Canada’s signals intelligence agency just confirmed it ran offensive cyber operations against a ransomware-as-a-service gang, an online extremist group, and a drug trafficking network in 2025. That’s a genuine escalation in state-level cybersecurity posture: a Western intelligence service publicly admitting it hacked criminals back. It’s also, for the sysadmin patching a NetScaler appliance at 11pm, almost entirely irrelevant. One gang went dark. Another one is already renting infrastructure to fill the gap. Your risk exposure this morning looks exactly like it did last week.

That gap between headline and reality is worth sitting with, because it explains why so many organizations keep getting breached even as governments claim to be winning.
A Spy Agency Goes on Offense, Your Attack Surface Doesn’t Shrink
The Communications Security Establishment’s disclosure is notable mostly for the honesty. Offensive cyber operations against criminal groups aren’t new; admitting to three of them in a single annual report is. CSE described disrupting a ransomware-as-a-service operator, a foreign extremist group running online radicalization campaigns, and a drug trafficking network that had moved its logistics online.
Read that as a policy story and it’s a big deal. Read it as an operational one and the math doesn’t change. Ransomware-as-a-service isn’t a company with one office you can raid. It’s a franchise model: a handful of operators build the tooling, dozens of affiliates rent it, and disrupting one operator just pushes affiliates toward the next platform. The FBI and international partners have taken down major RaaS infrastructure repeatedly over the past few years. Ransomware volume kept climbing anyway.
A ransomware-as-a-service gang, an online foreign extremist group and drug traffickers were separately the targets of offensive operations in 2025, according to Canada’s Communications Security Establishment.
None of this means offensive operations are pointless. Disrupting one operator’s revenue, infrastructure, and morale has real value, and it’s better than doing nothing. But if your organization’s threat detection and incident response planning assumes that state-level takedowns are shrinking the population of attackers who might hit you, that assumption is wrong. The attacker pool is elastic. Your defenses need to be built for the attacker who’s still standing, not the one who got taken offline.
Point-in-Time Compliance Keeps Losing to Attackers Who Don’t Check the Calendar
This is where a quieter story matters more than the CSE disclosure. Microsoft’s rundown of the 2025 Frost Radar for Cloud Security Posture Management and a parallel piece from SecurityWeek on business-aligned risk management are both describing the same shift: security teams are finally admitting that point-in-time compliance snapshots don’t reflect actual risk.
A compliance audit tells you what your environment looked like on the day someone checked. An attacker doesn’t care what your environment looked like on audit day. They care what it looks like right now, including the misconfigured storage bucket someone stood up last Tuesday and the service account that’s had standing admin rights since a project wrapped six months ago. Static, periodic assessments miss all of that by design.
The industry direction, per the Frost Radar analysis, is toward continuous risk management: posture tools that reassess constantly instead of quarterly, tied to business impact rather than a checklist of controls. That’s the right direction, but it only helps if organizations actually operationalize it instead of treating it as another dashboard nobody opens. A continuous risk feed that nobody triages is just a more expensive point-in-time report that happens to update automatically.
Layer in the other trend line from this week: Armored Likho and similar threat actors blending commodity malware with targeted intrusion tooling against government and infrastructure targets. These groups don’t wait for your annual risk review. Defense in depth has to run on the same clock attackers do, not the clock your compliance calendar runs on.
What Actually Moves Your Risk, Starting This Week
None of the geopolitical maneuvering changes what you control. Here’s what does:
- Replace scheduled vulnerability scans with continuous exposure monitoring on anything internet-facing, especially cloud storage, admin panels, and remote access appliances.
- Put brute-force protection in front of every exposed login, VPN, RDP, admin console, not just the ones your compliance framework happens to mention by name.
- Tighten firewall rules around lateral movement paths, not just the perimeter. Most ransomware damage happens after initial access, moving between systems that never needed to talk to each other.
- Feed threat intelligence, including IP and domain reputation data, directly into your detection stack so indicators get triaged automatically instead of sitting in a spreadsheet someone reviews on Fridays.
- Rehearse incident response against a ransomware-as-a-service scenario specifically, since that’s the affiliate model most likely to actually reach your environment, regardless of which specific operator gets disrupted this year.
- Kill standing privileged access nobody’s using. It’s the single most common thing post-breach forensics finds sitting there unmonitored.
Security hardening isn’t a project with an end date. It’s the ongoing work that determines whether a disrupted ransomware operator’s downfall matters to you at all, or whether the next affiliate group finds your environment exactly as soft as the last one did.
Sources
- Canadian spy agency reports hacking three criminal groups in 2025
- 5 insights from Frost & Sullivan’s 2025 Frost Radar for Cloud Security Posture Management
- The Shift Toward Business-Aligned Risk Management
- Armored Likho APT Targeting Government, Electric Power Entities
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
Take Control of Your Server Security
Don't let brute-force attacks slow you down. Try IPBan Pro risk-free for 30 days.
Secure. Automated. Lightweight.
