hourly wages might clear.
The structural problem with GCKey
The breach exposed a design trade-off that federal IT still carries. GCKey is a single sign-on system used by millions of Canadians to access services across multiple departments, CRA, Service Canada, Employment and Social Development Canada. The convenience is real. Log in once, access everything. The risk is equally real. Compromise one password and the entire ecosystem opens. In 2020, Multi-Factor Authentication was optional. It became mandatory only after the breach forced the government's hand.
The $15.5 million pool is small relative to the number of Canadians affected. That reflects how class action settlements value privacy breaches. Courts struggle to assign a dollar figure to the intangible harm of having your Social Insurance Number or tax data viewed by a stranger. The $150 baseline is not compensation for what was taken; it is a legal placeholder for something difficult to measure.
What filing actually requires
You must submit your claim through the official RicePoint portal before the November 27 deadline. The process is not automatic. Simply being part of the affected group does not trigger a payment. You need either the reference number from your breach notification letter or enough identifying information for the administrator to verify your inclusion in the 2020 list.
Payments are scheduled for 2025, after RicePoint finishes verifying all submitted claims. The administrator cross-checks each filing against the government's official breach database. If your name is not on that list, the claim fails regardless of what you experienced. This is a settlement for a specific technical failure during a specific five-month period, not a catch-all for CRA-related fraud.
The taxability question comes up often. Settlements for non-pecuniary damages, pain, suffering, invasion of privacy, are generally not considered taxable income by the CRA. The $150 falls into that category. Reimbursements for actual financial losses are treated differently depending on what they replaced, but for most claimants the tax impact will be zero.
Critics of the settlement argue the total fund is too small to deter future negligence. $15.5 million spread across thousands of claimants works out to less than the cost of a single data security audit for a mid-sized corporation. Whether that creates enough financial pressure to prevent the next breach is a separate question from whether this one is paying what it promised.
The federal government set aside $15.5 million in 2024 to compensate Canadians whose My Account or GCKey login credentials were stolen during a five-month window in 2020. The deadline to file is November 27, 2024. Most eligible people will receive $150.00, but the process is stricter than many claimants expect.
The breach ran from March 1 to August 14, 2020, a period when CERB and CESB applications surged and the CRA's online portals became prime targets for fraud. Hackers used credential stuffing, passwords leaked from unrelated websites, to gain access to government accounts. If your account was compromised during that window and you received a formal "Notice of Personal Information Breach" letter from the CRA or another federal department, you qualify. Being targeted by CRA scam calls or receiving generic phishing emails does not count.
Who gets paid and how much
The settlement divides compensation into two categories. The first is a baseline payment of $150.00 for "Identity Theft," which covers non-pecuniary damages, emotional distress, inconvenience, the general violation of having your tax information accessed without permission. This amount is standard for every verified claimant. You do not need to prove financial loss to receive it.
The second category reimburses actual documented losses, capped at $5,000 per person. This is where the burden of proof rises sharply. To claim more than the baseline, you need receipts. Credit monitoring subscriptions, legal fees, lost wages from time spent resolving the breach, identity theft insurance, all require dated invoices or pay stubs. The administrator, RicePoint Administration Inc., treats these claims like an audit. A vague description of "time spent on the phone" will be rejected. A timestamped log paired with proof of hourly wages might clear.
The structural problem with GCKey
The breach exposed a design trade-off that federal IT still carries. GCKey is a single sign-on system used by millions of Canadians to access services across multiple departments, CRA, Service Canada, Employment and Social Development Canada. The convenience is real. Log in once, access everything. The risk is equally real. Compromise one password and the entire ecosystem opens. In 2020, Multi-Factor Authentication was optional. It became mandatory only after the breach forced the government's hand.
The $15.5 million pool is small relative to the number of Canadians affected. That reflects how class action settlements value privacy breaches. Courts struggle to assign a dollar figure to the intangible harm of having your Social Insurance Number or tax data viewed by a stranger. The $150 baseline is not compensation for what was taken; it is a legal placeholder for something difficult to measure.
What filing actually requires
You must submit your claim through the official RicePoint portal before the November 27 deadline. The process is not automatic. Simply being part of the affected group does not trigger a payment. You need either the reference number from your breach notification letter or enough identifying information for the administrator to verify your inclusion in the 2020 list.
Payments are scheduled for 2025, after RicePoint finishes verifying all submitted claims. The administrator cross-checks each filing against the government's official breach database. If your name is not on that list, the claim fails regardless of what you experienced. This is a settlement for a specific technical failure during a specific five-month period, not a catch-all for CRA-related fraud.
The taxability question comes up often. Settlements for non-pecuniary damages, pain, suffering, invasion of privacy, are generally not considered taxable income by the CRA. The $150 falls into that category. Reimbursements for actual financial losses are treated differently depending on what they replaced, but for most claimants the tax impact will be zero.
Critics of the settlement argue the total fund is too small to deter future negligence. $15.5 million spread across thousands of claimants works out to less than the cost of a single data security audit for a mid-sized corporation. Whether that creates enough financial pressure to prevent the next breach is a separate question from whether this one is paying what it promised.
Read Next
Couche-Tard Q1 Profit Climbs While Lululemon Cuts Revenue Forecast: What Canadian Investors Need to Know
Retaliatory tariffs feel good until they hit Canadian wallets
Trade wars end when voters punish governments, not when diplomats shake hands
RBC calls the housing recovery now, but Vancouver and Toronto lag while Calgary surges