Canadian Spy Agency Highlights Cyber Operations Successes Against Drug Traffickers, Extremists, and Ransomware Groups in the Last Year
In a revealing review of its goals, Canada’s Communications Security Establishment (CSE) disclosed that it conducted several government-authorized cyber operations last year, focusing on combating drug trafficking, violent extremism, and a ransomware group.
The CSE’s annual report emphasizes significant national security challenges confronting Canada and its allies, including the illegal drug trade and cybersecurity threats. The agency is tasked with collecting foreign intelligence, protecting government networks, and mitigating online risks.
Published last week, the report notes that the CSE carried out three foreign “active cyber operations” in the previous year—initiatives that entailed cyberattacks targeting external threats to Canada’s national security and public safety.
One operation specifically targeted foreign cybercriminals implicated in trafficking chemicals essential for producing the opioid fentanyl. The CSE monitored these traffickers and launched a program that “disrupted and diminished their operational capabilities,” as detailed in the report.
Another active operation concentrated on collecting signals intelligence—data acquired from electronic devices and online communications—pertaining to an international extremist group promoting violent ideologies and recruiting individuals, including Canadians.
The report indicates that the agency assessed the group’s structure, recruitment strategies, and possible vulnerabilities, resulting in an operation that “effectively undermined the group’s credibility and restricted their capacity to radicalize and recruit.”
Furthermore, one initiative aimed at disrupting a ransomware-as-a-service model, which allows hackers to lease access to a ransomware gang’s tools for extortion. The CSE revealed that its signals intelligence team pinpointed the gang’s operations menacing Canada’s healthcare, transportation, and business sectors, culminating in a cyber operation that “rendered the group’s infrastructure nonfunctional” and deleted substantial data from the gang’s servers.
The agency also reported executing “technical disruptions” against ten notable ransomware groups targeting Canada to “render parts of their infrastructure inoperative.”
The report did not disclose the locations of the hackers, extremists, or ransomware groups, nor did it provide details on the methods used by the CSE during these operations. Although intelligence agencies routinely undertake cyber operations against threats, public announcements like these are rare to safeguard operational tactics and strategies.
U.S. Cyber Command, located in Fort Meade, Maryland, frequently conducts “hunt forward” operations, deploying cyber teams to allied nations to enhance their network security and counter hostile cyber activities. The frequency of U.S.-led hunt-forward operations has surged from just a few in 2018 to over two dozen expected by 2025.
Additionally, Canada’s CSE reported conducting one defensive cyber operation throughout the year aimed at countering a phishing campaign directed at Canadian federal institutions and other critical systems. The agency noted that it disrupted the group’s infrastructure and “curtailed their capacity” to target Canadians.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


