← Curriculum
/E-services and digital channels
/Level 3
Locked accounts, revoked access and suspected identity theft
Draft — unverified
Access to a CRA account can stop for reasons that range from the trivial to the serious, and the whole skill in this topic is telling them apart quickly — because the response is completely different. A forgotten password is an inconvenience. An account CRA has locked as a protective measure is a signal. A taxpayer describing changes they did not make, a refund that went to an account they do not recognise, or a return filed in their name that they did not file, is reporting a crime against them, and the call needs to be handled as that rather than as a technical support call. This is the highest-stakes topic in the line and the one where the reflex to be helpful can do the most damage, because the fastest way to restore access is exactly what an attacker wants.
Draft — not verified against a CRA source.
This was drafted by a language model from general knowledge, with no source
document behind it. Treat the structure and method as a starting point, and
treat every specific — box numbers, form numbers, dollar amounts, deadlines —
as unconfirmed until you check it below.
How to work through this tutorial
This sorts a broad symptom into distinct situations:
1. Learn the reasons access stops, from routine to serious.
2. Learn to distinguish a locked account from a forgotten credential.
3. Understand why CRA locks accounts protectively, and what that implies.
4. Learn the signs that identity theft rather than a technical fault is in play.
5. Understand what happens on a suspected compromise, and the agent's part in it.
6. Understand what restoring access must not become.
7. Work through an example that presents as a lockout and is not.
8. Check your work against the common errors.
9. Verify every specific against CRA's published guidance before relying on it.
Why access stops
Sort the causes before troubleshooting any of them.
**The credential.** Forgotten user ID or password; a Sign-In Partner credential that has changed or been closed. CRA can help with the first and cannot with the second, because it did not issue it.
**The second factor.** A lost or changed phone, an authenticator app on a replaced device. The credential is fine; the second proof is unavailable.
**Repeated failed attempts.** A protective threshold, usually temporary.
**A protective lock by CRA.** CRA has at times restricted access to accounts where there was reason to believe they may have been compromised, including where credentials appeared in a breach elsewhere. This is not a fault and not a punishment, and the taxpayer has usually done nothing wrong.
**Verification still incomplete.** Registration was never finished, so there is no full access to lose.
The first question on any such call is which of these it is. Nearly all of the useful work is in that classification.
Locked is not forgotten
A taxpayer will describe every one of the causes above as "I'm locked out", so the words do not classify the call.
A forgotten credential is a recovery problem: the person is who they say they are, and something they knew has been lost. The route is CRA's recovery process, or the issuer's if CRA did not issue the credential.
A locked account is a decision: something caused access to be restricted. Restoring it means satisfying whatever produced the lock, not resetting a password. Attempting the recovery route on a locked account produces a confusing series of failures and a caller who becomes convinced the system is broken.
Establishing which one is in play early — by asking what actually happens when they try, and what message they see — saves the entire call from going the wrong way.
Protective locks and what they imply
When CRA restricts access protectively, the implication for the conversation is important: something suggested this account might not be under the sole control of its owner.
That means two things at once. The taxpayer in front of you is probably the legitimate owner and is probably being inconvenienced for their own protection. And the reason the lock exists is that the person calling might not be.
An agent has to hold both. Being sympathetic about the inconvenience is right. Skipping steps because the caller is plainly genuine is not — the whole value of a protective lock is that it does not yield to a caller who sounds legitimate, since that is what a successful attacker sounds like.
Restoring access on this path generally requires stronger verification than an ordinary call, and it should. The agent's job is to explain why that is happening in a way that does not sound like an accusation, because it is not one.
The signals that this is identity theft
Certain reports change the nature of the call immediately, and they are worth knowing as a list because they arrive disguised as ordinary complaints:
- Personal information on the account changed without the taxpayer doing it — address, direct deposit details, marital status.
- A refund or benefit paid to an account the taxpayer does not recognise.
- A return filed in their name that they did not file, or an assessment for income they never earned.
- Correspondence about a benefit application they never made.
- A multi-factor passcode arriving unrequested.
- Being told an account already exists when they try to register for the first time.
- Being unable to file electronically because a return for that year has already been filed.
Any of these is a report of possible identity theft. The taxpayer will rarely use that phrase; they will say a payment is missing or the website is wrong.
What matters is that the call is routed onto CRA's process for suspected unauthorised access, and that it is not quietly closed by fixing the surface symptom.
What restoring access must not become
There is a version of helpfulness that hands an account to an attacker, and it is worth naming precisely because it feels like good service.
It looks like: relaxing verification because the caller is upset; accepting information the caller has supplied as corroboration of itself; changing the contact details or deposit information on an account before the caller's entitlement to it is established; confirming what is on the account in the course of "checking" it.
That last one deserves emphasis. Reading out the address or the deposit details currently on file, to ask whether they are right, tells an unverified caller what the account says. On a compromised account, it tells the attacker what to imitate.
