Inside Canada’s CSE Annual Report: What a Foreign Intelligence Agency’s Numbers Tell Us About the Global Ransomware Problem

Contents

3,200+ incidents, ten ransomware groups actively disrupted, and a state agency openly reporting that it “rendered infrastructure inoperable.” Canada’s Communications Security Establishment has published a rare, unusually candid look at what defending a G7 economy against cybercrime actually involves — with lessons that travel well beyond Canada’s borders.

Most annual reports from intelligence agencies say very little. Canada’s Communications Security Establishment (CSE) has, in its 2025-2026 Annual Report, said more than most — disclosing not just the scale of the threats it tracked but the specifics of operations it ran to disrupt them, including one against a ransomware-as-a-service group linked to more than 25 attacks on Canadian transportation, healthcare, pharmaceutical, and business targets. For anyone advising organisations on cyber risk, the report is worth reading closely, not because Canada’s threat landscape is identical to India’s or any other jurisdiction’s, but because the patterns it documents — AI-accelerated ransomware, critical-infrastructure targeting, and Cybercrime-as-a-Service — are patterns every connected economy is now living with.

Report at a Glance

Issuing bodyCommunications Security Establishment Canada (CSE), including the Canadian Centre for Cyber Security
Reporting periodApril 2025 to March 2026
Incidents handledMore than 3,200 cyber security incidents affecting federal institutions and critical infrastructure
Alerts & advisories issued25 alerts, 995 advisories, and over 97,000 National Cyber Threat Notification System alerts to 1,363 subscribed organisations
Ransomware actionDirect action taken against 10 of the most significant ransomware groups targeting Canada and its allies
Supply chain reviews1,772 supply chain risk assessments conducted to strengthen government cyber resilience
Foreign intelligence output3,976 foreign intelligence reports produced for the Government of Canada

The Operation That Stands Out

Most of the report reads as expected — statistics, advisories, partnership language. One disclosure breaks that pattern. CSE describes identifying, through its signals intelligence cybercrime team, a “notorious Ransomware-as-a-Service” group responsible for more than 25 incidents against Canadian transportation, healthcare, pharmaceutical, and business sector targets. Working with Five Eyes intelligence partners and law enforcement, CSE says it carried out an active cyber operation that rendered the group’s infrastructure inoperable and deleted a significant volume of stolen data that was being advertised for sale on the dark web.

This is a meaningfully different posture from most national cyber agencies, which typically confine public reporting to defensive advisories rather than confirming offensive disruption operations against named categories of criminal infrastructure. It reflects a broader shift, visible across the Five Eyes alliance over the past two years, toward treating ransomware groups as targets for direct technical disruption rather than purely a law-enforcement or private-sector defence problem.

Threat actors are using more advanced tools and techniques, increasing the scale and impact of attacks — and are leveraging new technologies, like artificial intelligence and cryptocurrency, to develop new extortion tactics.— CSE, Ransomware Threat Outlook 2025–2027

Six Judgments Worth Reading Outside Canada

Alongside the Annual Report, CSE’s National Cyber Threat Assessment 2025-2026 sets out key judgments about the threat landscape. Several of these translate directly to any jurisdiction assessing its own cyber exposure, India included.

Ransomware-as-a-Service

CSE assesses that the Cybercrime-as-a-Service business model is a primary driver of ransomware’s resilience globally — pre-built tools and infrastructure are now rented out to affiliates, lowering the technical barrier to launching an attack and making ransomware accessible to less sophisticated actors everywhere, not just in Canada.

Critical Infrastructure Is the Priority Target

Ransomware is described as the top cybercrime threat facing critical infrastructure specifically, because such organisations are perceived as more likely to pay quickly to avoid service disruption — a calculus that holds regardless of which country’s power grid, hospital network, or water system is involved.

AI Is Accelerating Both Sides

CSE’s assessment is explicit that AI is making cybercrime “cheaper and faster to conduct and harder to detect” — a trend with no jurisdictional boundary, and one that should inform how any organisation prioritises detection investment over the next two years.

Basic Hygiene Still Works

Despite the sophistication of modern attacks, CSE’s own findings point back to fundamentals — regular software updates, multi-factor authentication, and vigilance against suspicious activity remain, in the agency’s own words, “the most effective defences” available to any organisation.

Pre-Ransomware Notification: A Model Worth Studying

One of the more exportable ideas in CSE’s approach is its pre-ransomware notification programme — a system that warns organisations during the initial-access stage of an attack, before encryption or data theft occurs, based on threat intelligence about known malware and infrastructure. CSE’s data suggests these early warnings may have averted between 74 and 148 ransomware incidents in a single year, with estimated economic savings running into the tens of millions of dollars — figures that likely understate the real benefit, since they exclude reputational damage, downtime, and legal costs that ransomware incidents typically also generate. For jurisdictions building out national cyber security architecture, this early-warning model — built on threat intelligence sharing between a national agency and private-sector defenders — is arguably more replicable than large-scale offensive disruption operations, which require intelligence and legal authorities most countries’ agencies do not possess.

Why This Matters Beyond Canada’s Borders

Three things in this report are directly relevant to organisations and counsel operating outside Canada. First, the ransomware group CSE disrupted was targeting sectors — healthcare, pharmaceuticals, transportation — that are equally high-value targets everywhere, and Ransomware-as-a-Service groups typically operate across multiple countries simultaneously rather than confining themselves to one jurisdiction. An affiliate network disrupted in Canada may simply redirect its next campaign toward targets in India, Southeast Asia, or elsewhere. Second, the report’s emphasis on AI-accelerated attacks and supply-chain risk assessment (1,772 conducted in a single year) reflects a shift that Indian regulators and the CERT-In framework are tracking in parallel — supply chain compromise is increasingly the entry point of choice for ransomware actors globally, not an isolated Western concern. Third, the report’s own numbers on the gap between subscribed and eligible organisations for its threat notification system (1,363 subscribers, though the service is open to any Canadian organisation) is a reminder that even well-resourced national cyber programmes struggle with the same adoption problem India faces with CERT-In advisories and sector-specific notification systems — the tools exist, but uptake among eligible organisations remains incomplete.

Advisory — What Organisations Should Take From This Report

  • 01Treat ransomware as a governance issue, not just an IT issue. Board-level oversight of ransomware readiness, incident response plans, and cyber insurance coverage should be standard practice, not a reaction to an incident already in progress.
  • 02Subscribe to available threat notification systems. Whether it is CERT-In’s advisories in India or an equivalent elsewhere, the evidence from Canada’s own low subscription numbers shows that free early-warning tools go underused — enrolling is a low-cost, high-value step most organisations skip.
  • 03Prioritise the fundamentals CSE itself points to. Multi-factor authentication and consistent patching remain, by the agency’s own assessment, more protective than most advanced tooling purchased after the fact.
  • 04Map supply chain exposure. With supply chain compromise increasingly the preferred entry point for ransomware actors, vendor and third-party risk assessments deserve the same rigour as internal network security.
  • 05Build the legal response plan before the incident, not during it. Ransomware readiness should include pre-identified counsel, a defined chain of communication with regulators, and clarity on reporting obligations — decisions made calmly in advance are markedly better than decisions made under active extortion pressure.

If your organisation is assessing ransomware readiness or has faced a cyber extortion incident, having a legal response plan in place before an attack — covering regulatory notification, negotiation posture, and evidence preservation — materially changes the outcome. Reach out for a confidential review of your organisation’s cyber incident preparedness.

Picture of Adarsh Singhal & Associates
Adarsh Singhal & Associates

Leave a Reply

Your email address will not be published. Required fields are marked *