Canadians lost more than $704 million to fraud last year, according to the Canadian Anti-Fraud Centre. A big share of that started with a fake CRA text, email, or phone call.
Your CRA account holds your SIN, banking details, and tax history. If a scammer gets in, they can redirect your refund or file false claims in your name.
The good news: a few simple habits make your account much harder to break into. Here's exactly what to do.
The CRA has tightened its rules this year. Here's what's different:
These updates make the basics below more important than ever.
Log in to your CRA account often, not just at tax time. This helps you catch problems early, before they turn into bigger ones.
Watch for these warning signs:
If anything looks off, don't wait. Contact the CRA right away. A strong account security habit is also one of the essential policies every Canadian charity should have in place if you manage accounts on behalf of an organization.
MFA is mandatory for every CRA account. It asks for a one-time passcode every time you sign in, on top of your password.
As of February 2026, the CRA also requires a backup MFA method. This protects you if you lose your phone or change your number.
You can choose from:
To set it up: sign in to your CRA account, select Security settings, then Multi-factor authentication. It takes a few minutes and can save you a lockout headache during tax season. Full setup instructions are on the CRA's MFA help page.
The CRA communicates in specific, predictable ways. Scammers usually break at least one of these rules. See more examples on the CRA's own Recognize a scam page.
If you're ever unsure, don't click anything. Log in directly at canada.ca or call the CRA at 1-800-959-8281 to check your account status.
Use a strong, unique password for your CRA account. Don't reuse a password from another site.
Update it every few months, and right away if you think it may have been exposed in a data breach.
A strong password combines:
Make sure the CRA has your correct phone number and email address on file.
This matters for two reasons:
Email notifications alert you the moment something changes on your account, like a new address, banking update, or representative.
This is one of the simplest early-warning tools available, and it's free to turn on in your account settings.
Only authorize someone (like an accountant or family member) if you fully trust them and know why they need access. They'll need to register for the CRA's "Represent a Client" service before you can grant them access.
Review your list of authorized representatives regularly. Remove anyone who no longer needs it
If a business or organization asks to access your CRA information, verify they're legitimate first.
You can check a business's registration through your provincial or federal corporate registry before sharing any information. Weak digital security around donor or client data can also raise questions with the CRA. See What Does Your Charity Website Tell the CRA, and Why Does It Matter?
If you clicked a link, entered information, or think your account may be compromised, act quickly:
Reporting matters even if you didn't lose money. It helps the CRA and police track scam patterns and warn others. A compromised account can also create downstream compliance issues — see our breakdown of top Canadian charity compliance issues the CRA watches for.
The CRA may call or mail you, but it will never text you a refund link or ask for payment by e-transfer, gift card, or cryptocurrency.
Yes. MFA is required for all CRA accounts, and a backup MFA method has been required since February 2026.
1-800-959-8281 for individuals, or 1-800-959-5525 for businesses.
Change your CRA password right away, contact the CRA to flag your account, and report the incident to the Canadian Anti-Fraud Centre.
The material provided on this website is for information purposes only.. You should not act or abstain from acting based upon such information without first consulting a Charity Lawyer. We do not warrant the accuracy or completeness of any information on this site. E-mail contact with anyone at B.I.G. Charity Law Group Professional Corporation is not intended to create, and receipt will not constitute, a solicitor-client relationship. Solicitor client relationship will only be created after we have reviewed your case or particulars, decided to accept your case and entered into a written retainer agreement or retainer letter with you.

DOV GOLDBERG, J.D. is a lawyer at B.I.G. Charity Law Group and has dedicated his career exclusively to Charity and Not-for-Profit Law for over a decade. Dov guides charities, foundations, and non-profit organizations through every stage of the registration process, offering practical legal advice with a focus on compliance, governance, and long-term success. Known for his hands-on approach and deep knowledge of CRA requirements, Dov is committed to helping clients build strong, sustainable, and legally sound organizations.