OTHER

Canadian Spy Agency Highlights Annual Successes in Cyber Operations Against Drug Traffickers, Extremists, and Ransomware Groups

In a revealing assessment of its goals, Canada’s Communications Security Establishment (CSE) disclosed that it carried out multiple government-approved cyber operations last year, aimed at combatting drug trafficking, violent extremism, and a ransomware syndicate.

The CSE’s annual report underscores significant national security issues confronting Canada and its allies, including the illegal drug trade and cybersecurity threats. The agency’s responsibilities encompass foreign intelligence gathering, safeguarding government networks, and addressing online risks.

Published last week, the report notes that the CSE engaged in three foreign “active cyber operations” over the past year—initiatives that involved cyberattacks countering external threats to Canada’s national and public safety.

One operation specifically targeted international cybercriminals trafficking chemicals essential for synthesizing the opioid fentanyl. The CSE monitored these traffickers and initiated a program that “disrupted and degraded their operational capacities,” as mentioned in the report.

Another active initiative centered on collecting signals intelligence—data sourced from electronic devices and online communications—pertaining to an international extremist organization that espouses violent ideologies and recruits individuals, including Canadians.

The report indicates that the agency analyzed the group’s framework, recruitment strategies, and potential weaknesses, leading to an operation that “effectively undermined the group’s credibility and limited their ability to radicalize and recruit.”

Additionally, one endeavor aimed to disrupt a ransomware-as-a-service model, which allows hackers to rent access to a ransomware gang’s tools for extortion. The CSE revealed that its signals intelligence team identified the gang’s operations threatening Canada’s healthcare, transportation, and business sectors, resulting in a cyber operation that “rendered the group’s infrastructure nonfunctional” and eliminated significant data from the gang’s servers.

The agency also reported executing “technical disruptions” against ten prominent ransomware groups targeting Canada to “render parts of their infrastructure inoperative.”

The report, however, did not reveal the locations of the hackers, extremists, or ransomware organizations, nor did it disclose specific methods employed by the CSE during these operations. Although intelligence agencies frequently conduct cyber operations against threats, public disclosures like this are rare to safeguard operational strategies and techniques.

U.S. Cyber Command, headquartered in Fort Meade, Maryland, routinely conducts “hunt forward” operations, deploying cyber teams to allied nations to enhance their network security and counteract hostile cyber activities. The frequency of U.S.-led hunt-forward operations has increased from just a few in 2018 to over two dozen projected by 2025.

Furthermore, Canada’s CSE reported performing one defensive cyber operation throughout the year, targeting a phishing scheme aimed at Canadian federal institutions and other critical systems. The agency emphasized that it disrupted the group’s infrastructure and “curtailed their ability” to target Canadians.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.