News From Multiple Perspectives

CRA profile hack lawsuit settlement claim now open

Published August 7, 2026 at 12:31 PM UTC

Authored by
Every article published on DirectionFreeNews undergoes editorial review by our editorial team. Our editors research publicly available information from multiple trusted news organizations, compare differing perspectives, verify key facts, and publish balanced summaries intended to help readers better understand important events. Our editorial process is designed to reduce editorial bias by considering multiple reputable sources rather than relying on a single viewpoint

The Canada Revenue Agency (CRA) has opened a claims process for an $8.7 million settlement tied to the 2023 data breach that exposed personal tax information of hundreds of thousands of Canadians. The move gives anyone whose CRA online profile was accessed a chance to apply for compensation and signals the agency’s effort to resolve the lawsuit that followed the hack. In June 2023, a security lapse allowed unauthorized parties to view the online tax-filing profiles of roughly 900,000 Canadians, including details such as social-insurance numbers and income data. A class-action lawsuit was filed later that year, alleging the CRA failed to protect sensitive data. The settlement, approved by the Federal Court, allocates $8.7 million to be distributed to claimants who submit proof of a compromised profile. Applications must be filed online by Dec 31 2024 and require the claimant’s CRA reference number, a description of the breach impact and any supporting documentation. The claimants include individuals who reported identity theft, businesses that suffered fraud, and families whose credit scores were damaged. Legal experts note that the settlement does not cover all losses, but it provides a concrete avenue for redress. The CRA will review each claim and issue payments within six months of approval. Observers will watch whether the process is swift enough to restore public confidence in the agency’s digital services and whether additional policy changes follow to prevent future breaches.