How Can You Protect Your CRA Accounts from Scams and Fraud?

Dov Goldberg

Canadians lost more than $704 million to fraud last year, according to the Canadian Anti-Fraud Centre. A big share of that started with a fake CRA text, email, or phone call.

Your CRA account holds your SIN, banking details, and tax history. If a scammer gets in, they can redirect your refund or file false claims in your name.

The good news: a few simple habits make your account much harder to break into. Here's exactly what to do.

What's Changed for CRA Account Security in 2026

The CRA has tightened its rules this year. Here's what's different:

  • Backup MFA is now required. Starting February 2026, CRA account users must add a second multi-factor authentication method, like an authenticator app or passcode grid, so they aren't locked out if they lose their phone. Read the CRA's official announcement.
  • Scammers are using AI. The CRA has warned that generative AI tools are helping fraudsters create more convincing fake CRA emails, texts, and websites, with fewer typos and better formatting than before.
  • A new wave of "refund" text scams. The CRA flagged a fresh round of fake tax-refund texts that link to spoofed versions of the My Account login page.

These updates make the basics below more important than ever.

Monitor Your Account Regularly

Log in to your CRA account often, not just at tax time. This helps you catch problems early, before they turn into bigger ones.

Watch for these warning signs:

  • Changes to your address, banking, or direct deposit information you didn't make
  • New authorized representatives you don't recognize
  • Changes to your MFA or security settings
  • Sign-in attempts from unfamiliar devices or locations
  • A sudden flood of CRA emails you didn't expect (this can be a tactic called "email bombing," used to bury real notifications)

If anything looks off, don't wait. Contact the CRA right away. A strong account security habit is also one of the essential policies every Canadian charity should have in place if you manage accounts on behalf of an organization.

Set Up Multi-Factor Authentication (MFA)

MFA is mandatory for every CRA account. It asks for a one-time passcode every time you sign in, on top of your password.

As of February 2026, the CRA also requires a backup MFA method. This protects you if you lose your phone or change your number.

You can choose from:

  • A third-party authenticator app
  • A passcode grid you save or print (valid for 18 months)
  • A phone number for text or voice codes (primary method only — this doesn't count as a backup)

To set it up: sign in to your CRA account, select Security settings, then Multi-factor authentication. It takes a few minutes and can save you a lockout headache during tax season. Full setup instructions are on the CRA's MFA help page.

How to Spot a Fake CRA Message

The CRA communicates in specific, predictable ways. Scammers usually break at least one of these rules. See more examples on the CRA's own Recognize a scam page.

Real CRA Contact Scam Warning Sign
Never asks for payment by e-transfer, gift card, or crypto Demands immediate payment through these methods
Never sends refund links by text Texts a link claiming you have a refund waiting
Only sends MFA codes by text if you enrolled that way Sends unsolicited "verify your identity" links
Uses canada.ca web addresses Uses lookalike domains like cra-login-canada.com
Gives you time to verify before acting Pressures you with threats, arrest warnings, or countdowns

If you're ever unsure, don't click anything. Log in directly at canada.ca or call the CRA at 1-800-959-8281 to check your account status.

Change Your Password Regularly

Use a strong, unique password for your CRA account. Don't reuse a password from another site.

Update it every few months, and right away if you think it may have been exposed in a data breach.

A strong password combines:

  • At least 12 characters
  • A mix of upper and lower case letters, numbers, and symbols
  • No personal details like your name or birthdate

Keep Your Contact Information Current

Make sure the CRA has your correct phone number and email address on file.

This matters for two reasons:

  1. You'll actually receive MFA codes and account alerts when you need them.
  2. If someone tries to change your contact details without your permission, you'll get notified.

Turn On Email Notifications

Email notifications alert you the moment something changes on your account, like a new address, banking update, or representative.

This is one of the simplest early-warning tools available, and it's free to turn on in your account settings.

Be Careful Who You Authorize as a Representative

Only authorize someone (like an accountant or family member) if you fully trust them and know why they need access. They'll need to register for the CRA's "Represent a Client" service before you can grant them access.

Review your list of authorized representatives regularly. Remove anyone who no longer needs it

Verify Third Parties Through the Corporate Registry

If a business or organization asks to access your CRA information, verify they're legitimate first.

You can check a business's registration through your provincial or federal corporate registry before sharing any information. Weak digital security around donor or client data can also raise questions with the CRA. See What Does Your Charity Website Tell the CRA, and Why Does It Matter?

What to Do If You Think You've Been Scammed

If you clicked a link, entered information, or think your account may be compromised, act quickly:

  1. Change your CRA password immediately.
  2. Contact the CRA to flag your account for review.
  3. Report the scam to the Canadian Anti-Fraud Centre at 1-888-495-8501 or online.
  4. Check your account for unauthorized changes to your address, banking, or representatives.

Reporting matters even if you didn't lose money. It helps the CRA and police track scam patterns and warn others. A compromised account can also create downstream compliance issues — see our breakdown of top Canadian charity compliance issues the CRA watches for.

Frequently Asked Questions

Does the CRA ever call, text, or email me directly? 

The CRA may call or mail you, but it will never text you a refund link or ask for payment by e-transfer, gift card, or cryptocurrency.

Is multi-factor authentication mandatory? 

Yes. MFA is required for all CRA accounts, and a backup MFA method has been required since February 2026.

What's the CRA's official phone number to verify a message? 

1-800-959-8281 for individuals, or 1-800-959-5525 for businesses.

What should I do if I already gave out my information? 

Change your CRA password right away, contact the CRA to flag your account, and report the incident to the Canadian Anti-Fraud Centre.

The material provided on this website is for information purposes only. It is not intended to be legal advice. You should not act or abstain from acting based upon such information without first consulting a Charity Lawyer. We do not warrant the accuracy or completeness of any information on this site. E-mail contact with anyone at B.I.G. Charity Law Group Professional Corporation is not intended to create, and receipt will not constitute, a solicitor-client relationship. Solicitor client relationship will only be created after we have reviewed your case or particulars, decided to accept your case and entered into a written retainer agreement or retainer letter with you.

DOV GOLDBERG, J.D.

DOV GOLDBERG, J.D. is a lawyer at B.I.G. Charity Law Group and has dedicated his career exclusively to Charity and Not-for-Profit Law for over a decade. Dov guides charities, foundations, and non-profit organizations through every stage of the registration process, offering practical legal advice with a focus on compliance, governance, and long-term success. Known for his hands-on approach and deep knowledge of CRA requirements, Dov is committed to helping clients build strong, sustainable, and legally sound organizations.