OTHER

Canadian Spy Agency Highlights Successes in Cyber Operations Against Drug Traffickers, Extremists, and Ransomware Gangs in the Past Year

In a revealing analysis of its mission, Canada’s Communications Security Establishment (CSE) has disclosed that it undertook several government-sanctioned cyber operations last year aimed at combating drug trafficking, violent extremism, and a ransomware group.

The CSE’s annual report underscores significant national security threats confronting Canada and its allies, including challenges like the illegal drug trade and cyber risks. The agency is tasked with collecting foreign intelligence, protecting government networks, and addressing online threats.

Published last week, the report indicates that the CSE executed three foreign “active cyber operations” in the past year—endeavors that involved cyberattacks targeting external threats to Canada’s national security and public safety.

One operation specifically focused on foreign cybercriminals trafficking chemicals essential for synthesizing the opioid fentanyl. The CSE monitored these traffickers and implemented an initiative that “disrupted and diminished their operational capabilities,” as stated in the report.

Another active operation involved gathering signals intelligence—data obtained from electronic devices and online communications—concerning an international extremist group that advocates for violent ideologies and recruits individuals, including Canadians.

According to the report, the agency assessed the group’s organizational structure, outreach strategies, and potential weaknesses, leading to an operation that “successfully undermined the group’s credibility and limited their ability to radicalize and recruit.”

In addition, one initiative targeted the disruption of a ransomware-as-a-service model, which allows hackers to rent access to a ransomware gang’s tools for extortion efforts. The CSE revealed that its signals intelligence team identified the gang’s operations posing threats to Canada’s healthcare, transportation, and business sectors, resulting in a cyber operation that “rendered the group’s infrastructure inoperable” and deleted substantial data from the gang’s servers.

The agency also mentioned executing “technical disruptions” against ten major ransomware groups targeting Canada to “render parts of their infrastructure unusable.”

The report did not specify the locations of the hackers, extremists, or ransomware groups, nor did it detail the methods used by the CSE during these operations. While intelligence agencies often engage in cyber operations against threats, public disclosures of this nature are uncommon to safeguard operational methods and strategies.

U.S. Cyber Command, situated in Fort Meade, Maryland, regularly conducts “hunt forward” operations, deploying cyber teams to allied nations to enhance their network security and disrupt hostile cyber actions. The number of U.S.-led hunt-forward operations has surged from a handful in 2018 to more than two dozen anticipated by 2025.

Additionally, Canada’s CSE reported executing one defensive cyber operation during the year aimed at countering a phishing campaign targeting Canadian federal institutions and other critical systems. The agency stated it disrupted the infrastructure of the group and “reduced their capacity” to target Canadians.

When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.