The Decibel - The Canadian spy agency you may not have heard of

Episode Date: July 6, 2026

A recent report from the Communications Security Establishment, Canada’s electronic eavesdropping agency, revealed it conducted cyberattacks to disrupt the online fentanyl supply chain. The report a...lso detailed the agency’s growth; its budget will surpass $2-billion in 2026–27, up from just over $1-billion in 2024–25. The organization is one of the two main spy agencies in Canada and yet it remains relatively unknown to the general public. Steven Chase, the Globe’s senior parliamentary reporter, joins the show to explain what exactly the CSE does and how it fits into Canada’s security landscape. Questions? Comments? Ideas? Email us at thedecibel@globeandmail.com Hosted by Simplecast, an AdsWizz company. See pcm.adswizz.com for information about our collection and use of personal data for advertising.

Transcript
Discussion (0)
Starting point is 00:00:02 Canada has two main spy agencies, the Canadian Security and Intelligence Service, or CIS, which is well known to the public, and the lesser known communications security establishment, or the CSE. The CSE plays a crucial role in trying to fight cybersecurity threats. And a new report, which came out at the end of June, gives us insight into how the agency is expanding, the threats they're focusing on, and how they conducted cyber security threats. attacks to disrupt online foreign criminals involved in the fentanyl trade. Today, Stephen Chase is on the show. He's the Globe's senior parliamentary reporter, and he's here to explain the role this agency plays in Canada's security landscape. I'm Cheryl Sutherland, and this is the decibel from the Globe and Mail. Hi, Steve, thanks so much for coming back on the show.
Starting point is 00:01:02 Glad to be here. So to start, can you just give us a brief overview of what exactly the the communication, security establishment, or CSC is? Sure, it has a number of mandates, but really it calls itself the National Cryptologic Agency. And in plain language, that means the science of making and breaking codes. So this is a organization that eavesdrops around the world and collects data and conversations and transmissions.
Starting point is 00:01:38 to help Canada and its allies. Its motto actually, in Latin, it says providing and protecting information. I much prefer the Australian Signals Directorate's motto. The Australian Signals Directorate is the Australian equivalent of the communication security establishment. Their motto is, reveal their secrets and protect our own. That's way more flashy. And that really gets to the heart of it.
Starting point is 00:02:04 the CSC eavesdrops and spies around the world, and then it protects Canadian government computer infrastructure and critical infrastructure from hacking. There are a lot more parts to its mandate, but that's the basic role. Something you mentioned there that I think is important. You said it spies around the world. So does that mean it spies around the world,
Starting point is 00:02:27 but not within Canada? The one hard limit is that CSC cannot target Canadians or persons in Canada. So beyond that, its reach around the world is broad. It can spy on people, but it can't spy on Canadians or people in Canada. There is an a asterisk to that. One of its many mandates is to assist agencies and government departments in Canada by lending its tools to them.
Starting point is 00:02:56 So in those circumstances, it could conduct operations in Canada but these sort of operations would have to be approved by a judge's warrant. So generally, it's got free reign around the world in Canada. It's not allowed to spy in Canada. It's not allowed to collect information on people, on Canadians or people in Canada. Okay, with an asterisk there. Yeah. Okay, so that gives us a sense of what the CSC is.
Starting point is 00:03:25 But how important is the CSC to Canada's security infrastructure? It's one of Canada's two main spy agents. agencies and its mandate to protect the Canadian government, to protect Canadian government computers and data from hacking makes it paramount. There's nothing more important than protecting our secrets. And so this, of course, has also evolved to protecting critical infrastructure in Canada and actually undertaking disruptive operations abroad. So judging by its budget growth and its growth in staff, it is one of the most important security agencies in Canada. And we'll get into some of the details about the budget growth and the growth and staff
Starting point is 00:04:09 in a bit there, Steve. And what I'm curious about is that given that it plays such an important role here, why haven't we heard as much about the CSC when we've heard so much about CIS? Well, I think we've heard a lot about CIS in recent years because of reporting about leaks from CESIS about Chinese foreign interference. But on the other hand, CIS was also born out of scandal. Back in the 70s, there was an inquiry that the McDonald Commission, which had uncovered evidence that the RCMP Security Service had committed criminal acts in the name of fighting
Starting point is 00:04:50 Quebec separatism, you know, burning a barn to disrupt a meeting between the FLQ and the Black Panthers, stealing dynamites, spying on citizens. This scandal over the behavior of the R. CMP Security Service led to the creation of CIS in the 80s. And so I think Canadians have a far more recent understanding of how CESA came into being. The CISC goes back to 1946. And it's been essentially in the shadows for much more than half of the years since. Okay. So, 1946, that makes the CSC 80 years old, how did they start? What was their function? During the Second World War, we had a unit dedicated to breaking enemy codes and decrypting them. After the war, it turned into something called the Communications Branch of the National Research Council.
