CRA Cybersecurity Failures and the Heartbleed Breach Investigation
The Deep dive podcast di Eric Demers
Note sull'episodio
In this episode of The Deep Dive, we unpack a troubling history of cybersecurity failures at the Canada Revenue Agency. From the 2014 Heartbleed breach—where a critical vulnerability exposed the Social Insurance Numbers of 900 Canadians and led to the arrest of a 19‑year‑old student—to the wave of credential stuffing attacks that compromised over 42,000 accounts between 2020 and 2023, the CRA’s digital defenses have repeatedly fallen short. We explore what went wrong, how a major class-action settlement and damning reports from the Privacy Commissioner forced change, and whether mandatory multi-factor authentication is enough to restore trust. Finally, we look at what individual taxpayers can do—beyond hoping institutions get it right—to protect themselves in an era of relentless cyber threats.