A CRA data breach settlement could pay eligible Canadians up to $5,200. Here’s who may qualify, what records to save, and how to avoid fake payout messages online from criminals.
Table of Contents
What Happened?
The affected services included CRA My Account, My Service Canada Account, and other accounts reached through GCKey.
Criminals used credential stuffing, which means trying usernames and passwords stolen in earlier breaches. In some cases, they changed payment details or filed fraudulent benefit claims in victims’ names.
The Federal Court approved the settlement on May 5, 2026. The Government of Canada denies wrongdoing.
Personal and financial details can remain useful to criminals long after an attack. They may use them for phishing messages, account takeovers, or identity theft.
You may also have information leaked in another incident without realizing it. If you are unsure, automatic monitoring can help you spot problems earlier.
Futureproof monitors your data for leaks 24/7 and helps you reduce scam risks with simple, clear steps.
Who Qualifies for CRA Settlement Payments?
Class members include people whose government account information was accessed without permission from March 1 through December 31, 2020.
However, payment eligibility is narrower.
You may qualify only if the credential-stuffing attacks accessed your information between June 15 and August 30, 2020. You may also qualify if criminals used that information for fraud.
If KPMG emailed you about the settlement, the official website says you are eligible to apply. You can also check using your:
- Last name
- Email address
- Last three SIN digits
Use only the official KPMG settlement website when entering this information.
Futureproof scans your data for leaks and shows exactly how to close security gaps — before scammers find them first.
Check my safetyWho Was Affected and What Information Was Accessed?
Court records identify about 34,304 access claimants and 13,661 fraud claimants.
Access claimants had personal information viewed by unauthorized people. Fraud claimants had information viewed and then used to change account details or redirect government payments.
Court documents specifically mention personal information and direct deposit information. However, the settlement website does not list every data field involved.

At Futureproof, Kevin explains digital safety in simple words, with clear tips and zero fluff. He holds a degree in information technology and studies fraud trends to keep his tips up-to-date.
In his free time, Kevin plays with his cat, enjoys board-game nights, and hunts for New York’s best cinnamon rolls.
