Russian Hackers Breach Quebec Water Treatment Plant, Canada’s Spy Agency Reveals
Russian cybercriminals successfully infiltrated the water treatment systems of a Quebec community, gaining the ability to manipulate critical infrastructure before being detected and stopped, according to Canada’s signals intelligence agency.
In its latest annual report, released Monday, the Communications Security Establishment (CSE) disclosed that it identified over 3,200 cyber incidents during the reporting period targeting federal agencies or one of 10 critical infrastructure sectors, including energy, critical minerals, and water.
NoName Group Claimed Control Over Key Water Systems
One of the most alarming cases detailed in the report involved the Russian hacktivist group NoName, which broke into the network of a Quebec water company last October and accessed numerous essential systems.
According to CSE, NoName claimed it “gained the ability to secretly control pumps, chlorine dosing, pressure settings and monitoring/alert systems.” The report did not identify the specific Quebec community affected by the breach.
This incident represents one of the most concrete examples the federal cyber agency has cited demonstrating how foreign, state-backed hackers are actively attempting to compromise Canada’s critical infrastructure. The agency noted that these actors often seek to either blackmail system owners or plant dormant threats that could be activated in the event of hostilities between their country and Canada.
A First for Canadian Cyber Attribution
The breach is also notable as the first time CSE — which has previously issued warnings about foreign cyberattacks targeting Canada’s water infrastructure — has publicly attributed a wastewater treatment plant compromise to a Russian-backed group and confirmed the province where the affected system was located.
The U.S. Department of Justice has identified NoName as a cybercrime group funded by the Russian government that frequently conducts operations against Russia’s adversaries. The group has a documented pattern of targeting North American water systems.
“State-sponsored actors are becoming more aggressive and moving beyond traditional espionage to conduct more disruptive activities,” the report stated.
International Partners Alerted Canada to the Breach
Interestingly, the annual report notes that CSE did not independently discover the breach. Instead, the agency’s Cyber Centre was notified by the Organization of American States’ Cybersecurity Coordinating Network after NoName made public claims about the intrusion. CSE said it subsequently worked with unnamed partners to contain the threat.
Russia and China Pose Growing Threat in the Canadian Arctic
The report also highlights two primary state-sponsored cyber adversaries: Russia and China. It emphasizes that both countries represent a growing threat in the Canadian Arctic, where challenges posed by adversaries “go beyond traditional military and cyber threats to include economic and influence activities designed to influence access, infrastructure and decision-making in the region.”
CSE Used Offensive Powers Against Fentanyl Traffickers and Extremists
In a separate section of the report, CSE revealed that it deployed its extraordinary powers to conduct offensive and defensive cyber operations targeting a network of fentanyl precursor traffickers and an unidentified foreign extremist group attempting to recruit Canadians.
In the first operation, CSE disclosed that “major” foreign cybercriminals were brokering the purchase and sale of chemicals used to synthesize opioids such as fentanyl. The agency collected foreign intelligence on the group before launching an offensive cyber operation that “disrupted and disrupted” the brokers’ activities.
In the second case, the intelligence agency intercepted a foreign extremist group spreading violent ideology and recruiting in Western countries, including Canada. CSE then conducted another offensive cyber operation that “undermined the group’s credibility and limited its ability to radicalize and recruit new members.”
Five Eyes Operation Targeted Ransomware Group
In a separate collaborative operation, CSE said it worked with partners across the Five Eyes intelligence alliance — which includes Canada, the United States, the United Kingdom, Australia, and New Zealand — to attack an unnamed “notorious ransomware-as-a-service” cybercrime group. The operation successfully disabled the group’s systems and resulted in the deletion of “a large amount of stolen data.”
According to CSE, the group was responsible for more than 25 ransomware attacks across Canada’s transportation, healthcare, pharmaceutical, and business sectors. In these attacks, hackers lock users out of their networks or data and demand a ransom payment to restore access.
Rising Vulnerabilities Demand Greater Vigilance
Overall, the cyber defense agency warned that both the number and severity of major network vulnerabilities are increasing, underscoring the growing urgency for robust cybersecurity measures across Canada’s critical infrastructure sectors.