Starting point is 00:05:47 And that was its name until the 70s. Its job was intercepting signals and breaking them. For decades, it operated with essentially no public profile, doing foreign intelligence gathering and then adding the role of protecting government computer systems. I'd say that the Snowden leaks in 2013, that of the leaks of intelligence data by Edward Snowden in 2013, marked a turning point. Because at that point, we started to learn about things that CSE was doing that were controversial, and it was forced to explain itself.
Starting point is 00:06:20 Can you remind us of what the Stone and Leaks revealed about the CSE? CSC? Yeah. One of the things that we learned was that the CSC had used information from the free internet service at major Canadian airport to track the wireless devices of thousands of airline passengers for days after they left the terminal. And when travelers pass through the airport and their phones or laptops connected to free Wi-Fi, the system captured their devices unique identifiers. And then CSC was able to track these as they appeared in other wireless networks. across Canada and the U.S. for a week or more after they left the airport. How did that go down when that was revealed?
Starting point is 00:07:01 Well, C&C's defense was that it was collecting what it was called metadata, like the information about your phone, where it was connecting and so on, not the actual content of the communications. Now, critics had argued this was a distinction without a difference, that tracking thousands of people's movement across the country with any suspicion of wrongdoing, without any warrant, was plainly what the law was designed for vent. So the CSE has been around for a long time.
Starting point is 00:07:28 How has the organization grown and how has their mandate grown? Well, here's some numbers. The budget for the CSE will surpass 2 billion in this current fiscal year. That's up from just $1 billion in 24, 25, so just a few years ago. Its budget has doubled. And its workforce, which is about 4,200 people across, according to a recent count, is doubled what it was more than 10 years ago. It has become a priority for government funding.
Starting point is 00:07:59 They've sort of added responsibilities to a mandate over the years. First, it was code breaking and code making. Then it was protecting government computer systems. And then it was assisting other governments and agencies when needed. But in 2019, they added two types of foreign cyber operations. These are what are called defensive cyber operations and active cyber operations. Active is kind of a euphemism. It really should be offensive cyber operations.
Starting point is 00:08:30 So in both cases, they involve taking action in cyberspace to disrupt foreign-based threats to Canada. Now, active cyber operations are what really should be called offensive cyber operations, are used to disrupt foreign-based threats to Canadian interests, whether they're defense or security interests. And this is where CSC goes out there and hacks enemies, hacks hostile actors, maybe steals their money, locks down their money, disrupts their communications. In order to prevent them from doing something to Canada, defensive cyber operations are more reactive.
Starting point is 00:09:08 They're triggered when a system of importance is under attack and passive defenses are not enough. They go out there and they attack the enemy. Now, both of these require authoritative. from the Minister of National Defense, the difference is the Minister of Foreign Affairs must consent to what are called active or offensive cyber operations
Starting point is 00:09:29 because these, of course, could affect Canada's international relations. We'll be right back. Okay, so we have a bit of a sense of what this agency does. But who do they take direction from and who are they accountable to? Well, they're accountable to the Minister of Defense and there's two watchdogs who conduct independent review. There's the National Security and Intelligence Review Agency, and there's the Intelligence Commissioner.
Starting point is 00:10:00 Steve, let's turn to what Canada is facing in terms of cybersecurity threats. What are the major threats right now for Canada? The major threat is cybercrime. There are everyday fraud against individuals and businesses that cost billions of dollars. People are familiar with ransomware, where hackers gain control of a hospital or an organization's computers and refuse to release them until they're paid a ransom. And espionage. So cracking government systems to gain information that can be used by rivals or hostile
Starting point is 00:10:37 actors. There is also industrial sabotage. It is when hackers get inside the computer systems that affect utilities like gas companies or water companies. So they get inside. nuclear power plants or they get inside electrical grid systems and either plant worms or computer code that could act at a later date or do it immediately. I mean, close to home back in 2024, we learned that hackers had compromised one of Canada's largest wastewater treatment facilities
Starting point is 00:11:13 in the Durham region east of Toronto. Now, this was averted because they contained the breach, but it's an example of the kind of industrial sabotage that organizations such as the CSE are really concerned about. So there is a report released at the end of June that gave us a little bit of more information about what the CSE was working on. And the report mentioned an active cyber operation involving fentanyl brokers. What do we know about that? Well, we only know what the CSE told us, which is that they conducted basically hacking operations, offensive cyber. operations against foreign criminals who were brokering the purchase and sale of the ingredients used to make the opioid fentanyl. And they said that they did this in the 25, 26 year.
