On October 7, 2025, CSIRTAmericas, a cyber security incident-response group, relayed a claim from the hacktivist group NoName. The target was a Quebec municipality’s water treatment plant. The claim was precise: unauthorized access, and the ability to covertly control pumps, chlorine dosing, pressure settings, and the monitoring and alert systems. Canada’s Communications Security Establishment recorded the episode in its unclassified Annual Report 2025-2026, covering April 1, 2025, to March 31, 2026. The Canadian Centre for Cyber Security assessed the threat and coordinated mitigation with partners. The same report counted 3,216 cyber incidents affecting federal institutions and Canadian entities.
The report does not confirm that NoName seized the plant. It records the claim and the assessment. The Cyber Centre’s water-sector assessment says these systems now face risks they were not originally designed to withstand.
3,216 incidents, and a hole that opened weeks early
The Cyber Centre responded to 1,528 incidents at Government of Canada institutions and 1,688 at other Canadian entities. Of those 3,216 cases, the Centre itself identified 2,282, notified the organization, and provided support. The rest, 934, arrived as incident reports that then drew a response. General inquiries rose 9 percent, to 14,700.
In July 2025, Microsoft disclosed a set of zero-day vulnerabilities in on-premises SharePoint servers. The Cyber Centre coordinated the federal response. It issued alerts, provided sensor monitoring, ran forensic analysis, and published a technical assessment. Investigators found sophisticated exploitation, including novel techniques and custom in-memory payloads used to gain persistent access, move laterally, and exfiltrate sensitive data, at times beginning weeks before the public disclosure.
The Cyber Centre published 25 alerts and 995 advisories, a 25 percent increase in alerts and a 28 percent increase in advisories compared with 2023-2024. Notable alerts covered a critical vulnerability in Cisco software-defined wide area networks, issued with Five Eyes partners; hacktivists abusing internet-accessible industrial control systems in Canadian critical infrastructure; and the SharePoint case.
Sixty-seven Canadian organizations received pre-ransomware notifications after being identified as potential targets. The list cut across every level of government and across health care, energy, manufacturing, finance, and education. The National Cyber Threat Notification System sent more than 97,000 security alerts to 1,363 subscribed organizations, 97 of them new. On average, nearly 450 organizations were notified each week.
The report quotes a joint statement on malicious activity against Canadian critical infrastructure: “Malicious cyber activity targeting Canada’s critical infrastructure […] are on the rise and are a real and urgent threat. […] Any disruption to critical infrastructure is not only a threat to public health and safety, but also a threat to public confidence, the environment and the economy.”
In winter 2025, a campaign the report names Salt Typhoon emerged as a significant threat to networks worldwide. The Cyber Centre worked with the Canadian Security Intelligence Service and international partners. That collaboration produced a joint cyber security advisory with the U.S. National Security Agency and a joint cyber threat bulletin with the Federal Bureau of Investigation. The Centre says it continues to monitor the threat and to work with Canadian telecommunications providers and critical infrastructure operators.
The Cyber Centre also published an assessment of cyber threats to Canada’s water systems, with guidance for operators on preventing compromise, service disruption, or data theft.
Chief Caroline Xavier wrote, “These threats do not sleep, nor do they retreat in bad weather, nor do they take breaks on statutory holidays.”
Ten ransomware groups, and a deletion on the dark web
The CSE Act authorizes two kinds of foreign cyber operations: defensive and active. Defensive operations protect systems designated as important to the Government of Canada when other measures are not enough. Active operations disrupt foreign threats before they can harm Canada’s international affairs, defence, or security interests. These operations cannot target Canadians in Canada or around the world, nor anyone in Canada. Active operations must not interfere with the course of justice or democracy, or cause death or bodily harm. They run on a two-key system. The Minister of National Defence must approve all of them. Active operations also require the consent of the Minister of Foreign Affairs. Defensive operations require consultation with that minister.
This year the minister issued four authorizations for foreign cyber operations: three active, one defensive. They sit alongside nine authorizations submitted to the Intelligence Commissioner, all approved: one cyber security authorization for federal institutions, five for non-federal institutions, and three for foreign intelligence.
The report walks through how the mandates worked together.
In 2025, the Cyber Centre identified a phishing campaign targeting Canadian federal institutions and designated systems of importance. Foreign intelligence teams analyzed the campaign and identified the tools. That intelligence enabled a defensive cyber operation that disrupted the actor’s infrastructure and degraded its ability to keep targeting Canadians.
The same year, CSE’s signals-intelligence cybercrime team produced high-confidence reporting on a ransomware-as-a-service group responsible for more than 25 incidents against transportation, healthcare, pharmaceutical, and business sectors in Canada. Working with Five Eyes partners and law enforcement, CSE carried out an active cyber operation that rendered the group’s infrastructure inoperable and deleted a large amount of stolen data being advertised for sale on the dark web.
CSE also took concurrent action against 10 of the most significant ransomware groups causing harm to Canada and its allies. It carried out authorized technical disruptions to make parts of their infrastructure unusable, and it worked with international law enforcement to disrupt foreign cybercriminal networks.
