Canadian Spy Agency Highlights Annual Successes in Cyber Operations Against Drug Traffickers, Extremists, and Ransomware Gangs
In a straightforward assessment of its goals, Canada’s Communications Security Establishment (CSE) disclosed that it undertook multiple government-approved cyber operations last year aimed at combating drug trafficking, violent extremism, and a ransomware network.
The annual report from the CSE underscores significant national security challenges confronting Canada and its allies, including the illegal drug trade and cyber threats. The agency’s responsibilities encompass foreign intelligence collection, safeguarding government networks, and addressing online risks.
Published last week, the report reveals that the CSE carried out three foreign “active cyber operations” over the past year—initiatives aimed at countering external threats to Canada’s national and public safety through cyber actions.
One operation specifically targeted international cybercriminals involved in trafficking chemicals essential for producing the opioid fentanyl. According to the report, the CSE monitored these traffickers and implemented a program that “disrupted and degraded their operational capabilities.”
Another initiative centered on gathering signals intelligence—data from electronic devices and online communications—related to an international extremist group that advocates for violent ideologies and recruits individuals, including Canadians.
The report states that the agency explored the group’s structure, recruitment strategies, and vulnerabilities, resulting in an operation that “effectively undermined the group’s credibility and limited their capacity to radicalize and recruit.”
Moreover, one project aimed to dismantle a ransomware-as-a-service model allowing hackers to lease access to a ransomware gang’s extortion tools. The CSE’s signals intelligence team identified the gang’s operations threatening Canada’s healthcare, transportation, and business sectors, leading to a cyber operation that “rendered the group’s infrastructure nonfunctional” and deleted substantial data from the gang’s servers.
The agency also reported executing “technical disruptions” against ten major ransomware groups targeting Canada to “render parts of their infrastructure inoperative.”
Nonetheless, the report did not specify the locations of the hackers, extremists, or ransomware groups, nor did it outline the precise methods employed by the CSE in these operations. While intelligence agencies frequently execute cyber operations to mitigate threats, such public disclosures are rare due to the necessity of safeguarding operational tactics and strategies.
The U.S. Cyber Command, headquartered in Fort Meade, Maryland, regularly conducts “hunt forward” operations, deploying cyber teams to allied countries to enhance their network security and counter hostile cyber activities. The frequency of U.S.-led hunt-forward operations has surged from just a handful in 2018 to over two dozen anticipated by 2025.
Additionally, Canada’s CSE reported executing one defensive cyber operation throughout the year, aimed at a phishing campaign targeting Canadian federal institutions and other vital systems. The agency noted that it disrupted the group’s infrastructure and “curtailed their ability” to target Canadians.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


