Canada's spy agency reports hacking three criminal networks
Communications Security Establishment disclosed offensive cyber operations against ransomware operators, foreign extremists, and narcotics traffickers in 2025.
Canada's Communications Security Establishment confirmed it conducted three separate offensive cyber operations in 2025, targeting a ransomware-as-a-service gang, an online foreign extremist group, and drug trafficking networks.
The disclosure marks a rare public acknowledgment of active offensive cyber capabilities by the CSE, which operates under legal authorities permitting disruption of foreign threats. The agency did not identify specific groups by name or detail the technical methods employed. The operations represent a continuation of Canada's posture shift toward more assertive cyber activity against transnational criminal enterprises.
Ransomware-as-a-service platforms enable affiliates to deploy extortion malware without developing their own tools, lowering barriers to entry for criminal actors. The CSE's targeting of such infrastructure suggests an attempt to disrupt the supply chain of ransomware attacks rather than individual incidents. Foreign extremist groups operating online have long posed challenges for Western intelligence services balancing disruption with intelligence collection. Drug trafficking organizations increasingly rely on digital infrastructure for coordination and financial transactions, making them vulnerable to cyber operations.
- 01Ransomware operators face increased risk from state-sponsored disruption beyond law enforcement takedowns
- 02Criminal infrastructure providers may relocate operations or harden defenses against Western intelligence services
- 03Organizations in Canada and allied nations may see reduced ransomware activity if disruption proves effective
- 04Intelligence services worldwide may increase transparency around offensive cyber operations as deterrence strategy
Boston Scientific confirms cyberattack disrupting medical device shipments
The Massachusetts-based medical device manufacturer disclosed the incident in SEC filings Tuesday, warning of operational impact to its supply chain.
US sanctions Iranian nationals after UK power plant intrusion
Treasury action follows disclosure of cyber operation targeting British energy facility, marking coordinated transatlantic response to infrastructure threats.
Supply-chain attack embeds proxy botnet in Android car head units
Legitimate device-update app compromised to spread malware that turns in-vehicle systems into proxy nodes and ad-fraud platforms.