THE INTEL BRIEF

News and Content From Our Members





Menu
Log in
FR

Log in
<< First  < Prev   1   2   3   4   5   ...   Next >  Last >> 
  • July 28, 2026 1:33 PM | Anonymous

    By Charlotte Van Campenhout - Reuters

    BRUSSELS, July 28 (Reuters) - A Canadian woman of Chinese origin accused of spying while working as an intern at NATO's military headquarters in Belgium will remain in pretrial custody for another month, a spokesperson for the Belgian Federal Prosecutor's Office said on Tuesday.

    The Federal Prosecutor's Office declined to give further details about the woman, who is suspected of espionage on behalf of a third country and of membership in a criminal organisation.

    The prosecutor's spokesperson added that the suspect now has 24 hours to lodge an appeal. 

    The woman ​worked as an intern at NATO's Supreme Headquarters Allied ​Powers Europe (SHAPE) in the Belgian city of Mons.

    An intelligence source said the woman is in her 30s and not a student. They also said she had been close to completing her internship, prompting authorities to accelerate the investigation.

    Neither NATO nor Belgian authorities have specified what the suspect's work at NATO involved.

    Responsibility for conducting security checks on interns lies with their countries of origin, which in this case was Canada.

    The Canadian government did not immediately reply to a request for comment.

    Minister of Public Safety Gary Anandasangaree said during a press briefing on Monday that Canada "will continue to investigate the processes we have and the security screening".

    "In this particular case, I think it's important to get to the bottom of what happened," he said.

    SHAPE ​is NATO's top military headquarters, the base of Allied Command Operations, ‌which ⁠is responsible for planning and carrying out all operations of the 32-member transatlantic security alliance.

    The suspect had come to the attention of SHAPE's security services, which reported ​her to Belgian ​intelligence officials after observing her behaviour, ⁠according to the prosecutor's statement.

    A ​SHAPE spokesperson said ⁠there was no indication that NATO or SHAPE operational readiness, command and control arrangements or ongoing tasks had been affected.

    (Reporting by Charlotte Van Campenhout, additional reporting by Andrew Gray in Brussels, Maria Cheng in Ottawa 

  • July 20, 2026 12:22 PM | Anonymous

    Kristy Nease · CBC News · Posted: Jul 20, 2026 4:00 AM EDT

    Former federal scientist Dennis Lu, 65, was the subject of three briefings by the Canadian Security Intelligence Service (CSIS) to Lu's employer, Natural Resources Canada, according to court records. In May CSIS took the rare step of disclosing one of its own documents in court to set the record straight about how it came to be involved in the file.

    The country's top spy agency says Natural Resources Canada approached it with concerns about former federal scientist Dennis Lu more than two decades ago, not the other way around — and has made a rare disclosure of one of its documents in court to set the record straight, CBC News has learned. 

    There are also new details about part of the reason for a 23-month delay between the last Canadian Security Intelligence Service (CSIS) briefing about Lu to his employer in February 2021 and the start of Natural Resources' internal investigation into Lu in January 2023.

    Lu's security clearance was eventually revoked and an RCMP investigation resulted in criminal charges of breach of trust and unauthorized use of a computer.

    It's alleged that he used his access to the Natural Resources network to copy a total of more than 2,500 documents onto a USB key and external drive.

    He faces trial in Ottawa's Superior Court by a judge alone in January.

    This spring, a Department of Justice lawyer addressed court on behalf of CSIS "just to clarify" how the entire file on Lu began more than two decades ago.

    "It wasn't CSIS flags per se, it was a government tip-off," Sheldon Leung said.

    The lawyer's comments came during a pre-trial motion brought by Lu's defence team in its fight to access to hundreds of pages of third-party records that it said were relevant to the case — access it won for most of the documents.

    Hosted Chinese delegation

    Leung then read part of a CSIS document that the spy agency wanted the judge to see, dated Nov. 20, 2000 — the same year as CSIS's first briefing to Natural Resources about Lu.

    "On Nov. 14, 2000, a source provided the following unsolicited information regarding a visiting delegation. According to source one, Mr. Dennis Lu, research scientist at [Natural Resources'] Advanced Combustion Technology branch (ACT), had invited a visiting Chinese delegation without the knowledge of his operational manager," the document reads.

    "It was only after the fact, when questioned, that Lu provided the following information about the delegation to [his department's] security officials and his manager."

    But Leung read no further, saying only that the rest of the CSIS document contained details about a meeting and some potentially sensitive government information.

    This spring, a federal lawyer addressed court on behalf of the Canadian Security Intelligence Service 'just to clarify' how the entire file on Lu began more than two decades ago. (Sean Kilpatrick/The Canadian Press)

    'Resource constraints'

    During a separate pre-trial motion brought by the defence this summer about whether the investigation breached Lu's privacy, Brad Lanthier, a former chief security officer at Natural Resources, testified about the team he first joined in November 2022, 21 months after the last CSIS briefing about Lu.

    Under examination-in-chief by assistant Crown attorney Tim Radcliffe, Lanthier said the team had recently been separated from the IT department and wasn't set up to take a large investigation on.

    "There were severe, I would say, resource constraints in terms of our ability to conduct anything more than traditional risk investigations at that point in time," said Lanthier, now the RCMP's director general of national communications.

    "It took a little bit of time [before the investigation formally began in January 2023]," he said. "The security function was just kind of getting up and going."

    Lanthier testified that soon after he arrived, he was briefed about Canada's Task Force on Science and National Security, whose "primary goal was to safeguard science and to protect it from intellectual property theft, with a focus on foreign actor interference."

