Canada's Signals Intelligence Agency Turns Its Offensive Toolkit on Criminal Networks, Not Just State Adversaries- 277
July 7, 2026
Canada's Communications Security Establishment has disclosed that it ran three offensive cyber operations against foreign criminal and extremist networks in 2025, a rare public accounting from a Five Eyes signals intelligence agency of using its most sensitive capabilities against transnational crime rather than state adversaries — and a signal of how thoroughly the line between traditional cyber-espionage missions and domestic threat mitigation has begun to blur.
The CSE's annual report, released last week and first surfaced by TechCrunch, describes three "active cyber operations" conducted abroad against threats the agency judged to pose a risk to Canadian national security. The first targeted a foreign extremist group engaged in spreading violent ideology and recruiting new members in Western countries, including Canada itself. Using signals intelligence drawn from internet-connected devices, the agency mapped the group's organization, reach, and vulnerabilities, then executed an operation the report says "successfully undermined trust in the group" and curtailed its ability to radicalize and recruit — destroying the group's supporting infrastructure in the process. The second operation was directed at cybercriminals operating as intermediaries in the fentanyl supply chain, brokering the precursor chemicals used to manufacture the opioid; the CSE says the operation disrupted and diminished their operational capacity, without offering further detail on method or outcome. The third, and most technically detailed of the three, dismantled a ransomware-as-a-service platform whose infrastructure criminal affiliates had used to extort victims across Canada's healthcare, transportation, and business sectors. The agency used signals intelligence to map the group's internal workings before executing an operation that rendered its infrastructure inoperable and deleted a substantial volume of stolen data that had been advertised for sale on the dark web.

Beyond these three flagship operations, the report describes a wider, ongoing pattern of activity: concurrent "authorized technical disruptions" against ten of the most significant ransomware gangs targeting Canada, intended to render parts of each group's infrastructure unusable, and a separate defensive operation against a phishing campaign aimed at federal government institutions, which the agency says disrupted part of the attackers' infrastructure and reduced their capacity to target Canadians. As is standard practice for operational security, the report withholds the identities, locations, and specific methods behind every operation described — the disclosure is deliberately structured to demonstrate capability and intent without compromising tradecraft or ongoing investigations.

What makes this disclosure notable is less the operations themselves than the decision to publicize them at all. Offensive cyber operations against ransomware infrastructure, extremist networks, and narcotics-adjacent cybercriminals have increasingly become a normalized instrument of state power for Five Eyes intelligence services, but public acknowledgment of that activity — as opposed to leaks, indictments, or after-the-fact attribution by outside researchers — remains the exception rather than the rule. CSE's choice to detail these operations in its own annual report places it alongside a broader, still-emerging pattern among allied signals intelligence agencies of using public disclosure itself as a policy instrument: a way of demonstrating deterrent capability, reassuring domestic audiences that offensive cyber tools are being turned against tangible harms like fentanyl trafficking and ransomware extortion, and normalizing the idea that an agency built for foreign intelligence collection now routes a meaningful share of its offensive activity toward transnational criminal, rather than purely state, targets.
