Noah MitchellVIEW PROFILE →
Canada faces rising cyber threats as ransomware targets critical infrastructure
Canada's cybersecurity agencies warn of escalating cyber threats, with ransomware now the top cybercrime danger to critical infrastructure. The Canadian Centre for Cyber Security responded to more than 3,200 incidents in a single year, while state-sponsored actors and cybercrime services continue to
Canada is facing a rapidly evolving and increasingly dangerous cyber threat landscape, according to the country's leading cybersecurity agencies. As attacks grow in both scale and sophistication, government institutions and critical infrastructure operators are being urged to strengthen their defences against a range of threats that continue to expand year after year across every sector.
Thousands of incidents in a single year
The scale of the challenge is reflected in recent figures from the Canadian Centre for Cyber Security. During its 2025 to 2026 reporting period, which covered the months from April 2025 to March 2026, the centre responded to more than 3,200 cybersecurity incidents that affected federal institutions and critical infrastructure across the country, underlining the persistent nature of the threat.
These figures come from the annual report of the Communications Security Establishment, known as CSE, which detailed the activities of the agency and its cyber centre. The report made clear that cyber threats continued to grow in complexity throughout the period, forcing defenders to adapt constantly to new tactics and techniques deployed by malicious actors targeting the nation.
Ransomware leads the threats

Among all the dangers identified, ransomware stands out as the top cybercrime threat facing Canada's critical infrastructure. Cybersecurity authorities warn that ransomware actors will continue to diversify their tactics in response to heightened attention from law enforcement, making the threat both persistent and highly adaptable as criminals seek to maximise their illicit profits.
The CSE reported that its intelligence supported investigations into sophisticated ransomware-as-a-service operations. These operations were responsible for more than 25 separate incidents that targeted a wide range of sectors, including transportation, healthcare, pharmaceutical companies and businesses, demonstrating how broadly the ransomware threat has spread across the Canadian economy.
In response, the agency took concurrent action against 10 of the most significant ransomware groups causing harm to Canada and its allies. This involved carrying out authorised technical disruptions designed to make parts of their infrastructure unusable, while also working closely with international law enforcement partners to help dismantle foreign cybercriminal networks operating abroad.
The financial toll of ransomware
The financial impact of ransomware on Canada has been severe and rising steadily. According to the National Cyber Threat Assessment, reported losses reached 383 million Canadian dollars in 2021, climbing to 530 million in 2022 and 567 million in 2023. The average ransom paid in Canada in 2023 stood at approximately 1.13 million Canadian dollars, a sharp increase of 150 per cent over two years.
Certain sectors have proven especially vulnerable to these attacks. Incidents affecting the healthcare sector nearly doubled compared with 2022, with notable disruptions affecting hospitals and health services. The energy sector was also hit, as an incident in June 2023 disrupted payment processing at Petro-Canada stations, showing how attacks can affect everyday services for ordinary citizens.
State-sponsored threats
Beyond financially motivated criminals, Canada also faces significant threats from state-sponsored actors. The assessment identified the People's Republic of China as a leading concern, noting that at least 20 government networks had been compromised over a period of four years, with a focus on innovation, intellectual property and critical minerals sectors of strategic importance to the country.
Other nations were also named as sources of persistent cyber activity. Russia was described as conducting a multi-layered strategy that combines espionage with disinformation campaigns, while Iran carried out 24 coercive cyber operations in 2023 alone. North Korea, meanwhile, prioritises generating revenue through ransomware and cryptocurrency theft in order to help fund its regime.
Emerging risks and investment
The rise of artificial intelligence has introduced new risks into the cyber landscape. The assessment recorded 107 reported generative AI incidents causing harm in 2023, with a projection of 138 such incidents for 2024. These tools are increasingly being used to create deepfakes, craft highly personalised phishing messages and power sophisticated disinformation campaigns targeting the public.
To confront these growing challenges, the Canadian government has committed substantial resources to its cyber defences. Budget 2024 allocated 917.4 million Canadian dollars to enhance intelligence and cyber operations programs aimed at addressing national security threats, signalling a clear recognition of the urgent need to protect the country in an increasingly hostile digital environment.





