CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Canadian spy agency reports hacking three criminal groups in 2025

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 492

As cited

Copy frozen at (site build).

ransomware

Canadian spy agency reports hacking three criminal groups in 2025

Canada's Communications Security Establishment (CSE) conducted offensive cyber operations against three separate criminal groups in 2025, including a ransomware-as-a-service gang, an online foreign extremist group, and drug traffickers. The agency did not disclose specific details about the targets, methods, or outcomes of these operations.

Why it matters: Organizations using Canadian infrastructure and law enforcement agencies should understand that state-sponsored cyber offensive capabilities are being deployed against ransomware operators and criminal networks, which may disrupt threat actor operations but could also escalate cyber conflict.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Canadian spy agency reports hacking three criminal groups in 2025

No summary had been written when this copy was frozen.

First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

ransomware

Canadian spy agency reports hacking three criminal groups in 2025

Canada's Communications Security Establishment disclosed that in 2025 it conducted offensive operations against three distinct criminal groups. The targets included a ransomware‑as‑a‑service organization, an online foreign extremist network, and a drug trafficking syndicate.

Why it matters: Organizations linked to ransomware, extremist, or drug trafficking activities are at risk of follow‑on actions and should review their threat‑intelligence feeds and defensive controls.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary