Canada's communications security agency said it conducted several state-sanctioned hacks last year to disrupt the activities of drug lords, violent extremists and ransomware gangs, offering a rare glimpse into the top spy organization's priorities.
Disclosures in the Canadian Intelligence Agency's annual report highlight some of the major national security threats facing Canada and its closest allies, from the importation of illegal drugs to cyber-attacks. The CSE, a spy agency, is tasked with gathering foreign intelligence, protecting government systems, and disrupting online adversaries.
A report released last week said CSE carried out three “aggressive cyber operations” overseas last year. The term refers to cyberattacks against foreign activities that threaten Canada's national security and public safety.
According to the report, one of the operations targeted cybercriminals outside Canada who were brokering the sale of chemicals used to make the synthetic opioid fentanyl. The report said the CSE collected information about brokers and conducted operations to “disrupt and degrade their ability to operate.”
Another active effort included the collection of signals intelligence (data generated from electronic and internet-connected devices) about extremist groups overseas, including in Canada, that were spreading violent ideologies and recruiting members.
The report said authorities analyzed the group's organization, scope, and potential vulnerabilities in order to carry out operations that were “successful in undermining the group's credibility and limiting its ability to radicalize and recruit new members.”
Another operation involved disrupting a ransomware-as-a-service operation where hackers could borrow access to a ransomware gang's infrastructure to launch devastating extortion attacks. CSE said its signals intelligence division determined how the gang operated against Canada's health, transportation and business sectors and subsequently conducted aggressive cyber operations that “rendered the group's infrastructure inoperable.” The operation also deleted much of the data on the gang's servers.
The agency announced it simultaneously carried out “technical disruption” of 10 of the most significant ransomware organizations targeting Canada to “disable portions of their infrastructure.”
The report does not specify the location of hackers, extremists or ransomware gangs, or details of CSE's operations targeting them. It is not uncommon for spy agencies to conduct cyberattacks against adversaries, but such operations are rarely disclosed or detailed in order to protect the methods and techniques used.
The Fort Meade, Maryland-based Cyber Command, which directs the U.S. government's cyber operations, regularly conducts “hunt-forward” operations in which it dispatches cyber teams to allies to secure networks and thwart cyber operations launched by adversaries. The number of U.S.-led Hunt Forward operations has increased from a few in 2018 to more than 20 by 2025.
Canada's CSE said it conducted one defensive cyber operation targeting phishing attacks against Canadian federal government agencies and other critical systems during the year. The agency said it had disrupted the group's infrastructure and “diminished its ability” to target Canadians.
If you buy through links in our articles, we may earn a small commission. This does not affect editorial independence.

