Canadians affected by the 2020 Government of Canada online account breach may be able to apply for compensation under a court-approved class action settlement connected to CRA My Account, My Service Canada Account, and other accounts accessed through GCKey.
The settlement was approved by the Federal Court on May 5, 2026. KPMG is listed as the claims administrator, and the official settlement materials say eligible claimants may receive payments depending on how their information was accessed or used.
The most important point for readers is practical: not every class member will receive money, and most people should not assume they will receive the maximum amount advertised in headlines. Payment eligibility depends on whether the person’s information was accessed during the credential-stuffing attacks between June 15 and August 30, 2020, and whether the information was only accessed or was also used for fraud.
This guide explains who may qualify, how the payment tiers work, what documents may help, and how to avoid fake settlement messages.
What the CRA My Account Settlement Is About
The class action concerns alleged unauthorized access to personal or financial information in Government of Canada online accounts during 2020. The accounts named in the settlement materials include CRA My Account, My Service Canada Account, and other Government of Canada online accounts accessed using GCKey.
The underlying incident involved credential stuffing. In plain terms, credential stuffing happens when attackers try username and password combinations obtained from other breaches to see whether the same credentials work on another service. It is especially risky when people reuse passwords across financial, government, email, or shopping accounts.
The lawsuit alleged that inadequate safeguards allowed unauthorized third parties to access confidential personal and financial information. In some cases, the settlement materials say fraudulent benefit applications were made. The Government of Canada denies wrongdoing, and the settlement resolves the claims without that allegation being proven at trial.
For affected account holders, the settlement is less about a general data breach notice and more about what happened to their own account: whether information was accessed, whether it was used for fraud, and whether they spent time or money dealing with the consequences.
Who May Be Included in the Class
The class definition covers people whose personal or financial information in a Government of Canada online account was disclosed to a third party without authorization between March 1, 2020, and December 31, 2020.
Government of Canada online accounts listed in the settlement materials include:
- Canada Revenue Agency accounts, including CRA My Account.
- My Service Canada Account.
- Other Government of Canada online accounts accessed using GCKey.
There is an important distinction between being a class member and being entitled to a payment. The settlement materials say not all class members will receive compensation. Payments are tied to the credential-stuffing attacks directed at Government of Canada online accounts between June 15 and August 30, 2020.
A person may be eligible to apply for payment if their personal information was accessed during that attack period, or if it was accessed and then used for fraudulent purposes.
The settlement materials also refer to “Excluded Persons,” meaning people who contacted Murphy Battista LLP about the CRA privacy breach class action, Federal Court file number T-982-20, before June 24, 2021. The official materials state that Excluded Persons are included in the settlement, but payment entitlement still depends on the settlement agreement’s eligibility rules.
If KPMG sent you a settlement notice, the materials say you are eligible to apply for a payment. People who are unsure can use the eligibility check on the official settlement website by entering the requested identifying information.
Possible CRA Breach Settlement Payments
The settlement has three main compensation categories. The maximum combined amount can reach $5,280, but that figure applies only if a claimant qualifies for the maximum available amount in each category. Many people will fall into a lower tier.
| Claim type | Maximum listed amount | What it covers |
|---|---|---|
| Access claim | Up to $80 | Time spent dealing with unauthorized access to personal or financial information. |
| Fraud claim | Up to $200 | Time spent addressing fraudulent use of personal or financial information. |
| Special compensation fund | Up to $5,000 | Documented out-of-pocket expenses related to the breach, such as unreimbursed fraud losses, identity theft costs, or professional fees. |
Access Claims: Up to $80
The access claim category is for time spent dealing with unauthorized access. The listed rate is $20 per hour for up to four hours, for a maximum of $80.
This tier is likely to apply where a person’s information was accessed but there is no documented fraudulent use. Examples of related time may include reviewing account activity, contacting government departments, securing affected accounts, or taking reasonable steps after learning about the access.
Fraud Claims: Up to $200
The fraud claim category is for time spent dealing with fraudulent use of personal or financial information. The listed rate is $20 per hour for up to 10 hours, for a maximum of $200.
This category may be relevant where the compromised information was used for something more serious than access alone, such as an unauthorized benefit application or another fraud-related account issue. Claimants should expect this category to require a clearer explanation of what happened and how much time was spent fixing it.
Special Compensation Fund: Up to $5,000
The special compensation fund is for documented out-of-pocket expenses connected to fraudulent use of personal or financial information. The settlement materials give examples such as unreimbursed fraud losses, identity theft costs, and professional fees.
