Canada’s Communications Security Establishment (CSE) disclosed last week that it carried out three state-authorized cyberattacks in the past year, targeting drug traffickers, violent extremists, and a ransomware-as-a-service operation. The revelations, published in the intelligence agency’s annual report, offer a rare public look at how one of the Five Eyes spy agencies is actively disrupting threats to national security and public safety. The operations ranged from dismantling the digital infrastructure of a fentanyl precursor chemical brokerage to rendering a ransomware gang’s servers inoperable, underscoring the expanding role of offensive cyber capabilities in Canadian defense strategy.
Disrupting the Fentanyl Supply Chain at Its Source
One of the three foreign active cyber operations detailed in the report targeted cybercriminals operating outside Canada who were brokering the sale of chemicals used to produce the synthetic opioid fentanyl. The CSE collected signals intelligence on the brokers and then executed an operation that, according to the report, “disrupted and diminished their ability to operate.” The operation struck at a critical node in the illicit fentanyl supply chain, directly linking cyber intelligence gathering with a tangible public safety outcome.
Countering Violent Extremist Recruitment and Radicalization
Another operation focused on an overseas extremist group that was actively spreading violent ideology and recruiting members, including inside Canada. The CSE analyzed the group’s organizational structure, reach, and potential vulnerabilities before conducting an operation that “successfully undermined the group’s credibility and limited their ability to radicalize and recruit new members.” This approach signals a growing willingness among state intelligence agencies to use offensive cyber tools not just for data collection, but for active influence and disruption of adversarial messaging.
Dismantling a Ransomware-as-a-Service Operation
The third active cyber operation targeted a ransomware-as-a-service (RaaS) operation that allowed hackers to rent access to the gang’s infrastructure for launching destructive extortion attacks. The CSE’s signals intelligence unit first mapped how the gang targeted Canada’s healthcare, transportation, and business sectors. The subsequent active cyber operation “rendered the group’s infrastructure inoperable” and deleted much of the data stored on its servers. Separately, the CSE said it conducted concurrent technical disruptions against ten of the most significant ransomware gangs targeting Canada, making parts of their infrastructure unusable without full operational disclosure.
The Growing Role of Offensive Cyber Operations in National Security
While spy agencies have long conducted cyberattacks against adversaries, such operations are seldom disclosed in detail in order to protect methods and techniques. Canada’s CSE follows a pattern increasingly seen among allied nations. For comparison, U.S. Cyber Command, based at Fort Meade, Maryland, regularly conducts hunt forward operations, deploying cyber teams to allied countries to secure networks and disrupt adversary cyber activity. These operations have risen from just a handful in 2018 to more than two dozen in 2025, reflecting a broader strategic shift toward persistent, forward-leaning cyber engagement.
The CSE also reported one defensive cyber operation in the same period, targeting a phishing campaign aimed at Canadian federal government institutions and other critical systems. The agency disrupted the group’s infrastructure and degraded their ability to target Canadians.
What Organizations Should Do to Strengthen Ransomware Defenses
For organizations concerned about the ransomware threat landscape, the CSE’s disclosures serve as a reminder that ransomware-as-a-service operations remain a top-tier risk to critical infrastructure and private sector networks. To reduce the likelihood of a successful attack, organizations should implement a multi-layered endpoint protection solution that includes behavioral analysis and real-time threat detection. Maintaining offline, immutable backups and enforcing multi-factor authentication across all remote access points are essential baseline defenses. Additionally, adopting a zero-trust network architecture and conducting regular tabletop exercises tailored to ransomware scenarios can significantly improve incident response readiness. No single product or vendor can guarantee complete protection, but a defense-in-depth strategy that combines technical controls with user awareness training remains the most effective approach against the kind of targeted ransomware operations the CSE has now publicly disrupted.