CRA Breach Settlement: Who Qualifies for Up to $5,280 and How to File Before February 2027
The Federal Court approved an $8.7 million settlement in May 2026 for victims of the 2020 CRA and GCKey credential stuffing attacks. KPMG opened the claims portal on August 4, 2026, and eligible Canadians have until February 3, 2027 to file. Here's what happened, who can claim compensation, and what you need to know.
What the settlement covered
Between June 26 and August 18, 2020, credential stuffing attacks compromised thousands of CRA and GCKey accounts. The hackers didn't break into government servers. They used login credentials stolen from other breaches, LinkedIn, Adobe, old forum leaks, and tried them against CRA portals, where thousands of Canadians had reused the same passwords. In at least 12,700 accounts, attackers changed direct deposit information and filed fraudulent CERB applications, leaving victims locked out of their accounts and, in many cases, stuck with a debt they never incurred.
The Federal Court approved the settlement on May 5, 2026. The government paid but did not admit fault, which is standard in Crown settlements. Rice Parsons Leoni & Elliott LLP (formerly Rice Harbut Elliott LLP), the law firm that represented the class, received court approval for 33.33% of net settlement proceeds in legal fees.
The three tiers of compensation
Access claims: Up to $80 per person for time and inconvenience, calculated at $20 per hour for up to 4 hours. This covers everyone whose account was compromised during the breach window, even if they didn't lose money. The compensation recognizes the bureaucratic nightmare, being locked out of tax portals during CERB season, spending hours on hold, filing affidavits to prove you didn't apply for benefits someone else stole in your name.
Fraud claims: For claimants whose information was used fraudulently, compensation is calculated at $20 per hour for up to 10 hours, for a maximum of $200.
Special compensation fund: If you suffered financial damage or identity theft fallout, you can file for up to $5,000 for documented out-of-pocket expenses. Examples: unreimbursed fraud losses, credit monitoring costs, legal fees, or fees stemming from credit freezes. These claims require documentation like bank statements or letters from credit bureaus.
The government does not automatically send cheques. You have to file a claim through the KPMG portal at breachsettlementcanada.kpmg.ca, and for the special compensation fund, provide documentation.
Why some victims don't qualify
Being locked out of your CRA account in 2020 does not automatically make you eligible. Compensation is limited to two specific groups: those whose accounts were subject to unauthorized access during the credential stuffing attacks between June 26 and August 18, 2020, or those whose information was accessed through a Represent a Client account between October 8 and November 25, 2020. If CRA flagged your account because you forgot your password or failed a security question, that's not covered.
CERB confusion trips up some claimants. If you received a letter saying you owed CERB money you never applied for, that's a separate administrative process with CRA collections. The settlement addresses damages, not debt forgiveness. Some victims assume the payout will clear the fraudulent debt. It won't.
The claims window
Claims must be submitted no later than February 3, 2027. KPMG, as claims administrator, is processing all submitted claims. If you never received notice about the settlement, you can still file if you believe you're eligible. Visit the official portal at breachsettlementcanada.kpmg.ca to verify your eligibility using your last name, the last three digits of your SIN, and the email address associated with your government account.
What to expect
Final payout amounts will depend on the total number of valid claims submitted. The settlement provides tiered compensation, and the actual dollar amounts may be subject to pro-rata adjustment depending on claim volume. Roughly $6 million of the $8.7 million settlement has been set aside for class members, with the remainder covering legal fees, administrative costs, and honoraria for representative plaintiffs.
The settlement does not address long-tail identity theft cases that materialized years after the 2020 breach. Some victims didn't realize their breach was the root cause of fraud until 2023 or later, tax returns filed in their name, collections calls for debts they never opened. Those cases may be covered if the victim can demonstrate the harm originated from the 2020 breach and files before the February 2027 deadline.
The Federal Court approved an $8.7 million settlement in May 2026 for victims of the 2020 CRA and GCKey credential stuffing attacks. KPMG opened the claims portal on August 4, 2026, and eligible Canadians have until February 3, 2027 to file. Here's what happened, who can claim compensation, and what you need to know.
What the settlement covered
Between June 26 and August 18, 2020, credential stuffing attacks compromised thousands of CRA and GCKey accounts. The hackers didn't break into government servers. They used login credentials stolen from other breaches, LinkedIn, Adobe, old forum leaks, and tried them against CRA portals, where thousands of Canadians had reused the same passwords. In at least 12,700 accounts, attackers changed direct deposit information and filed fraudulent CERB applications, leaving victims locked out of their accounts and, in many cases, stuck with a debt they never incurred.
The Federal Court approved the settlement on May 5, 2026. The government paid but did not admit fault, which is standard in Crown settlements. Rice Parsons Leoni & Elliott LLP (formerly Rice Harbut Elliott LLP), the law firm that represented the class, received court approval for 33.33% of net settlement proceeds in legal fees.
The three tiers of compensation
Access claims: Up to $80 per person for time and inconvenience, calculated at $20 per hour for up to 4 hours. This covers everyone whose account was compromised during the breach window, even if they didn't lose money. The compensation recognizes the bureaucratic nightmare, being locked out of tax portals during CERB season, spending hours on hold, filing affidavits to prove you didn't apply for benefits someone else stole in your name.
Fraud claims: For claimants whose information was used fraudulently, compensation is calculated at $20 per hour for up to 10 hours, for a maximum of $200.
Special compensation fund: If you suffered financial damage or identity theft fallout, you can file for up to $5,000 for documented out-of-pocket expenses. Examples: unreimbursed fraud losses, credit monitoring costs, legal fees, or fees stemming from credit freezes. These claims require documentation like bank statements or letters from credit bureaus.
The government does not automatically send cheques. You have to file a claim through the KPMG portal at breachsettlementcanada.kpmg.ca, and for the special compensation fund, provide documentation.
Why some victims don't qualify
Being locked out of your CRA account in 2020 does not automatically make you eligible. Compensation is limited to two specific groups: those whose accounts were subject to unauthorized access during the credential stuffing attacks between June 26 and August 18, 2020, or those whose information was accessed through a Represent a Client account between October 8 and November 25, 2020. If CRA flagged your account because you forgot your password or failed a security question, that's not covered.
CERB confusion trips up some claimants. If you received a letter saying you owed CERB money you never applied for, that's a separate administrative process with CRA collections. The settlement addresses damages, not debt forgiveness. Some victims assume the payout will clear the fraudulent debt. It won't.
The claims window
Claims must be submitted no later than February 3, 2027. KPMG, as claims administrator, is processing all submitted claims. If you never received notice about the settlement, you can still file if you believe you're eligible. Visit the official portal at breachsettlementcanada.kpmg.ca to verify your eligibility using your last name, the last three digits of your SIN, and the email address associated with your government account.
What to expect
Final payout amounts will depend on the total number of valid claims submitted. The settlement provides tiered compensation, and the actual dollar amounts may be subject to pro-rata adjustment depending on claim volume. Roughly $6 million of the $8.7 million settlement has been set aside for class members, with the remainder covering legal fees, administrative costs, and honoraria for representative plaintiffs.
The settlement does not address long-tail identity theft cases that materialized years after the 2020 breach. Some victims didn't realize their breach was the root cause of fraud until 2023 or later, tax returns filed in their name, collections calls for debts they never opened. Those cases may be covered if the victim can demonstrate the harm originated from the 2020 breach and files before the February 2027 deadline.
Sources
Read Next
Asset managers cut product portfolios to fund AI and outsourcing overhauls
ETFs now hold 42% of Canadian fund assets as OSC tightens crypto and liquidity rules
One in Five Canadian Parents Still Pays Bills for Kids in Their Late Thirties
Joint mortgages surge in Ontario and B.C. as first-time buyers face rising delinquency pressure