Suspicious activity has been detected by the Canadian Ministry of Financein more than 48,000 accounts of the Canada Revenue Agency (CRA). The agency has been in the spotlight in recent months after a large number of attacks affected systems .

According to the Treasury Department, the cyberattacks that took place in July and August targeted both the CRA and GCKey, an online portal that allows users to access government services, such as employment insurance and immigration services.
As it has been learned, the malicious actors who carried out the attacks used a method called credential stuffing to gain access to CRA accounts. This method involves using usernames and passwords across multiple platforms to abuse accounts that use the same credentials across multiple previously compromised accounts
While a large number of CRA accounts showed evidence of suspicious activity, the Treasury Department confirmed that GCKey had not been compromised by malicious actors. However, GCKey has revoked 9,300 credentials for its system as a precautionary measure and has contacted affected users to advise them on how to block subsequent cyberattack attempts.
According to CBC News, those who receive a revocation message can either register with new credentials, or use SecureKey Concierge for more secure, future access.
The Ministry of Finance announced that the RCMP (Royal Canadian Mounted Police) investigation into the cyberattacks is ongoing and that the departments involved have contacted the Office of the Privacy Commissioner.
