Canadian Spy Agency Announces Successful Cyber Operations Against Drug Traffickers, Extremists, and Ransomware Groups in the Past Year
In a rare glimpse into the goals of a prominent intelligence agency, Canada’s Communications Security Establishment (CSE) has disclosed that it carried out various government-authorized cyber operations last year to combat the activities of drug traffickers, violent extremists, and a ransomware organization.
The insights from the CSE’s annual report emphasize the urgent national security issues confronting Canada and its allies, which include illegal drug trafficking and cyber threats. The CSE’s responsibilities encompass collecting foreign intelligence, protecting government networks, and addressing online dangers.
Published last week, the report indicates that the CSE engaged in three foreign “active cyber operations” over the last year—these operations involve cyberattacks on external entities that threaten Canadian national security and public safety.
One operation highlighted in the report specifically targeted foreign cybercriminals involved in the distribution of chemicals required for synthetic opioid fentanyl production. The CSE monitored these brokers and executed an operation that “disrupted and diminished their operational capabilities,” as stated in the report.
Another active operation concentrated on collecting signals intelligence—information gathered from electronic devices and internet connections—focused on an international extremist group spreading violent ideologies and recruiting members, including individuals within Canada.
According to the report, the agency evaluated the group’s structure, outreach efforts, and possible weaknesses to carry out an operation that “successfully undermined the group’s credibility and restricted their capacity to radicalize and recruit new members.”
Furthermore, one operation sought to disrupt a ransomware-as-a-service model, which enables hackers to rent access to a ransomware gang’s resources for executing malicious extortion attempts. The CSE disclosed that its signals intelligence unit identified the gang’s activities targeting Canada’s healthcare, transportation, and business sectors, leading to a cyber operation that “rendered the group’s infrastructure inoperable,” along with deleting substantial amounts of data from the gang’s servers.
The agency also noted that it concurrently executed “technical disruptions” against ten major ransomware groups targeting Canada to “render parts of their infrastructure unusable.”
The report did not specify the locations of the hackers, extremists, or the ransomware group, nor did it detail the specific methods utilized by the CSE in these operations. While it’s common for intelligence agencies to conduct cyber operations against threats, public disclosures of this nature are infrequent to safeguard operational tactics and strategies.
The U.S. Cyber Command, based in Fort Meade, Maryland, regularly conducts “hunt forward” operations, deploying cyber teams to allied nations to secure their networks and disrupt hostile cyber activities. The number of U.S.-led hunt-forward operations has grown from a few in 2018 to over two dozen anticipated by 2025.
Additionally, Canada’s CSE reported executing one defensive cyber operation during the year aimed at mitigating a phishing campaign that targeted Canadian federal institutions and other critical systems. The agency asserted it disrupted the group’s infrastructure and “reduced their capacity” to target Canadians.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


