Spy agency says it doesn’t just go after extremists’ computers. It also goes after their online reputation
CSE says it was authorized to run four active or defensive cyber operations last fiscal year, including another that targeted ransomware groups
OTTAWA — Canada’s cyberintelligence agency doesn’t just go after violent extremist group leaders’ computers and networks, it also attacks their reputation, credibility and trustworthiness to undermine them, according to a new report.
In its latest annual report published Friday, the Communications Security Establishment (CSE) offered new detail about what it does during an “active cyber operation”.
In other words, how CSE leads its minister of defence-approved campaigns meant to disrupt, influence or interfere with online threats posed by hostile actors like foreign states, organized crime or extremist groups.
The activities go well beyond the clichéd image of tech wizards in hoodies hacking into foreign threat actors’ computers and wreaking havoc on their IT systems (though that also happens).
In cases last year where CSE ran operations against violent extremist organizations, for example, the cyber-spy agency targeted the adversaries’ online presence and reputation on top of their IT infrastructure.
“Using a multi-faceted approach that targeted VEOs’ technical infrastructure and online presence, CSE conducted active cyber operations to damage the credibility and influence of key group leaders, reducing their ability to inspire and lead,” reads the report.
The operations also aimed to “weaken trust and reduce cohesion between leaders and followers, undermining the unity and strength of these organizations,” the report continues.
Asked in an interview if CSE leads online disparagement campaigns against leaders of violent extremist organizations, Cyber Centre deputy head Bridget Walshe declined to go into detail.
“It’s difficult for me to get into details about the actual techniques that are being used, because if we share those techniques, then that impacts them and the effectiveness decreases,” Walshe said.
“Violent extremism is a big one, because there is an immediate threat to Canada. So, what we’ve tried to do is highlight what the impact is” of CSE’s cyber operations, she said of the latest report.
In total, CSE says it was authorized to run four active or defensive cyber operations last fiscal year, including another that targeted the 10 biggest ransomware groups impacting Canada.
In one case late last year, the agency detected a ransomware group targeting Canadians working in a critical infrastructure sector. Within 48 hours, the report reads, CSE’s teams identified and notified victims and ran a cyber operation to disrupt the criminal group’s activity.