    'A significant amount of risk'

    He also learned about the Chinese government's Thousand Talents Program, which aims to bring scientists and researchers from all over the world to China, as well as the country's intelligence law, which can be used to compel citizens to share information with China to benefit its national security and economy.

    As for Lu, Lanthier was told by colleagues that CSIS had briefed Natural Resources about him multiple times, that he was taking an extended leave without pay in China, and that he had asked his supervisors for permission to teach in China.

    Taken together with the foreign interference threats from China, Lanthier said he believed there was "a significant amount of risk." So he asked IT staff to search Lu's emails for specific keywords, with CSIS providing input on what the search terms would be.

    Lu was not granted permission to teach in China, and his access to Natural Resources' network was cut off while he was on leave because there would have been no need for him to access it, Lanthier told court.

    Lu's access to Natural Resources Canada's network was cut off while Lu was in China during his leave of absence ahead of retirement, court heard.


    Wrote MP to get network access back

    Then Lu returned to Canada and asked for his network access to be reinstated — moves that were "surprising" to the federal department, Lanthier said, because Lu's original plan had been to transition into retirement during his leave in China.

    Lu's request for network access was therefore denied, Lanthier said, and Lu's reaction to the denial raised further suspicions.

    "I believe Mr. Lu used a few different avenues, including writing his MP, requesting his access back. At that point the risk [in my opinion] had escalated significantly given the travel, given the change in plans, and given the what appeared to be determined request to get access back," Lanthier testified.

    "We were then informed that Mr. Lu had in fact amended his leave, so therefore, just like any employee, we had no choice but to give him his access back. But we did request [IT to conduct] daily activity reports [about] Mr. Lu."

    He allegedly copied 2,414 documents off a Natural Resources shared server on July 7, 2023, and a further 188 documents on Aug. 9, 2023.

    His security clearance was then revoked, Lanthier said.

    Lanthier personally referred the case to the RCMP on Aug. 17, 2023. Based on "the sheer volume of files that had been transferred," Natural Resources then had to conduct a damage assessment to determine what was taken, whether it was of value, and whether other government departments would be affected, he said.


    A USB key was one of two devices Lu allegedly used to copy Natural Resources documents off of the federal department's shared drive.

    Searched 16 years of emails, phone use

    In cross-examination, Reem Zaia, one of Lu's defence lawyers, pointed out that many countries have talent programs, including Canada, and that Canada's Policy on Sensitive Technology Research and Affiliations of Concern came into effect in May 2024 — almost a year after the documents were allegedly copied.

    Lanthier acknowledged no evidence was found that Lu was a member of China's Thousand Talents Program and said he didn't know exactly what CSIS's concerns about Lu were — aside from affiliations with the Chinese government — when the investigation into Lu was ordered and conducted.

    Zaia also read aloud part of a document outlining the testimony Lanthier had been expected to give, which said that "the fact-finding review [into Lu] identified some associations and correspondence with individuals from a country of a concern [China], but it was not definitive based on the narrow search conducted at the time."

    That "narrow search," as Zaia pointed out and Lanthier acknowledged, included 16 years of Lu's work emails — received, sent and/or deleted — from January 2007 to 2023. It also covered all communications to and from his work cellphone — calls, messages and/or texts — across the same 16 years.

    No instructions to exclude Lu's private information were made, court heard.

    Co-operative agreements with China

    Lanthier also didn't dispute that:

    • Natural Resources security categorization standards allowed employees with security clearance such as Lu to store protected A-, B- and C-level documents on USB keys and external hard drives (A-level documents could cause injury to an individual, organization or government if compromised; B-level documents could cause serious injury; and C-level documents could cause extremely grave injury).
    • A report found that about 1,100 Natural Resources employees were using USB keys in 2023.
    • The standard operating procedure at Natural Resources allowed some staff 24/7 access to the federal department's network even if they had retired, according to a senior director of operations in an interview with RCMP. (Lanthier told Zaia he wasn't aware of that procedure, but had no reason to doubt it.)

    He also wasn't aware that Natural Resources had a memorandum of understanding with China's National Energy Administration.

    It took effect in June 2017, lasted five years, focused on energy, and "encouraged participants to promote technical and policy co-operation, including the exchange of experts and information as well as joint research," Zaia said.

    Prime Minister Mark Carney, back left, and Premier of China Li Qiang, back right, look on as Minister of Energy and Natural Resources Tim Hodgson, front left, and Wang Hongzhi, Director of the National Energy Administration in China, front right, sign a memorandum of understanding to co-operate on energy in Beijing on Jan. 15, 2026.

    (There had been a previous memorandum between Natural Resources and China's National Energy Administration regarding nuclear energy in 2014. A new memorandum between the departments to strengthen energy co-operation took effect in January this year.)

    Pre-trial motions in Lu's case are ongoing. Four weeks have been set aside for Lu's trial next year.



  • July 16, 2026 12:33 PM | Anonymous

    Former senior CSIS intelligence officer Dan Stanton told a Capitol Hill briefing that foreign states are using criminal organizations to target diaspora groups because it gives them plausible deniability.
    Greg Mercer - The Globe and Mail 
    2026-07-15

    A former senior CSIS intelligence officer warned U.S. congressional representatives and staff in Washington Tuesday that foreign states such as India are increasingly using transnational criminal groups to outsource surveillance, coercion, intimidation and lethal violence.

    Dan Stanton, who spent 32 years in Canada’s spy agency and is now director of the national security program at the University of Ottawa, told a Capitol Hill briefing that this country’s experience with transnational repression shows hostile countries are using criminal organizations to target diaspora groups because it gives them plausible deniability.

    Mr. Stanton’s remarks to U.S. politicians and their aides come a week after U.S. officials and the head of the RCMP announced a series of charges and arrests across three prominent India-based gangs – including the leaders of the Bishnoi gang, which authorities say ordered the assassination of B.C.-based Sikh separatist Hardeep Singh Nijjar three years ago.

