Canada’s signals intelligence agency says it carried out state-authorized hacks in 2025 against a ransomware-as-a-service gang, foreign fentanyl-chemical traffickers, and a violent extremist group. In its annual report, the Communications Security Establishment said one operation made the ransomware gang’s infrastructure inoperable and deleted stolen data being advertised on the dark web, and that it also conducted 10 additional technical disruptions against major ransomware gangs last year. The specific groups, malware, and infrastructure were not named.
Why it matters: This is a rare public acknowledgment that a government agency directly disrupted criminal cyber infrastructure rather than only warning about it. Defenders should watch for follow-on disclosures about which ransomware groups were hit, because that could affect threat tracking, infrastructure blocklists, and victim-notification efforts.
Anna Mackay
2026.07.14
93% relevant
This appears to describe one of the same underlying CSE disruption operations previously reported in broad terms, adding that one target was online foreign criminals brokering fentanyl ingredients and framing it as part of CSE’s expanded offensive cyber activity.
SecurityWeek News
2026.07.10
94% relevant
The roundup restates that Canada’s Communications Security Establishment used its foreign cyber operations authority to hack and disrupt ransomware infrastructure, adding that the operations degraded the groups’ command-and-control capabilities.
2026.07.06
100% relevant
This article establishes a distinct story about Canada publicly disclosing offensive cyber operations against ransomware and other foreign threat actors in 2025.
← Back to all stories