Special Features

Cybersecurity Month

Chinese attackers accessed Canadian government networks – for five years

India makes it onto list of likely threats for the first time


A report by Canada's Communications Security Establishment (CSE) revealed that state-backed actors have collected valuable information from government networks for five years.

The biennial National Cyber Threat Assessment described the People's Republic of China's (PRC) cyber operations against Canada as "second to none." Their purpose is to "serve high-level political and commercial objectives, including espionage, intellectual property (IP) theft, malign influence, and transnational repression."

Over the past four years, at least 20 networks within Canadian government agencies and departments were compromised by PRC cyber threat actors.

The CSE assured citizens that all known federal government compromises have been resolved, but warned that "the actors responsible for these intrusions dedicated significant time and resources to learn about the target networks."

The report also alleges that government officials – particularly those perceived as being critical of the Chinese Communist Party (CCP) – were attacked. One of those attacks includes an email operation against members of Interparliamentary Alliance on China.

The purpose of the cyber attacks is mainly to gain information that would lead to strategic, economic, and diplomatic advantages. The activity appears to have intensified following incidents of bilateral tension between Canada and the PRC, after which Beijing apparently wanted to gather timely intelligence on official reactions and unfolding developments, according to the report.

Canada's private sector is also in the firing line, with the CSE suggesting "PRC cyber threat actors have very likely stolen commercially sensitive data from Canadian firms and institutions."

Operations that collect information that could support the PRC's economic and military interests are priority targets.

The intelligence agency predicted espionage activities will intensify alongside economic growing tensions between the PRC and Canada's allies.

Among the products identified as lustworthy for Beijing are: humanoid robots, quantum computers, new displays, brain-computer interfaces, 6G networks, ultra-large scale new intelligence computing centers, Web 3.0, and advanced aviation equipment.

India rising

The report also named Russia and Iran as significant hostile states – which isn't surprising.

The inclusion of India, named for the first time as an emerging threat, may be. Canada and India are, after all, both democracies and share membership of the UK-centric Commonwealth of Nations.

"We assess that Indian state-sponsored cyber threat actors likely conduct cyber threat activity against Government of Canada networks for the purpose of espionage," stated the agency, adding "We judge that official bilateral relations between Canada and India will very likely drive Indian state-sponsored cyber threat activity against Canada."

India and Canada have recently experienced increased diplomatic friction. In September of last year, Canadian prime mMinister Justin Trudeau publicly accused the Indian government of involvement in the murder, on Canadian soil, of Sikh activist Hardeep Singh Nijjar.

In the weeks that followed, Canada's military and parliament experienced cyber attacks from independent – but politically state-aligned – Indian hacktivists.

The cyber threat assessment highlighted that such motivated hacktivism, from many sources, complicates the threat environment and can disrupt critical infrastructure. ®

Send us news
15 Comments

Trump administration wants to go on cyber offensive against China

The US has never attacked Chinese critical infrastructure before, right?

China gorging on silicon before Uncle Sam slams the door

Chip imports up more than 14% this year in anticipation of fresh restrictions

Infosys founder calls for 70-hour work week – again – claiming it creates jobs

Plus: China wants to end AI mashups of classic vids; TSMC set to open Japan fab; and more

China preps another rocket that Beijing hopes will become its workhorse

Long March-8A improves payload by forty percent and comes just a month after Long March 12 debut

Blue Yonder ransomware termites claim credit

Also: Mystery US firm compromised by Chinese hackers for months; Safe links that aren't; Polish spy boss arrested, and more

China's homebrew Bluetooth alternative is on the march as Beijing pushes universal remotes

'Star Flash' is said to include 5G tech and leave rival wireless protocols struggling in the crack of a sofa

US reportedly mulls TP-Link router ban over national security risk

It could end up like Huawei -Trump's gonna get ya, get ya, get ya

How Chinese insiders are stealing data scooped up by President Xi's national surveillance system

'It's a double-edged sword,' security researchers tell The Reg

Trump tariffs transform into bigger threats for Mexico, Canada than China

America's neighbors now face 25% because of fentanyl and immigration, China just 10% on top of existing duties

Supreme Court to hear TikTok's appeal against law that would force it to shut, or sell

Will consider free speech arguments just nine days before the clock runs out

China strikes back with Nvidia antitrust probe as US tightens tech chokehold

Beijing cites GPU giant's Mellanox merger conditions from four years ago

Indian police demand Starlink identify alleged drug smugglers

Elon Musk's satellite internet service asked to explain who used its service to navigate to remote islands