     Mr. Nijjar’s death sparked a diplomatic fallout between Ottawa and New Delhi, after then-prime-minister Justin Trudeau told Parliament in 2023 that there was credible evidence Indian government agents had orchestrated the killing.

    In 2024, the Mounties warned that Indian government agents were linked to multiple homicides, extortions and other violent criminal activities, and Ottawa expelled India’s high commissioner and five other diplomats. In May, CSIS said India remains one of the main perpetrators of foreign interference and espionage in the country.

    India has denied any role in the Nijjar plot, and refuted allegations it’s involved in transnational repression or interference in Canada. Prime Minister Mark Carney, trying to expand trade with the country of 1.4 billion, said he raised Canada’s concerns about foreign interference when he met with Prime Minister Narendra Modi in New Delhi in March.

    A 2024 U.S. Department of Justice indictment accused an Indian government intelligence officer, Vikash Yadav, of using hired gunmen to arrange Mr. Nijjar’s killing, as well as a failed plot against his New-York based lawyer. India now says Mr. Yadav was a “rogue operative” who has gone missing and can’t be extradited to the U.S. to face prosecution.

    U.S. investigators say the gunmen sent Mr. Yadav a video of Mr. Nijjar’s dead body, as proof of his killing, which he then shared with Nikhil Gupta, who he had hired to arrange the assassination of lawyer Gurpatwant Singh Pannun. Mr. Gupta had pleaded guilty in that plot and is to be sentenced in September.

    The Globe and Mail previously reported that Canadian national security officials were presented with evidence that Indian consular staff in Vancouver supplied information to assist in the assassination of Mr. Nijjar, a man India labelled a terrorist for his role in a campaign to create a breakaway state in Punjab called Khalistan.

    Mr. Stanton told The Globe that relying on plausible deniability offered by gangs is part of the same playbook used by states such as Iran, Russia and China when they seek to suppress their critics living in Western countries.

    “I just want to signal that this is a growing problem, and India is one of the main actors,” he said. “The ones doing the really messy, dirty work have a certain criminal history, and so when they’re caught, the state that’s behind it, or their intelligence service, has that firewall because they can say, ‘They’re just criminals.’”

     Mr. Stanton, speaking as part of a panel that include Representative Jim McGovern and U.S. national security experts, offered the only Canadian perspective in the room. He told the crowd that when he began working in counterintelligence, it was a world of spies and double agents. Today, countries have to defend against the new threat of transnational criminals, who sometimes wittingly or unwittingly do the work of foreign powers, he said.

    “The problem is that our institutions in Canada are still organized for a world where espionage and organized crime were separate disciplines,” he said. “Today they’re increasingly intertwined, requiring police and intelligence agencies to operate across legal authorities and mandates that were never designed for this kind of hybrid threat. That’s the intelligence and law-enforcement challenge of our time.”

    India began a more aggressive approach to national security following the 2008 Mumbai terrorist attacks, he said. Under Mr. Modi, the country has concluded that extradition and international legal processes are inadequate, and it increasingly embraced the “direct neutralization” of those it regards as terrorist threats outside its borders, he said.

    “The problem is that our institutions in Canada are still organized for a world where espionage and organized crime were separate disciplines,” he said. “Today they’re increasingly intertwined, requiring police and intelligence agencies to operate across legal authorities and mandates that were never designed for this kind of hybrid threat. That’s the intelligence and law-enforcement challenge of our time.”

    India began a more aggressive approach to national security following the 2008 Mumbai terrorist attacks, he said. Under Mr. Modi, the country has concluded that extradition and international legal processes are inadequate, and it increasingly embraced the “direct neutralization” of those it regards as terrorist threats outside its borders, he said.

    Canada, along with the U.S., has been slow to recognize this shift, and needs to understand how serious of a problem foreign interference inside our borders has become, he said.

    “We’ve done everything we can with terrorism, espionage, political interference and cyberthreats, but we really, our governments and countries haven’t really done much in terms of addressing transnational repression,” he told The Globe.

    Mr. Pannun, a close associate of Mr. Nijjar’s in the campaign for an independent Khalistan, said last week’s indictments of Indian gang members don’t absolve India of involvement in the murder-for-hire plots, even though they were silent on any government involvement. He called for international sanctions against the Indian state.

    “The Bishnoi indictment cannot be viewed in isolation. It must be read together with the U.S. murder-for-hire prosecution targeting me. Together, these two cases strip away all plausible deniability, exposing the lethal, dual-track transnational assassination apparatus operated by the Indian government,” he said in a statement.

    “Justice cannot stop with the jailed gangsters, the triggermen, or the intermediaries. The trail of evidence leads directly to the highest echelons of the Indian government.”

     


  • June 16, 2026 2:47 PM | Anonymous

    Sam Cooper

    Jun 16

     
    READ IN APP
     
    Flow chart of China’s botnet attack flow, generated by The Bureau from research reports.

    OTTAWA — For the first time, a Federal Court judge has authorized Canada’s intelligence service to hack into privately owned routers, servers and household internet devices across the country and disarm the malicious software that conscripts them into foreign botnets — virtual armies implanted by hostile states to act as trojan horses, attacking critical Canadian infrastructure from within Canadian homes — a power the court itself acknowledged would otherwise be a crime.

    A newly released Federal Court ruling reveals the first warrant of its kind ever granted to Canadian Security Intelligence Service — authority to neutralize two state-run botnets pre-positioned against critical infrastructure, in what The Bureau assesses is Canada’s leg of a broader Five Eyes campaign that, across 2024, disrupted both Chinese and Russian intrusions.

