The door is now open after six years, a federal lawsuit, and a court-approved settlement. Canadians who had their government online accounts hacked in the summer of 2020 can now file claims via the CRA cyber breach settlement portal, which is run by KPMG and can be found at breachsettlementcanada.kpmg.ca, as of August 4, 2026. The deadline is February 3, 2027, which seems reasonable until you consider how many people are likely still unaware of this.
In a very particular COVID-era way, the breach itself was startling. Credential stuffing, which involves simply tossing stolen username and password combinations at government login pages until something works, was a tactic employed by hackers that worked far more frequently than it should have. Tens of thousands of Canadians had their CRA accounts, My Service Canada accounts, and GCKey-linked portals accessed without their knowledge between June and August of 2020. The victims’ home addresses, bank account information, and social insurance numbers were all lying around, and strangers frequently used them to apply for CERB and CESB in their names.
Looking back at the timeline, it’s difficult to avoid getting a little frustrated. In part, the government’s initial response focused on implying that Canadians’ bad password practices were partially to blame. The framing didn’t hold up over time. In August 2022, the Federal Court certified Sweet v. His Majesty the King, a class action lawsuit that reflected a larger legal argument that Ottawa had neglected to implement adequate safeguards to protect sensitive accounts, particularly at a time when millions of people were suddenly depending on those portals to survive financially.
The $8,760,500.90 settlement reached in December of last year is an oddly exact amount that, when split among tens of thousands of potential claimants, somehow feels both significant and modest. The Canadian government disputes any misconduct. Even tho that is standard legal language, it still hurts a little when you consider that people had to spend hours on their own time sorting thru fraudulent benefit applications, freezing credit, and tracking down identity theft fallout.

There are three levels of compensation available via the CRA cyber breach settlement portal. Up to $80, calculated at $20 per hour for up to four hours of time lost dealing with the breach, is available to those whose accounts were accessed but not used fraudulently. The cap increases to $200 if the accessed data was actually utilized—fraudulent CERB claims, diverted benefits, etc. Additionally, there is a Special Compensation Fund that offers up to $5,000 to individuals who experienced actual out-of-pocket losses due to unreimbursed fraud, identity theft fees, or credit freeze penalties.
Before filing, it’s important to understand that not everyone who received a notification letter in 2020 will be eligible for a payment. Claimants who were impacted between June 15 and August 13, 2020, or whose data was accessed thru Represent-a-Client accounts between October and November of that year, are specifically eligible. Your last name and the last three digits of your social insurance number are required on the KPMG portal’s eligibility check page. This is a minor but somewhat awkward requirement, considering the situation.
The entire situation has a somewhat surreal quality. In order to determine your eligibility, you must provide personal identifying information to the portal intended to compensate individuals for a data breach. From a verification perspective, it’s not irrational, but it’s the kind of detail that raises concerns. The irony persists despite the fact that this is a court-administered procedure and KPMG is a respectable company.
Ottawa agreed to donate any unclaimed funds to the Privacy and Access Council of Canada for privacy research after the deadline in February 2027. It’s a sensible result, but it might unintentionally encourage the government to hope that few people apply. Settlements like this typically have lower-than-expected claim rates because people don’t learn about them in time, but that might be reading too much into it.
Before the window closes, anyone who believes they were impacted should check their eligibility at breachsettlementcanada.kpmg.ca and file. Although it won’t make up for what transpired, the accountability that was offered took long enough to materialize.