The rule holds without exception, and it holds hardest on exactly the calls where it is most uncomfortable. If verification cannot be completed, access is not restored on that call, and nothing is disclosed on the way to not restoring it.
A worked example: a lockout that was not a lockout
Teaching example. The figures below are invented to show the
method. They are not CRA figures, and no amount here should be used for a
real taxpayer.
The details in this example are invented for teaching. Nothing here should be quoted as CRA's position or as a script.
Suppose Bernard calls in the spring, annoyed. He has tried to file his return and the transmission was rejected. He then tried to sign in to check something and could not. He describes all of it as being locked out of his account, and he wants his password reset.
The reset is the wrong thing to reach for, and it is the thing he is asking for.
Two details reframe the call. The transmission was rejected on the basis that a return for that year had already been filed. And when he last successfully signed in, some weeks ago, he recalls that his address looked wrong and he assumed it was a display error.
A return already filed, plus account details he did not change, is not a technical fault. It is the signature of someone else having used his identity — and, suppose, having directed a refund to an account that is not his.
Resetting his password would restore his access and do nothing about any of that. Worse, if the person on the phone were the attacker rather than Bernard, the reset is precisely the outcome they called for.
So the call runs on the suspected-compromise path: full verification, the report handled through CRA's process for unauthorised access, and no changes made to the account until entitlement is established.
The lesson: the caller's description of the problem is not the classification of the problem. Bernard's account of events was accurate and his diagnosis was wrong.
Common errors
Taking "I'm locked out" as a classification. It describes five different situations with five different answers.
Running credential recovery on an account that is under a protective lock.
Treating a protective lock as a fault to apologise for rather than as a control doing its job.
Relaxing verification because the caller is distressed. That is the condition the control exists for.
Reading current account details back to an unverified caller to "confirm" them. That is a disclosure, and on a compromised account it is a gift.
Changing contact or deposit details before entitlement is established.
Fixing the presenting symptom — a rejected filing, a missing refund — without recognising the pattern behind it.
Treating an unrequested passcode, or a return already filed, as an oddity rather than as a signal.
Telling a taxpayer that a suspected compromise is resolved. That is not something to promise on a call.
Quoting CRA's identity-theft process from memory rather than following the current published and operational guidance.
What to verify this tutorial against
This was drafted without a source document. Much of the actual procedure here is operational rather than public, which limits what this tutorial can properly say — see the note at the end.
CRA's guidance on protecting yourself against identity theft, and on what to do if you suspect your CRA account has been compromised, is the primary public reference and the thing to point a taxpayer at.
CRA's pages on sign-in problems and account recovery cover the credential and multi-factor recovery routes, including the point that CRA cannot recover a credential it did not issue.
CRA's published statements about restricting access to accounts as a precaution are the reference for the protective-lock section. Confirm the current position; this has changed as CRA's practice has developed.
CRA's guidance on reporting a scam or suspected fraud covers the reporting routes available to a taxpayer.
The Canadian Anti-Fraud Centre is the external reference CRA points taxpayers to for identity theft more broadly. Confirm what CRA currently recommends before directing anyone.
Note for the reviewer: the steps an agent actually follows on a suspected compromise are internal operational guidance and are deliberately absent here. Do not add them — DEC-001 confines this platform to public sources. What this tutorial can teach is recognition and the principles, and it should stay at that level.
Your progress
This is your own record of what you have worked through. It says nothing
about whether the content has been verified.
Quiz not attempted.
4 questions available —
marking this complete does not require taking it, but the quiz is the only
thing here that distinguishes having read the page from having learned it.
Take the quiz
Claims to confirm
These are the checkable specifics from this tutorial — the details most
likely to be wrong in a drafted page. Confirm each against CRA guidance.
0 of 10 confirmed.
-
other
CRA cannot reset or recover a Sign-In Partner credential, because it is issued by the financial institution rather than by CRA.
-
other
Repeated failed sign-in attempts can cause CRA to restrict access to an account temporarily.
-
other
CRA has restricted access to online accounts as a precaution where it had reason to believe the accounts may have been compromised.
-
other
A protective restriction placed on a CRA account is not resolved by resetting the account password.
-
other
Being unable to file electronically because a return has already been filed for that year and taxpayer is a possible indicator of identity theft.
-
other
A change to an account's address or direct deposit information that the taxpayer did not make is a possible indicator of unauthorised access.
-
other
Receiving a multi-factor authentication passcode that was not requested is a possible indicator that another party holds the account credentials.
-
other
CRA publishes guidance on what a taxpayer should do if they suspect their CRA account has been accessed without authorisation.
-
other
CRA directs taxpayers to the Canadian Anti-Fraud Centre in connection with identity theft and fraud reporting.
-
other
Restoring access to an account restricted for security reasons requires verification beyond that used for an ordinary enquiry.
Verify this tutorial
10 claim(s) still unconfirmed. Confirm them
above first — verifying the page while its specifics are outstanding would
defeat the purpose of listing them.