    The authority is disclosed in newly released reasons from Madam Justice Kane, who granted the warrant on May 1, 2024, and renewed it that August. Her reasons, dated February 2026, were made public only this week — more than two years after the warrant was first granted — after government lawyers applied significant redactions that stripped out the identities of the two foreign adversaries, along with other material they deemed national security secrets. That choice may itself invite scrutiny: the United States has openly attributed closely similar intrusions — and, in The Bureau’s assessment, likely part of the very same campaign — to Chinese state hackers, including the group known as Volt Typhoon.

    The Federal Court announced the decision Monday as the first judicial authorization permitting CSIS to use threat reduction measures to protect critical infrastructure from foreign adversaries.

    The ruling names no adversary. But its technical fingerprint, and its timing, place it squarely within an allied campaign that the United States made public through 2024 — a link the court itself invited, noting that the CSIS affiant pointed to a U.S. press release on disrupting cyber threats and to other Five Eyes governments being more open about botnet takedowns.

    The U.S. intelligence community calls the People’s Republic the “most active and persistent cyber threat” to American institutions, and the Office of the National Cyber Director has warned that Beijing seeks to “hold at risk U.S. and allied critical infrastructure.”

    Congressional researchers track three publicly disclosed Chinese state-sponsored groups under the “Typhoon” label Microsoft assigns to Beijing’s hackers: Volt Typhoon, which pre-positions inside American energy, water, communications and transportation systems to prepare for disruption rather than espionage; Flax Typhoon, tied to Chinese contractors and built on a botnet of more than 260,000 internet-connected devices that U.S. authorities disrupted in September 2024; and Salt Typhoon, linked to the 2024 compromise of American telecommunications carriers.

    It is the first two — Volt and Flax — that most closely fit the Canadian warrant. Volt Typhoon’s botnet was built largely on “end of life” Cisco and NetGear routers no longer receiving security patches — the very class of vulnerable hardware the Canadian court singled out — and served to pre-position against critical infrastructure, mirroring the ruling’s account of hijacked devices used as covert doorways into energy and government systems.

    Flax Typhoon’s botnet of internet-connected cameras and appliances, in turn, mirrors the court’s emphasis on compromised household devices. Together the two would explain the reference to two foreign adversaries as two distinct Chinese operations. But the phrase can also be read as two different states. Within weeks of each other in early 2024, the FBI disrupted both Volt Typhoon’s router botnet and a separate network of routers that Russia’s military intelligence, the GRU, had turned into a global espionage platform — leaving a Chinese-and-Russian pairing equally consistent with the timing. The Bureau cannot resolve which from the redacted reasons.

    What is on the record is that Canada is no bystander: the Communications Security Establishment’s cyber centre co-signed the Five Eyes advisories that named Volt Typhoon as a Chinese state-sponsored actor pre-positioning for disruption in the event of a crisis.

    It is the first application of its kind since Parliament created the threat reduction power in the 2017 national security overhaul. CSIS sought what the court called the Cyber Threat Reduction Measures Warrant because the steps required to dismantle the networks — altering, degrading and destroying data on infected machines — would, absent a judge’s order, amount to offences under the Criminal Code’s computer-mischief provisions.

    According to the ruling, the threat came from two botnets controlled by two foreign adversaries. A botnet is a network of compromised devices — in this case Canada-based servers, small office and home office routers, and Internet of Things hardware, the everyday objects the court listed as doorbell cameras, security cameras, televisions and other Wi-Fi appliances. Cyber actors seize control of these devices, the affiant explained, and operate them in two layers: a command-and-control tier that issues instructions, and a client tier of infected machines, or bots, that carry them out.

    The strategic danger, as the court described it, is concealment.

    By routing through hijacked Canadian devices, a hostile state can appear to be a legitimate connection — a service provider’s customer, an employee working from home — while probing critical infrastructure, military networks and government systems. The compromised devices become covert entry points, and the victimized owner can be made to look responsible for attacks they never launched. The court identified the energy sector among the targets, and warned that without the warrant the adversaries could direct their botnets to probe and potentially disrupt Canadian infrastructure.

    The judge was emphatic that the operation targeted machines, not their owners. CSIS would not seek the identity of any user, would intercept no content, and would destroy any personal information incidentally swept up.

    Two further legal dimensions deserve scrutiny. The warrant rested on internet protocol addresses CSIS had gathered without a warrant — a method the Supreme Court complicated in early 2024 when it held that Canadians have a reasonable expectation of privacy in an IP address. The Federal Court navigated the tension in a companion classified decision, finding the addresses were lawfully and non-intrusively collected and led only to devices, not people. And the warrant cleared the court cleanly, with a security-cleared lawyer appointed to probe the evidence and win a requirement that CSIS use the least intrusive means available.

    The court left the broader stakes in plain language. Without the warrant, it found, the foreign adversaries would regard Canada as an easy target to exploit.


  • June 16, 2026 10:51 AM | Anonymous

    Wesley Wark

    June 15

    An article by Professor Wark that covers "Beyond the Five Eyes”  and invites us to look past the familiar architecture of allied intelligence cooperation and consider the wider, evolving landscape of democratic security partnerships. As global threats grow more diffuse and technologically complex, the question is no longer whether the traditional Five Eyes framework remains vital—it does—but how like‑minded nations can extend its spirit of trust, interoperability, and shared purpose. This discussion challenges us to think about what comes next: the partners, principles, and capabilities that will define intelligence collaboration in the decades ahead.
    ---------------------------------------------------------------------------------

    Over the past 18 months, Canada has been busy laying the foundations for a much broader network of intelligence sharing arrangements, a diversification strategy that mirrors efforts in the economic domain. The intention is to lessen dependence on the US-dominated Five Eyes arrangement, especially at a time of rising uncertainty over the politicisation of US intelligence, without compromising Canada’s ongoing seven-plus decades relationship with the core four—US, UK, Australia and New Zealand.

     

    The general instrument for these new relationships is a bilateral treaty generally referred to as a “Security of Information Agreement,” which allows for protocols governing the sharing of classified intelligence and information. These agreements also facilitate economic opportunities in a variety of defence sectors, where the security of information must be maintained. Such treaty arrangements have been around for a long time, and the list of countries with which Canada has established bilateral security arrangements is long. It is dominated by ties with European countries, but includes one lone Middle Eastern state, Israel, one African country, South Africa, and two Latin American countries, Brazil and Chile. [1]

    What is notable about the recent push is the acceleration of treaty arrangements, the more explicit focus on intelligence sharing, and the way they have reached into the Indo-Pacific to include Japan and South Korea. No less than eight such arrangements have been entered into since December 2024, effectively since the coming of the new Trump administration in the U.S.

    The march began with an agreement reached with Ukraine, signed during a meeting of NATO foreign ministers in Brussels. [2] The accompanying news release noted that its signature reaffirmed Canada’s commitment to supporting Ukraine by “deepening bilateral security cooperation and increasing information sharing and defence collaboration between Canada and Ukraine.” [3]

    One recent example of how the agreement has facilitated industrial defence cooperation is the partnership forged between a Hamilton, Ontario- based drone manufacturer, Sentinel, and a Ukrainian company, Airlogix, to manufacture drones in Canada for the Ukrainian armed forces. [4]

    Next up was Poland, with an agreement signed in Warsaw on January 16, 2025. The Polish signatory was the head of Poland’s Internal Security Agency (ABW). The agreement was accompanied by official statements about its importance in facilitating new defence industrial partnerships in sectors such as aerospace, marine, nuclear and space, while “increasing information sharing and collaboration with Poland.” [5]

    Canada shifted to the Iberian peninsula for its next set of agreements, with Spain and Portugal, in September 2025. The General Security of Information Agreement with Spain was signed by Canada’s ambassador to Spain and by the Secretary of State for the Spanish National Intelligence Center (CNI). [6] The CNI is the central agency for Spanish intelligence activities and its mission includes promotion of “relations of cooperation and collaboration with other intelligence services.” [7] As the Canadian new release noted, the agreement will “provide the framework for the exchange of classified information with Spain, including defence intelligence as well as sensitive operational information and technical data related to weapons systems.” [8] A similar agreement was signed one week later with Portugal. [9]

    Two new agreements were signed with Indo-Pacific countries in early 2026, first with Japan and then with the Republic of Korea.

    A security of information agreement with Japan came into force on January 16, 2026. The Japanese Ministry of Foreign Affairs noted that “it is expected that this Agreement will ensure appropriate protection of classified information shared between the two governments and will promote further beneficial information exchanges.” [10] A broader “strategic roadmap” between the two countries was announced on March 6. Included in the roadmap were issues of defence collaboration including the desire to expand consultations on regional security threat assessments. [11]

    The negotiation with the Republic of Korea leading to an “Agreement on the Protection of Military and Defence Classified Information” were embedded in a wide-ranging statement on Foreign and Defence relations between the two countries. It was pitched as an agreement between middle powers drawing together, while facing a dangerous international environment. The joint Canada-Republic of Korea statement, issued at the Ministerial level on Febnruary 25, 2026, called attention to the threats posed by the Russian invasion of Ukraine and the role played by North Korea is supporting and assisting the Russian attack. It called for an enhanced partnership in the Indo-Pacific, and between the two countries’ militaries. It addressed frontier security issues of mutual concern with regard to cyber threats, rapid technological change, especially in AI, and challenges in the space domain. [12]

    The most recent in initiative in the Canadian campaign to sign classified information sharing protocols with foreign partners involved France. This was a product of a visit by the Prime Minister to France in advance of the G-7 meeting (chaired by France), now just underway. Prime Minister Carney, alongside French President Emmanuel Macron, announced a new “General Security of Information Agreement” with the twin purpose of creating stronger access for Canadian firms in the French defence market and enhancing the ability to “exchange classified information between Canada and France across defence, space, aerospace, cybersecurity, AI and maritime systems.” [13]

    France has long been thought of as a potential new partner if the FVEYs ever expanded beyond its current establishment. Such expansion seems unlikely in the moment, but a deepened bilateral intelligence relationship with France is a viable alternative, one that can be helped in its implementation by the appointment of the former National Security and Intelligence Adviser, Nathalie Drouin, as Canada’s ambassador to France.

    Make no mistake. This flurry of bilaterial treaty arrangements is an instrument of both economic and intelligence diplomacy expanding Canada’s reach into global defence markets and pools of national intelligence. The economic benefits are often extolled in public; the benefits of enhanced intelligence sharing generally muted by secrecy concerns.

    Some of the onus on making them work in practice will depend on the ability of the Canadian intelligence community to bring relevant information to the table and find ways of sharing to mutual benefit. The speed with which this will happen will vary across the new information arrangements, from fast with countries like Ukraine and France, to slower with states such as Portugal, where there is not much established practice of intelligence sharing. The most challenging element may well be the new arrangements with Japan and South Korea—involving countries with important access to intelligence in the Indo-Pacific, but where the practice of intelligence sharing is only nascent and where Canada has less to bring to the table.

    ------------------------------------------------------------

  • May 21, 2026 4:39 PM | Anonymous

    CSIS warns it can't keep pace with 'volume, velocity and variety of threats' without Bill C-22

    Catharine Tunney · CBC News · Posted: May 20, 2026 4:39 PM EDT

    Canada's spy agency says its ability to keep pace with threats and contribute to intelligence alliances will be at risk if the government's latest attempt to pass a lawful access bill fails — a warning that comes as momentum against the Liberals' Bill C-22 grows.

    "There is a moment that we need to meet as a country right now," Nicole Giles, deputy director of policy and strategic partnerships at the Canadian Security Intelligence Service (CSIS) said during a recent interview. 

    "Canada is the only Five Eyes country without a lawful access regime and that is hugely prohibiting our ability to keep pace with the increasing volume, velocity and variety of threats that are being thrown at us in an environment of incredibly rapid technological change and advances."

    Giles joined senior officials from Public Safety Canada and the RCMP on Wednesday for a briefing with CBC News to respond to growing concerns from civil liberty advocates, business groups, tech companies and senior U.S. lawmakers about the legislation. The same officials also spoke to other media, suggesting a concerted campaign to counter criticism. 

    The bill, this government’s second attempt at passing lawful access legislation since the federal election last spring,  promises to give police and spies faster access to information on Canadians during investigations — something they've been pushing for since the rise of the cellphone. 

    But the bill has garnered backlash from critics ranging from privacy and civil rights advocates to businesses and tech giants. 

    Most of the criticism has been directed at Part 2 of Bill C-22, which would require electronic service providers — a still undefined term that likely would mean telecommunication, internet and social media companies — to adapt their systems to make it easier to hand over requested information to security and intelligence officials, provided they have a warrant.

    Tech companies like Meta and Apple and messaging services including Signal have warned that this obligation would weaken privacy protections such as encryption, and would create pathways not only for police to lawfully access information, but also for hackers and foreign adversaries. 

    "If you are weakening encryption, if you're weakening the cybersecurity systems because you want to ensure that the good guys have access, the risk is that some of the bad guys can gain access as well," Michael Geist, the University of Ottawa’s Canada Research Chair in internet and e-commerce law, said last week in an interview with CBC about the bill. 

    "It's pretty hard to shut that door to everybody else."  

    CSIS opens up about 2 hindered operations

    Giles said there's "a misunderstanding" around the bill, which already includes a provision to prevent providers from creating systemic vulnerabilities. 

    "C-22 does not seek to mandate back doors or universal decryption capabilities by any stretch of the imagination," said Giles. "Rather, it is seeking to facilitate targeted, lawful and exceptional access under very strict legal controls." 

    In a rare move, Giles partially lifted the veil of secrecy and spoke about two real-life operations hindered by what the service sees as a lawful access regime in Canada. Given the classified nature of CSIS's work, most identifying information was left out.

    In the first case, Giles said the service was trying to determine the movements of a terrorist group. CSIS had obtained a warrant and was trying to trail the cellphone of a person of interest, but the electronic service provider did not have the capability to track the device because it isn't legally required to, she said. 

    "And so as a result, we had to resort to very costly and very risky in-person surveillance that also maintained significant gaps in our coverage," she said.

    Under Bill C-22, the government could require electronic service providers to develop and maintain location tracking capabilities.

    "These are not exceptional things," Giles said. "It would just bring us up to the basement that our allies and that our Five Eyes partners have."

    Citing another operation, Giles said a foreign partner carrying out an investigation outside of Canada contacted CSIS for help because a few of their subjects of interest were associated with Canadian phone numbers.

    The foreign player told CSIS their intelligence suggested threat activity was moving into Canadian territory, she said.

    Giles said CSIS was able to confirm that the phone numbers were obtained through a reseller, "however, resellers don't maintain records of their sales, and don't track any of their clients activities." 

    "So we were unable to respond to the foreign partners' request for information, which impedes our ability to ensure that we're performing as part of that intelligence collective of like-minded democracies," she said.  

    "We're also not able to get cited on the threat that's actually potentially in Canada."

    Concerns about metadata retention 

    Bill C-22 would also require core providers to retain metadata for up to one year. It wouldn't cover browsing history or the contents of messages, but it could include logs showing which telephone numbers a phone has been in contact with, and where someone carrying their device has travelled to.

    Geist described the metadata requirement as "essentially a surveillance map." 

    "It's building a massive haystack in the prospect that maybe you need to go find a needle at some point in the future," he said in an interview with CBC last week. 

    Sgt. Aaron Gilkes with the RCMP's technical investigation services defended the retention timeline, pointing by way of example to the rise of extortion cases in which victims are often first contracted by voice-over-internet protocol (VoIP).

    "Typically the bad guy is not going to use their regular telephone to make that phone call and have their own numbers show up," he said. "It's going to spoof a phone number."

    An investigator would try to trace the origin by going after what's known as signalling data — essentially information between devices and locations, Gilkes said.   

    "The issue with that is that that information that's contained in that signalling data is very ephemeral, very volatile. It only lasts about a week to 10 days," he said. 

    "So for us, these are the challenges that we face where we do know that some data does exist, we do know that it is kept for business purposes, but it's not kept long enough for us to be able to actually access it to forward our investigations."

    Possible amendments coming

    Public Safety Minister Gary Anandasangaree has suggested he's open to amendments. 

    "We don't want to make anybody less safe. That is entirely opposite of what we are trying to do," Richard Bilodeau, Public Safety Canada’s acting assistant deputy minister for the national and cybersecurity branch, said recently.  

    Bilodeau said officials are listening to concerns, especially those around end-to-end encryption. It's a communication method where data is encrypted on the sender's device and decrypted only on the recipient's device. 

    "It is one of those areas that we've taken careful note and we're seized with that issue," he said. "We'll see what direction we take on bringing clarity to the act on that point or any other." 


