Canadian Spy Agency Unveils Successful Cyber Operations Targeting Drug Traffickers, Extremists, and Ransomware Gangs in the Past Year
Offering a rare glimpse into the aims of a prominent intelligence agency, Canada’s Communications Security Establishment (CSE) has disclosed that it carried out multiple government-authorized cyber operations last year to counteract the actions of drug traffickers, violent extremists, and a ransomware organization.
The insights presented in the CSE’s annual report emphasize significant national security dilemmas that Canada and its allies face, ranging from illegal drug distribution to cyber threats. The CSE’s responsibilities include collecting foreign intelligence, protecting government networks, and combating online dangers.
Published last week, the report notes that the CSE executed three foreign “active cyber operations” in the previous year—these refer to their cyberattacks targeting external entities that endanger Canadian national security and public safety.
One operation cited in the report focused on cybercriminals abroad involved in the distribution of chemicals essential for manufacturing the synthetic opioid fentanyl. The CSE tracked the brokers and then carried out an operation that “disrupted and reduced their operational capabilities,” as stated in the report.
Another active operation aimed at gathering signals intelligence—information garnered from electronic devices and internet connections—targeted an international extremist organization spreading violent ideologies and recruiting members, including within Canada.
The report indicates that the agency analyzed the group’s framework, outreach efforts, and potential vulnerabilities to conduct an operation that “successfully damaged the group’s credibility and limited their capacity to radicalize and recruit new individuals.”
Additionally, one operation sought to disrupt a ransomware-as-a-service framework, enabling hackers to rent access to a ransomware gang’s resources for executing harmful extortion attempts. The CSE disclosed that its signals intelligence unit pinpointed the gang’s activities against Canada’s healthcare, transportation, and business sectors, launching an active cyber operation that “rendered the group’s infrastructure non-functional,” along with erasing substantial volumes of data from the gang’s servers.
The agency also noted that it simultaneously performed “technical disruptions” against ten major ransomware gangs targeting Canada to “render sections of their infrastructure unusable.”
The report did not disclose the geographical locations of the hackers, extremists, or the ransomware group, nor did it elaborate on the specific techniques the CSE utilized in these initiatives. While it is common for intelligence organizations to conduct cyber operations against their adversaries, such public disclosures are uncommon in order to preserve the strategies and methods used.
The U.S. Cyber Command, based in Fort Meade, Maryland, routinely engages in “hunt forward” operations, where cyber teams are deployed to allied nations to secure their networks and disrupt hostile cyber activities. The frequency of U.S.-led hunt-forward operations surged from a handful in 2018 to over two dozen by 2025.
Furthermore, Canada’s CSE reported executing one defensive cyber operation throughout the year aimed at thwarting a phishing campaign targeting Canadian federal institutions and other critical systems. The agency asserted it disrupted the group’s infrastructure and “diminished their capacity” to target Canadians.
When you purchase through links in our articles, we may earn a small commission. This doesn’t affect our editorial independence.


