Canada Revenue Agency (Re), 2026 OIC 48
Date: 2026-03-31
OIC file number: 5824-01584
Access request number: A-2024-181402
Summary
The complainant alleged that the Canada Revenue Agency (CRA) improperly withheld information under paragraph 16(2)(c) (facilitating the commission of an offence) of the Access to Information Act in response to an access request. The request was for a telephone list for the CRA Headquarters International and Large Business Directorate indicating name, title, group, level, telephone number of each individual and reporting relationship. The allegation falls under paragraph 30(1)(a) of the Act.
The complainant also alleged that the CRA had not conducted a reasonable search for records in response to the same access request. The allegation falls under paragraph 30(1)(a) of the Act.
During the investigation, the complainant decided it was no longer necessary for the Office of the Information Commissioner (OIC) to investigate the reasonable search allegation.
The CRA failed to demonstrate that the requirements of paragraph 16(2)(c) were met because it did not establish that there is a reasonable expectation that harm would occur if the employee phone numbers were disclosed; that is, the representations received did not provide clear and convincing evidence on the likelihood of harm occurring.
The Information Commissioner issued an initial report setting out her intention to order the CRA to disclose the phone numbers withheld under paragraph 16(2)(c). The CRA gave notice to the Commissioner that it had released the phone numbers to the complainant on March 11, 2026. The complaint is well founded.
Complaint
[1]The complainant alleged that the Canada Revenue Agency (CRA) had improperly withheld information under paragraph 16(2)(c) (facilitating the commission of an offence) of the Access to Information Act in response to an access request. The request was for a telephone list for the CRA Headquarters International and Large Business Directorate indicating name, title, group, level, telephone number of each individual and reporting relationship. The allegation falls under paragraph 30(1)(a) of the Act.
[2]The complainant also alleged that CRA had not conducted a reasonable search for records in response to the same access request. The allegation falls under paragraph 30(1)(a) of the Act.
[3]During the investigation, the complainant decided it was no longer necessary for the Office of the Information Commissioner (OIC) to investigate the reasonable search allegation.
Investigation
[4]When an institution withholds information under an exemption, it bears the burden of showing that refusing to grant access is justified.
Subsection 16(2): facilitating the commission of an offence
[5]Subsection 16(2) allows institutions to refuse to disclose information that, if disclosed, could reasonably be expected to facilitate the commission of an offence.
[6]To claim this exemption, institutions must show the following:
- Disclosing the information (for example, information on criminal methods or techniques, or technical details of weapons, as set out in paragraphs 16(2)(a) to (c)) could facilitate the commission of an offence.
- There is a reasonable expectation that this harm could occur—that is, the expectation is well beyond a mere possibility.
[7]When these requirements are met, institutions must then reasonably exercise their discretion to decide whether to disclose the information.
Does the information meet the requirements of the exemption?
[8]In response to the access request, CRA disclosed a table containing information such as employee name, division, job title, work email address, and employees’ supervisor information. CRA withheld only the column that contains employee phone numbers.
[9]The OIC raised to CRA that in the course of previous investigations conducted by the office, CRA opted to disclose the same or similar information. In response, CRA claimed that despite previous release of this type of information, circumstances have since changed due to the COVID-19 pandemic.
[10]Specifically, CRA noted that government employees now use cell phones in place of landline telephones. CRA explained there are security risks with cell phones that did not exist with landline telephones and as such, releasing the cell phone number could facilitate hacking, the interception of private communications, and would allow individuals to commit different types of offences, including phishing, risk of ID theft, fraud and harassment.
[11]CRA explained in detail how these offences could be committed referencing an attack known as Signalling System No. 7 (SS7). This type of attack can be used by hackers to listen in on phone calls, read text messages, track location in real time and bypass two-factor authentication codes sent via text.
[12]CRA provided a CBC news article to further support its assertion. This article explains that hackers can spy on a cellphone using only the phone number by gaining access to the SS7 network, posing risks such as espionage, fraud, and privacy breaches. CRA explained that the likelihood of harm is increased by the multiple phone numbers involved.
[13]For the reasons below, the OIC find that CRA has failed to demonstrate that there is a reasonable expectation this harm could occur – that is, that the expectation is well beyond a mere possibility. While CRA’s submissions support the general proposition that cellphones number may be used in committing certain offences, CRA has failed to provide clear and convincing evidence on the likelihood that harm will come to pass.
[14]First, the information provided in the article showed that the test was conducted on an unsecured phone, and not on a Government of Canada device, which are understood to be protected, and designed to be as secure as possible. As mentioned by the CBC article, encryption is one way to protect from SS7 attacks.
[15]CRA confirmed that its cell phones are protected using encryption technologies to secure data between devices and servers. Further, its employees are made aware of the security risks associated with using mobile devices, specifically those associated with passwords, WI-FI, charging, software, cameras, keyboard & word prediction, and loss or theft.
[16]Further, the Government of Canada requires that all portable devices must be password or biometric controlled, increasing the security of these devices. The Communications Security Establishment of Canada has indicated that it is actively working to reduce SS7 vulnerabilities by offering guidance, best practices, and by providing mobile security recommendations to institutions.
[17]Second, it is the OIC understanding that SS7 attacks occur by hacking into the SS7 network, rather than specific devices. The usefulness of cell phone numbers is only apparent once the would-be attacker has successfully breached the network infrastructure. Considering the withheld information does not advise whether the numbers are for cell phones or landlines, and that SS7 attacks can only be carried out via mobile devices, the OIC is further of the view that the likelihood of an individual using this phone list to facilitate an SS7 attack is unlikely.
[18]Third, these vulnerabilities have been known since 2008, yet the government has not prohibited the use of cellphones by government employees. In fact, since 2020, use of cellphones by government employees has become widespread. No evidence was presented that showed this practice has had any significant security impacts.
[19]Finally, it appears that several of the phone numbers exempted from disclosure are already publicly available. When asked about this inconsistency, CRA failed to explain why certain employees’ numbers were posted on GC Directory. Rather, CRA asserted that only a small number of the phone numbers were publicly available and that the low percentage of publicly available numbers did not justify disclosing the remaining large number of telephone numbers.
[20]Although only some of these cell phone numbers are publicly accessible, the fact that any are public at all undermines the assertion that the same type of information for different individuals must be withheld to avoid the facilitation of a commission of an offence. It also calls into question the reasonable expectation of harm as no harm has occurred as a result of the publicly available information.
[21]In light of the above, CRA has not demonstrated a reasonable expectation of probable harm within the meaning of paragraph 16(2)(c) that would directly result from the disclosure of the disputed information that is well beyond the merely possible or speculative.
[22]The OIC concludes that the information does not meet the requirements of paragraph 16(2).
Outcome
[23]The complaint is well founded.
Initial report and notice from institution
On February 24, 2026, the Information Commissioner issued her initial report to the Minister of National Revenue setting out her order to disclose the phone numbers withheld under paragraph 16(2)(c).
After the Information Commissioner issued her initial report, CRA disclosed the information at issue. Therefore, it is not necessary for the Information Commissioner to order CRA to do so.
Review by Federal Court
When an allegation in a complaint falls under paragraph 30(1)(a), (b), (c), (d), (d.1) or (e) of the Act, the complainant has the right to apply to the Federal Court for a review. The complainant must apply for this review within 35 business days after the date of this report and must serve a copy of the application for review to the relevant parties, as per section 43.