  • May 05, 2026 12:04 PM | Anonymous

    CSIS: same old, same old

    Or, let’s try something new

    Wesley Wark May 4, 2026

    The headline from the recent annual report from the Canadian Security Intelligence Service was…same old, same old. [i]

    · On-going foreign interference by the usual bad actors, China, India, Russia. (No mention of the U.S.A, or the potential national security threats posed by the Alberta separatist movement.)

    · On-going domestic violent extremism getting more complicated to detect and more ideologically scrambled, even zeroed out. In response, CSIS had to add a new category (alongside religious, ideological and political), “nihilistic violent extremism” (NVE).

    · Lots of foreign espionage directed against Canada, especially by Russia and by China. Someone at CSIS has a sense of humour, as they have nicknamed the Chinese intelligence services…wait for it, PRICS.

    · Attention continues to be paid by the Service to economic and research security and to the Arctic

    The annual report got some one-day coverage in some of the mainstream media (Globe and Mail, Global, National Post) but stirred no editorial attention at the Toronto Star or CBC. No political party jumped on it. No Parliamentary committee promised to study it. There was no statement from the Public Safety Minister or the PM.

    That’s life for CSIS—a fitful presence in the public consciousness, the same expansive menu of threats, the same high and unending workload. Fortunately for the Service, they escaped most of the government’s budget reduction scalpel/axe and are only required to cut back by 2%. This, we are told, they can manage without losing workforce, which is their engine.

    So, if there are no real surprises in the most recent edition of the CSIS Public Report, maybe we should turn to the question of changes that would allow CSIS not just to slog along, but to be a more effective, high-performance intelligence service operating for a middle power that wants to lead the world. Assuming, of course, that the threat environment is not going to turn sunny any time soon.

    To be that leading middle power in a broken international system, Canada needs more foreign intelligence, a lot more. To that end CSIS should be given a clear mandate (which would require a change to some of the oldest and untouched sections of the CSIS Act) to allow it to collect foreign intelligence in accord with the government’s intelligence priorities. This should become job #1 for CSIS.

    To free up resources and strategic bandwidth to become a foreign intelligence service, there are onerous functions that CSIS should be set free of. I would include in that list: security screening, immigration screening and national security review of foreign direct investment conducted as part of the Investment Canada Act.

    Whoa there, you say. Surely these are all important tasks. Absolutely, but CSIS is drowning in them. Have a look at the stats in the 2025 Public Report.

    CSIS received no less than 129,130 security screening requests in 2025.

    CSIS ingested 438,000 referrals for security screening of immigration files

    CSIS was involved in national security review under the ICA of 1106 investment proposals [ii]

    The CSIS work on security screening and immigration screening should be turned over to a new, separate agency tasked only with screening and able to apply specialised expertise and data tools, including AI (with a knowledgeable human in the loop). Call it, just to be fancy, Canada’s SAS, “Special Agency for Screening.”

    National security review of foreign investment should be part of a new, specialised and stand-alone economic intelligence agency which would work closely with the Department of Finance, Industry Canada, and Global Affairs Canada, but would be the government’s centre of expertise (we don’t have one on economic intelligence at the moment). Surely this idea would appeal to you know who…

    While we are at it, axe the ITAC (now reverted to its original 2004 name as Integrated Threat Assessment Centre). Redeploy its analytic assets primarily to Public Safety and, for the relatively recent ITAC mission of detecting threats to politicians, to the RCMP (where it belonged in the first place).

    Get CSIS out of cyber security and enforce a no duplication rule with the federal government’s lead on cyber security, which is the Communications Security Establishment.

    In this very new-look CSIS hen house, foreign intelligence would rule the roost. That’s the way it should be in future. And yes, we would need to make sure that the RCMP could truly handle the intelligence collection, analysis and law enforcement mission required by domestic threats and violent extremism.



    [i] Canadian Security Intelligence Service, Public Report 2025, May 1, 2026, https://www.canada.ca/content/dam/csis-scrs/images/2025/public-report/Public%20Report_EN_2025_DIGITAL.pdf




  • May 04, 2026 10:49 AM | Anonymous

    Neil Bisson, President of the Ottawa-Gatineau Chapter of the Pillar Society and Director of the Global Intelligence Knowledge Network, recently spoke with Jeremie Charron of CTV News to discuss findings from the latest Canadian Security Intelligence Service Annual Report.

    A key concern highlighted in the report is the increasing involvement of youth in counter-terrorism investigations. According to CSIS, 1 in 10 such investigations now involves individuals under the age of 18, with some as young as 13.

    In the interview, Neil outlines how online environments—driven by constant connectivity, algorithmic exposure, and peer-driven influence—are creating conditions where vulnerable and impressionable youth can be targeted and radicalized by extremist actors.

    This emerging trend underscores the need for greater awareness across communities, including parents, educators, and policymakers.

    The interview starts at the 9 minute mark:

    https://www.youtube.com/watch?v=CpWM6zet5S0

  • May 01, 2026 3:25 PM | Anonymous

    The SOUFAN Center - IntelBrief

    Wednesday, April 22, 2026

     

     

    Bottom Line Up Front

    • The Iran War has renewed a global focus on energy security and supply chain chokepoints, and increased Russian and Chinese activities in the Arctic is accelerating the focus on exploration in the High North.
    • Antarctica remains an overlooked frontier where strategic competition is quietly taking shape, and the People’s Republic of China (PRC) is making inroads that could bear fruit in the future.
    • The PRC’s growing infrastructure, technological innovation, data collection, and logistical capabilities are framed as scientific exploration, but may have other dual-use advantages.
    • PRC activities in Antarctica could enable Beijing to secure early-mover advantages should the treaty system currently governing the region weaken in the coming decades.

