A significant data breach has affected Interac’s 2Keys, a multi-factor authentication (MFA) software provider used by the Canadian government for verifying users accessing federal services. The breach, discovered in mid-August 2025, resulted in the theft of over 880,000 phone numbers and 85,000 email addresses linked to government accounts. The incident follows a broader trend of cybersecurity challenges facing authentication systems, including recent concerns about AI-generated voice deepfakes threatening two-factor authentication security.
The compromised data, which was stolen during a two-week period beginning August 3, 2025, consisted exclusively of contact information used for MFA verification when accessing services such as the Canada Revenue Agency (CRA), Employment and Social Development Canada (ESDC), and the Canada Border Services Agency (CBSA), which has been working to modernize its identity verification systems.
“The data accessed did not include any additional personal identifiable information or sensitive personal data. This information alone does not allow the unauthorized individual(s) to access Government of Canada accounts or other personal information,” said ESDC spokesperson Mila Roy.
The breach occurred during a routine software update by 2Keys, revealing a security vulnerability in the MFA system. The incident highlights the growing importance of secure authentication infrastructure, as the Canadian government has been moving forward with plans for a comprehensive digital ID program. While no fraudulent activity or compromised government accounts have been detected in connection with the breach, affected individuals have reported receiving spam and fraudulent messages, indicating potential attempts at phishing or scams using the stolen contact information.
The Office of the Chief Information Officer (CIO) and ESDC are actively investigating the incident in collaboration with 2Keys. The breach comes amid increasing cyber threats to government infrastructure, following a separate cyberattack on the Canadian House of Commons that occurred earlier in August 2025.
While the stolen data was limited to contact information used for verification purposes, the incident affects users of multiple federal government services that rely on 2Keys’ MFA system for secure access. The investigation remains ongoing as authorities assess the full scope and impact of the breach. The event has prompted discussions about potentially transitioning to more secure authentication methods, such as biometric-based MFA solutions that don’t rely on traditional contact information for verification.
Sources: National Post