A third case study is about fentanyl precursors. In 2025, CSE discovered that key online cybercriminals based outside Canada were brokering the purchase and sale of precursor chemicals used to fabricate synthetic opioids like fentanyl. It collected foreign intelligence on the brokers, developed options to disrupt them, and conducted authorized active cyber operations that disrupted and diminished their ability to operate. On July 10, 2025, the agency hosted Fentanyl Awareness Day in a classified setting. Canada’s Fentanyl Czar, Joint Operational Intelligence Cell stakeholders, and the Public Health Agency of Canada were in the room.
A fourth case concerns a foreign extremist group spreading violent ideology and seeking to recruit in Western countries, including Canada. After signals-intelligence teams mapped the network, CSE conducted an active cyber operation that, the report says, undermined the group’s credibility and limited its ability to radicalize and recruit.
CSE produced 3,976 foreign signals intelligence reports in the year, for 30 client departments and 3,332 individual clients. It handled 55 requests for assistance. The Communications Operational Production and Coordination Centre, the 24-hour nucleus, alerted the Cyber Centre to 121 cyber security incidents after hours and notified stakeholders of 220 significant terrorist or global incidents.
Two attributions, and 930 disclosures
CSE is a core member of the Security and Intelligence Threats to Elections Task Force, with CSIS, Global Affairs Canada, and the RCMP. Through SITE, it shared foreign intelligence on threats to the 45th General Election in 2025 and the Battle River-Crowfoot by-election. Working with partners, CSE also supported public attribution of two instances of foreign state-directed information operations on social media aimed at influencing public opinion. The report does not name the states behind those two attributions in that passage. Elsewhere it says signals intelligence helped identify and counter People’s Republic of China state-sponsored threats and supported the protection of democratic processes at the federal and provincial levels.
A national awareness campaign launched in early 2024, and continued through the 2025 federal election period, carried the line “If it raises your eyebrow, it should raise questions.” The ads were displayed over 44 million times and generated more than 250,000 visits to an online disinformation webpage.
CSE states that it does not conduct activities that target Canadians at home or around the world, or individuals located in Canada. While conducting foreign intelligence, it may incidentally acquire information related to Canadians. Canadian identifying information is removed or masked before intelligence is shared. Designated departments and agencies may request access. Each request is reviewed under the CSE Act.
In 2025, CSE received 1,032 domestic requests for Canadian identifying information and 75 international requests. It disclosed 930. It denied or cancelled 177.
Separately, the compliance team identified 186 operational compliance incidents that involved information related to Canadians, and 14 that did not. The report does not describe the incidents. It says all of them are reviewed and assessed, and that the team identifies corrective actions and trends. Seven external complaints went to the Chief. None went to the National Security and Intelligence Review Agency.
Six ministerial orders were in effect as of March 31, 2026. Three of them designate electronic information and information infrastructures of the governments of Latvia, Ukraine, and Lithuania as being of importance to the Government of Canada.
Eighty years, and 4,178 people
The report calls 2025 a turning point. Minister of National Defence David J. McGuinty writes that government investments in 2025 helped Canada achieve NATO’s 2 percent benchmark in 2025-2026 and support a path toward the Alliance’s 5 percent Defence Investment Pledge by 2035. Budget 2025, Chief Xavier writes, made “historic defence investments that reflect the trust placed in CSE’s capabilities.” The workforce reached 4,178 employees, an increase of 337, or 8.1 percent.
After a series of cyber incidents targeting northern institutions, and with the Minister of Defence’s authorization, the Cyber Centre began deploying sensors to territorial government systems in Yukon, the Northwest Territories, and Nunavut in 2024-2025. Sensors are now on systems across several provinces and all three territories, about 5 percent of the fleet. In 2025 those deployments led to roughly 150 prevention and detection reports shared with provincial and territorial partners.
CSE is 80 years old this year. Xavier writes that the core purpose has endured: analyzing threats, protecting digital infrastructure, supporting Canada’s military and security partners, and keeping Canadians safe. Much of the rest, the report says, must remain classified.
The free archive stays free. A paid membership funds the time to read reports like this one and put the record in front of readers.
Related Hansard Files Articles
Source Documents
Communications Security Establishment Canada. (2026). Annual report 2025-2026 (Catalogue No. D95-11E-PDF).







In the past I’d focus a comment on my frustration that all levels of Canadian Governments use sole-source software, especially where the sole-source is foreign. I spent years doing what I could to convince politicians and government agencies to participate in more accountable Open Source software projects, and remove those foreign dependencies and gaping governance openings for foreign interference.
However, I see little to no movement in that thinking by Canadian institutions.
****
I am wondering if there is any discussion at the Hansard/reports level of the progress of the USA to add a 6th eye to FVEY.
The origin stories and ideologies of the 5 members of the UNs WEOG (Western Europe and Other Group) that don't share a border with Western Europe are similar (Canada, Australia, New Zealand, United States, Israel), so it feels logical that FVEY (UK+CANZUS at the moment) would eventually add Israel.
I have noticed a disconnect in the general public's understanding of the origin stories and political alignment of the 5 non-Western European WEOG members, so am curious if and when these alignments will become more visible at the political level (parliament and bureaucracies).
So, what did Louise Penny know about water plant attack threat in her 2024 novel The Grey Wolf? Could there be a chance that a clever CSE agent used it to file a check?