     

     

    The Iran War has renewed a global focus on energy security and supply chain chokepoints — from the Strait of Hormuz to the Malacca Strait. In addition, increased Russian and Chinese activities in the Arctic, along with U.S. President Donald Trump’s posturing around Greenland, are accelerating the focus on exploration and militarization in the High North, including use of the Northern Sea Route for shipping as well as exploration of oil, gas, and mineral deposits. Taken together, this has intensified the geopolitical competition for resources, energy security, and frontier exploration. Antarctica, however, remains a frequently overlooked frontier where strategic competition is quietly taking shape, and the People’s Republic of China (PRC) is making important inroads that could pay dividends down the line. 

    Antarctica is governed by the Antarctic Treaty System (ATS), established in 1959, which designates that the continent should be used only for peaceful and scientific purposes. The ATS explicitly prohibits “any measures of a military nature, such as the establishment of military bases and fortifications, the carrying out of military maneuvers, as well as the testing of any type of weapons.” The ATS, via the 1991 Protocol on Environmental Protection (commonly referred to as the Madrid Protocol), also regulates the extraction of resources: “any activity relating to mineral resources, other than scientific research, shall be prohibited.” There are currently 29 consultative parties to the ATS and 29 non-consultative parties. In order to be recognized as a consultative party and thus be privy to decision-making, the country must be “conducting substantial research activity” on the continent. The PRC obtained its consultative status in 1985. 

    Apart from the restrictions included in the ATS, the conditions of Antarctica have historically presented constraints on opportunities for economic and military activity. With over 98 percent of Antarctica currently ice-covered, the inaccessibility — coupled with the harsh climate and limited infrastructure — has rendered scale and cost efficiency of permanent human settlement and industrial development extremely difficult. Climate change may, however, change that in the future. The continent is believed to hold significant resource deposits, including copper, iron, gold, silver, platinum, and cobalt. A 2026 study published in the scientific journal Nature Climate Change suggests that Antarctica may hold between 12-25 million metric tons of copper deposits. Some estimates suggest 500 billion tons of oil and 300-500 billion tons of natural gas may exist on the continent. As Dr. Anne-Marie Brady, an expert on Antarctica and Chinese foreign policy stated: “Many oil-poor states regard Antarctica’s potential mineral resources as part of the solution to their medium-term energy needs.” As the ice melts, more land may become available for mineral and resource exploration. And by 2048, any consultative party to the ATS can request to hold a conference to review the Protocol currently prohibiting non-scientific activity of mineral resources, effectively calling into question the long-term durability of the ATS amidst intensifying strategic competition and the exploration for resources. 

    Yet, real challenges for future commercial mineral exploration remain, including viable transportation and permanent commercial infrastructure — which could be solved with scientific and technological advancements. A more immediate important resource in Antarctica is related to fisheries and krill. Krill is a cornerstone of the Antarctic ecosystem, but it is also important for aquaculture feed and pet food, as well as the production of human supplements like Omega-3. 

    In addition, the continent is valuable for its environment, which can be utilized for scientific research, but it can also be utilized for satellite ground systems, radio and space weather monitoring, as well as potential signal intelligence-related capabilities. As such, PRC activity in Antarctica has increased in the 21st century. The PRC currently has three permanent research stations (ChangCheng, Zhongshan, and Qinling), two seasonal stations (Kunlun and Taishan), while planning for another seasonal station, likely in 2027. When completed, it would become the fourth Chinese station established in Antarctica over the last two decades. The Chinese Communist Party (CCP) has a stated goal of being a “polar great power” by 2030 and has, to this end, invested heavily not only in technology and infrastructure, such as icebreakers — leading it to outpace the U.S. fleet — and satellites, but also on diplomacy and governance norms to expand its influence in the Arctic and Antarctica. 

    While much of the PRC’s activity in Antarctica, since first setting foot there in December of 1984, has been scientific in nature — ranging from meteorology and geomagnetism to marine hydrology — there are concerns that some activities may be employing dual-use technology. The 2022 U.S. Department of Defense report on Military and Security Developments involving the PRC assessed that Beijing’s strategy for Antarctica “includes the use of dual-use technologies, facilities, and scientific research, which are likely intended, at least in part, to improve PLA [the People’s Liberation Army] capabilities.” The report noted that ChangCheng, Zhongshan, Kunlun, and Taishan can operate as reference stations for Beijing’s BeiDou satellite navigation network (the PRC alternative to the U.S. GPS system). The Center for Strategic & International Studies (CSIS) noted in a 2023 report that the Qinling research station will also include a satellite ground station that can be dual-use, and that the “station’s position may enable it to collect signals intelligence from U.S.-allied Australia and New Zealand and could collect telemetry data on rockets launching from newly established space facilities in both countries.” 

    The U.S. continues to monitor Antarctic developments — including a January 2026 inspection of the Zhongshan station under the ATS — and cooperate with allies such as Australia and New Zealand. However, uncertainty about budget cuts that may impact U.S. scientific operations in Antarctica could place a heavier burden on U.S. allies. The PRC appears to operate with the understanding that a sustained physical presence and scientific leadership in Antarctica will be the primary currency of influence. This is positioning Beijing not only to possess infrastructure and data capabilities in the future, but also to carry diplomatic weight to influence any future governance norms of the continent. Specifically, should the treaty regime weaken over the next two decades, the PRC will seek to position itself to secure early-mover advantages.

    https://thesoufancenter.org/intelbrief/


<< First  < Prev   1   2   3   4   5   ...   Next >  Last >> 



The Pillar Society Privacy Policy and Terms of Service | © Copyright 2025 The Pillar Society | All Rights Reserved