This is the category behind many “up to $5,000” headlines. It should not be read as an automatic payment. A claimant seeking reimbursement from this fund should be ready to provide records showing the expense, the amount, and its connection to the breach.
Why the Full $5,280 Will Not Apply to Everyone
The largest number in the settlement is useful for understanding the ceiling, but it can be misleading if read as a typical payout.
A claimant would need to qualify for the maximum access claim, the maximum fraud claim, and the maximum special compensation amount to reach $5,280. That requires more than being part of the class. It requires the right facts and, for the larger reimbursement category, documentation.
The settlement materials also say payment amounts may be reduced depending on the number of claims submitted. That means even valid claims could receive less than the maximum listed amount if approved claims exceed the available funds for compensation.
A practical way to think about the tiers is:
- If your information was accessed but not used for fraud, the access claim may be the relevant category.
- If your information was used fraudulently, the fraud claim may also apply.
- If you paid money out of pocket because of the fraudulent use, the special compensation fund may be relevant, but documentation matters.
How to Check Eligibility and Prepare a Claim
The claim form may not be available at the moment a reader first checks the settlement website. The official materials tell class members to visit the settlement website regularly for updates and instructions on applying for compensation.
Affected Canadians can still prepare before the claim period opens.
- Use the official eligibility check. The settlement website asks for a last name, the last three digits of a SIN, and an email address to verify compensation eligibility.
- Search for a notice from KPMG. Check both the inbox and spam folder for settlement correspondence from the claims administrator.
- Gather account records. Save any CRA, Service Canada, or government account correspondence connected to unauthorized access or account recovery.
- Collect fraud records if relevant. Keep any documents related to unauthorized benefit applications, account changes, corrected tax slips, or communications about fraudulent activity.
- Organize expense records. For the special compensation fund, collect receipts, invoices, bank records, credit monitoring bills, professional fee records, and other documents that show out-of-pocket costs.
- Secure your government accounts. Use unique passwords, update recovery information, and confirm direct deposit details through the proper government account process.
The safest approach is to prepare records now and wait for the official claims process rather than responding to unsolicited messages.
Documents That May Help Support a Claim
The documentation you need depends on the claim category. A simple access claim may require less proof than a fraud or reimbursement claim, but keeping records is still useful.
Documents that may help include:
- Government correspondence about unauthorized account access.
- Notices about direct deposit changes or account recovery.
- Records of fraudulent CERB, CESB, or other benefit activity, if applicable.
- Bank statements showing unreimbursed losses tied to the incident.
- Receipts for identity theft recovery costs or credit monitoring.
- Invoices from professionals who helped resolve fraud or identity theft issues.
- Correspondence with credit agencies, banks, police, CRA, Service Canada, or other relevant organizations.
Do not upload or send sensitive documents through a link in a text message or random email. Use only the official claims process provided by the administrator.
How to Avoid CRA Settlement Scams
Class action settlements often attract scam messages because the topic already involves money, deadlines, and personal information. This settlement is no different: anyone who may qualify should be careful before clicking links or entering identity details.
A legitimate settlement process should not require an upfront fee to release funds. Any message asking you to pay a processing charge, tax, courier fee, verification fee, or transfer fee before receiving compensation should be treated as suspicious.
Watch for these warning signs:
- A text message promising instant CRA breach money.
- An email that pressures you to act immediately or lose a payout.
- A link that does not match the official settlement website.
- A request for full SIN, banking password, CRA login, or one-time security code.
- A demand for payment by gift card, cryptocurrency, wire transfer, or e-transfer.
If a message looks suspicious, do not click the link. Go directly to the settlement website through a browser or use the official contact information already published by the claims administrator.
Key Takeaway for Affected Canadians
The CRA My Account breach settlement may provide compensation to eligible people whose Government of Canada online account information was accessed, or accessed and used for fraud, during the 2020 credential-stuffing attacks.
The settlement has meaningful limits. The largest advertised payout is not automatic, payment depends on eligibility and claim category, and documented expenses will matter for larger reimbursement claims.
For now, the most useful steps are to verify eligibility through the official settlement process, gather records, secure affected accounts, and ignore unsolicited messages that ask for money or sensitive login information.
This article is for general informational purposes only and is not legal, tax, financial, or cybersecurity advice. Settlement rules, claim requirements, deadlines, and payment amounts should be confirmed through the official claims administrator before filing.