Starting point is 00:12:05 The CSC didn't identify the brokers, their country of origin, the techniques they used. But security experts, like Stephanie Carvin at Carleton, said that they could have targeted their ability to pay. They could have seized or locked their digital assets, such as cryptocurrency currency wallets, or they could have hacked the fentanyl broker's communications, among other disruptive actions. What does it tell you that an organization like the CSC is highlighting operations against the fentanyl supply chain in its report? Well, I think they're trying to demonstrate to the U.S. government that Canada is taking
Starting point is 00:12:38 action against fentanyl. As you will recall, Donald Trump in 2025 imposed tariffs on Canada that started at 25% on Canadian products and rose to 35%. He used allegations that fentanyl was coming into the United States from Canada as his main rationale for that. The Canadian government, of course, pushed back on that and said that the minute amounts of fentanyl were coming across the border. And Mr. Trump's tariffs were subsequently struck down by a Supreme Court ruling. But this is an attempt to show the Americans that were responding to their concerns. And if it ever comes up again, if Mr. Trump ever brings it up again, the government will be able to point to this as evidence that we've
Starting point is 00:13:23 been taking action. Okay. So that's what we learned about a cyber operation involving fentanyl brokers. Do we learn about other things that the CSC was working on? Yeah. In their latest report, they said they took action against 10 of the most significant ransomware groups that are causing harm to Canada and its allies. And working with our allies that conducted an offensive cyber operation against a specific
Starting point is 00:13:45 ransomware as a service group responsible for more than 25 incidents against. against Canadian organizations in the transportation, health care, pharmaceutical, and business sectors. It said that they rendered the group's infrastructure inoperable and deleted a large amount of stolen data that the group had advertised for sale on the dark web. Okay, so you've laid out two examples from this report. But Steve, I'm curious. Do you think we know enough about what the CSC does? Absolutely not.
Starting point is 00:14:14 There's the old Spider-Man principle that with great power comes great responsibility. And in this case, CSE has an enormous mandate, a ton of money, and a lot of free reign to conduct hacking and interception operations around the world. As a reporter, it does concern me that we know so little about what they do when it comes to code breaking and interception. And I think that we see that allies praise them for this. We've seen the British praise CSE for being effective. And it always makes me wonder, well, what is it they're effective in doing? A large part of their operations are shrouded in secrecy.
Starting point is 00:14:55 We have two watchdog groups to keep watch over them, but, you know, sunshine is a great disinfectant, and it concerns me that we still know so little about their biggest job, which is foreign intelligence gathering. I do have to ask you, though, because CSC is a security agency, like what kind of balance do they need to strike between secrecy and transparency, right? Because, of course, wouldn't it compromise their effectiveness if more things were out in the open? Those stories that broke in 2013 from the Snowden leaks gave us some insight into how they operate and raised a lot of questions. So given that what was released in unauthorized leaks raised a lot of questions, it does make me wonder if
Starting point is 00:15:40 there's a lot more that we should be reviewing and considering. I mean, as a journalist, it's troubling that this organization operates with so little public profile to what is essentially foreign intelligence gathering. So just to end here, Steve, the CSC's budget is up. Their headcount has grown. And this stands in opposition to most other government departments. So what does that tell you about the federal government's priorities? It tells me that Ottawa is increasingly leaning on the CSC in a more dangerous and uncertain
Starting point is 00:16:13 world, where cybercrime is on the way up, where rival states are more and more aggressive and hostile about interfering in other states or hacking, and where defense is playing an increasingly important role in budgets. Okay, Steve, we'll leave it there. Thank you so much. All right. Thanks a lot. That was Stephen Chase, the Globe's Senior Parliamentary Reporter.
Starting point is 00:16:42 That's it for today. I'm Cheryl Sutherland. Tiff Lamb mixed this episode. Our producers are Madeline White, Rachel Levy McLaughlin and Mikhail Stein. Our editor is David Crosby. Adrian Chung is our senior producer and Angela Pichenza is our executive editor.
Starting point is 00:17:04 Thanks so much for listening.

There aren't comments yet for this episode. Click on any sentence in the transcript to leave a comment.