1/5 The GC has taken action in response to credential stuffing attacks mounted on the GCKey service and the CRA.
2/5 The password/usernames of 9,041 users were collected fraudulently and used to try and access GC services. We cancelled these GCKey accounts & departments have been contacting Canadians who are affected.
3/5 Credential stuffing attacks involve the use of passwords/usernames collected from previous hacks worldwide.
4/5 We’re reviewing the activity associated with those accounts that have evidence of potentially suspicious activity. We’re continuing our investigation to determine if there have been any privacy breaches.
5/5 Canadians should check their online accounts that have the same password/username for suspicious activity. To reduce the risk of cyberattacks, use unique passwords for different accounts. For more information visit https://bit.ly/2E21RCa