The federal government confirmed a cyberattack exposing emails and phone numbers linked to CRA, ESDC, and CBSA accounts. Image: The Canadian Press


Sept 10, 2025 Tags:

A federal government cyber incident has exposed the emails and phone numbers of several Canadians linked to government accounts.

The breach affected users of the Canada Revenue Agency (CRA), Employment and Social Development Canada (ESDC), and Canada Border Services Agency (CBSA). Officials confirmed the breach after being alerted by a security partner last month.

How the Breach Was Detected

On August 17, cybersecurity provider 2Keys Corporation notified the government about unusual activity.
2Keys supplies the multi-factor authentication tool used for secure access to CRA, ESDC, and CBSA accounts.
The company discovered the breach, reported it quickly, and began working with federal officials.

External cybersecurity experts were brought in to assist with the investigation. Authorities stressed that the response was immediate, aiming to reduce risks for affected users.

What Information Was Compromised

Treasury Board of Canada Secretariat confirmed that only limited data was accessed.
Phone numbers tied to CRA and ESDC accounts were exposed.
Email addresses linked to CBSA accounts were also accessed.

The breach occurred between August 3 and August 15.
The vulnerability was traced back to a routine software update.
That update unintentionally created a gap, which hackers exploited.

How the Attack Was Carried Out

Authorities say the malicious actor used the stolen phone numbers to send spam text messages.
These messages contained a link to a fake government website designed to steal personal details.
Officials warned Canadians to avoid clicking on suspicious links and to remain cautious.

The Treasury Board noted that the fake website was quickly identified and blocked.
No evidence suggests that further sensitive data, such as banking or tax information, was compromised.

Government Response and Assurance

Officials emphasized that the incident was contained and systems have now been secured.
The multi-factor authentication service is fully restored and considered safe for continued use.

The Treasury Board reassured Canadians that there is “no indication of additional personal data being disclosed.”
Government cybersecurity teams continue to monitor for any further suspicious activity.

What Canadians Should Do

Experts recommend Canadians stay alert for phishing attempts.
Avoid sharing personal information through links received in unsolicited emails or texts.
If you receive a suspicious message claiming to be from the government, delete it immediately.

Users are also encouraged to regularly update passwords and enable two-step verification where available.

Why This Matters

Cyberattacks on government systems raise concerns about data safety and public trust.
Even limited breaches can open the door to scams targeting unsuspecting Canadians.
The government’s quick detection and response may have prevented a larger security fallout.

Canadians, however, remain at risk of phishing messages crafted from the stolen data.

While officials insist the damage was limited, the incident is a sharp reminder of growing cyber threats.

Canadians are urged to stay vigilant, watch for scams, and protect their personal information online.

How useful was this post?

Click on a star to rate it!

Average rating 0 / 5. Vote count: 0

No votes so far! Be the first to rate this post.

You may also like

Cheap Laptops Challenge MacBook Neo With More Storage and Memory

Apple has stepped into the budget laptop segment with the launch of the MacBook Neo, priced at $599. On paper,....

Apple iPhone 17e Leads Apple Product Launch Week With M4 iPad Air Update

Apple has kicked off a fresh round of hardware announcements with a clear focus on value and performance. The company....

Viral AI Caricature Trend Sparks Serious Privacy Fears, Expert Warns

A viral social media trend that turns personal details into AI-generated caricatures is raising red flags among cybersecurity experts, who....

India AI Impact Summit 2026: Global Leaders, CEOs Gather in New Delhi for High-Stakes Talks

India has opened a major global gathering focused on artificial intelligence and its growing worldwide influence. The India AI Impact....

PlayStation State of Play February 2026: Biggest Announcements and Games Revealed

One week after Nintendo set the tone for 2026, PlayStation stepped forward with its own showcase. The PlayStation State of....

Bell AI Data Centre Near Regina Signals Major Tech Investment in Saskatchewan

Bell Canada is planning a major expansion of artificial intelligence infrastructure near Regina, according to newly filed municipal documents.The project....

Moltbook: Experts Flag Security Risks on Viral AI Forum

A strange new social platform has captured the internet’s curiosity — and concern. Moltbook, a social forum designed exclusively for....

Global Software Stocks Slide as AI Fears Trigger ‘SaaSpocalypse’

A global sell-off in software stocks is accelerating as investors grow increasingly anxious about how fast artificial intelligence could upend....

Experts Find Rare Space Molecule Hints at Life Origins of Past Life

Scientists have identified the largest organic molecule containing sulfur ever found in interstellar space, a discovery that may help explain....

NASA updates Artemis II wet dress test and launch windows soon

NASA has moved the timeline for a key Artemis II test because of severe winter weather in Florida. The agency....

Meta Blocks Teens From AI Characters Ahead of Child Safety Trial

Meta is temporarily revoking teen access to its AI characters as scrutiny over tech platforms and child safety intensifies. The....

NASA Astronaut Sunita Williams Retires After 9-Month Orbital Ordeal

NASA astronaut Sunita Williams has announced her retirement, marking the end of a remarkable 27-year career in space exploration. Her....