Canada’s Communications Security Establishment (CSE) executed a series of state-authorised cyberattacks last year targeting foreign drug traffickers, violent extremists, and a ransomware syndicate to protect national security.
Details revealed in the Canadian intelligence agency’s annual report highlight the critical national security threats confronting Canada and its allies, spanning from illicit drug importation to sophisticated cyberattacks. The CSE is mandated to gather foreign intelligence, safeguard government networks, and actively disrupt hostile online actors.
According to the document published last week, the CSE conducted three overseas “active cyber operations” during the past year. This term denotes offensive cyber strikes launched against foreign entities deemed threats to Canadian public safety and national security.
Targeting the Fentanyl Supply Chain
The first of these operations targeted foreign cybercriminals brokering precursor chemicals used in manufacturing the synthetic opioid fentanyl. After gathering intelligence on the brokers, the CSE launched a targeted cyber offensive that successfully disrupted and diminished their operational capabilities.
Neutralising Extremist Propaganda
A second offensive targeted an overseas extremist organisation utilising digital platforms to spread violent ideology and recruit members, including individuals within Canada.
By collecting and analysing signals intelligence—data harvested from electronic and internet-connected devices—the CSE mapped the group’s organisational structure, reach, and vulnerabilities. The subsequent operation successfully undermined the group’s credibility and restricted its capacity to radicalise and recruit.
Dismantling Ransomware Infrastructure
The third operation dismantled a dangerous ransomware-as-a-service (RaaS) network, which allowed affiliate hackers to rent infrastructure to launch devastating extortion attacks. The CSE’s signals intelligence unit mapped the gang’s activities targeting critical Canadian infrastructure, including healthcare, transport, and commercial sectors.
The agency then executed a cyber strike that rendered the group’s infrastructure completely inoperable and wiped substantial amounts of data from their servers. Alongside this, the CSE initiated concurrent technical disruptions against 10 of the most prominent ransomware syndicates threatening Canada, disabling key parts of their networks.
The Covert Nature of Global Cyber Warfare
While the report omits the geographical locations of these targets and the exact technical methods deployed, such confidentiality is standard practice to safeguard intelligence sources and operational techniques. Offensive cyber operations of this nature are commonplace among global spy agencies but rarely publicised.
For comparison, the US Cyber Command, based in Fort Meade, Maryland, regularly deploys “hunt forward” teams to allied nations to secure networks and disrupt adversary infrastructure. These American-led operations have surged from a small handful in 2018 to more than two dozen in 2025.
Defending the Canadian State
Alongside offensive strikes, the CSE executed a defensive cyber operation to neutralise a sophisticated phishing campaign targeting federal government institutions and critical systems. The agency successfully dismantled the attackers’ infrastructure, significantly degrading their capacity to target Canadian citizens and public assets.
