Canadian Spy Agency Highlights Successful Cyber Operations Against Drug Traffickers, Extremists, and Ransomware Groups in the Last Year
In a revealing look at the aims of a major intelligence body, Canada’s Communications Security Establishment (CSE) has disclosed that it undertook multiple government-sanctioned cyber operations last year to combat the activities of drug traffickers, violent extremists, and a ransomware group.
The insights from the CSE’s annual report underscore the urgent national security threats confronting Canada and its partners, such as the illegal drug trade and cyber risks. The CSE is tasked with collecting foreign intelligence, protecting government networks, and addressing online threats.
Published last week, the report indicates that the CSE executed three foreign “active cyber operations” over the past year—initiatives involving cyberattacks against external threats to Canadian national security and public safety.
One highlighted operation specifically targeted foreign cybercriminals involved in the trafficking of chemicals needed for synthesizing the opioid fentanyl. The CSE monitored these brokers and carried out an operation that “disrupted and diminished their operational capabilities,” as stated in the report.
Another active effort focused on gathering signals intelligence—data collected from electronic devices and internet connections—related to an international extremist organization promoting violent ideologies and recruiting individuals, including those in Canada.
According to the report, the agency examined the group’s structure, outreach methods, and possible weaknesses to carry out an operation that “successfully undermined the group’s credibility and limited their ability to radicalize and recruit.”
Furthermore, one operation was directed at disrupting a ransomware-as-a-service model, which enables hackers to rent access to a ransomware gang’s resources for conducting extortion attempts. The CSE revealed that its signals intelligence unit detected the gang’s activities targeting Canada’s healthcare, transportation, and business sectors, culminating in a cyber operation that “rendered the group’s infrastructure inoperable,” as well as deleted significant data from the gang’s servers.
The agency also mentioned that it concurrently executed “technical disruptions” against ten major ransomware groups targeting Canada to “render parts of their infrastructure unusable.”
The report did not detail the locations of the hackers, extremists, or ransomware group, nor did it reveal the specific techniques utilized by the CSE in these operations. It is common for intelligence agencies to conduct cyber operations against threats, but public disclosures of this nature are unusual to safeguard operational methods and strategies.
U.S. Cyber Command, located in Fort Meade, Maryland, regularly conducts “hunt forward” operations, sending cyber teams to allied countries to enhance their network security and disrupt hostile cyber actions. The number of U.S.-led hunt-forward operations has surged from a handful in 2018 to more than two dozen anticipated by 2025.
Additionally, Canada’s CSE reported executing one defensive cyber operation during the year to counter a phishing campaign targeting Canadian federal institutions and other essential systems. The agency asserted it disrupted the group’s infrastructure and “reduced their capacity” to target Canadians.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


