Canada's Spy Agency Uses First-of-Its-Kind Warrant to Clean Botnet-Infected Devices

A Federal Court ruling lets Canada's intelligence service reach into infected routers and IoT gear to neutralize two foreign-run botnets — a new regulatory precedent for intelligence-agency-led botnet-cleanup operations.

Share
Flat white line-art of a warrant document beside a small mesh of device nodes and a neutral shield — Canada first-of-its-kind botnet-cleanup warrant.

Key Takeaways

  • Canada's Federal Court released a public version of a ruling on June 15, 2026 confirming that the Canadian Security Intelligence Service (CSIS) obtained a warrant — the first time it has used its threat-reduction-measures powers this way — to remotely alter, degrade, and destroy malware on devices infected by two foreign-run botnets sitting on Canadian soil.
  • The warrant, granted by Justice Catherine Kane on May 1, 2024 and renewed that August, authorized CSIS to disinfect Canada-based servers, small office and home office (SOHO) routers, and Internet of Things devices such as doorbells, security cameras, and televisions, without seeking user identities or intercepting content.
  • The case establishes an intelligence-agency-led model for court-ordered botnet cleanup that parallels earlier law-enforcement operations in the United States, while leaving open questions about device-owner notification and the warrantless collection of IP addresses that informed the application.

A Federal Court ruling lets Canada's intelligence service reach into infected routers and IoT gear to neutralize two foreign-run botnets — a new regulatory precedent for intelligence-agency-led botnet-cleanup operations.

OTTAWA — Canada's domestic intelligence service obtained a judge's permission to reach into infected servers, home routers, and Internet of Things devices on Canadian soil and neutralize two foreign-run botnets, according to a Federal Court ruling whose public version was released on June 15, 2026. The Canadian Security Intelligence Service (CSIS) described the move as a first-of-its-kind use of its threat-reduction-measures authority, marking the first time the agency has reached for that power to actively disinfect compromised devices rather than merely collect intelligence on the threat.

The warrant let CSIS alter, degrade, and destroy botnet data on the infected machines and cut the devices loose from the networks controlling them. The targets were Canada-based servers, small office and home office (SOHO) routers, and Internet of Things gear — doorbells, security cameras, televisions, and other Wi-Fi-enabled appliances — that two foreign states had quietly conscripted as relays. The ruling lands less as a breach story than as a law-enforcement and policy milestone: a court signing off on a spy agency remotely touching private hardware to clean it up.

At a Glance
FieldDetails
AgencyCanadian Security Intelligence Service (CSIS)
ActionRemote disinfection of botnet-infected devices
Legal authorityThreat-reduction-measures warrant under the CSIS Act (as reworked in the National Security Act, 2017)
BotnetNot specified — two foreign-run botnets; operator identities redacted
DevicesNot specified — Canada-based servers, SOHO routers, and IoT devices
PrecedentFirst-of-its-kind CSIS use of threat-reduction-measures powers for botnet cleanup
StatusWarrant granted May 1, 2024; public ruling released June 15, 2026

What Was Disclosed

The Federal Court of Canada released a redacted, public version of its reasons on June 15, 2026, more than two years after the underlying order. According to the ruling, Justice Catherine Kane granted the warrant on May 1, 2024, renewed it that August, and issued her confidential reasons in February 2026. The document had stayed out of public view until this month's release. It is the first time CSIS has used its threat-reduction-measures warrant powers to remotely disinfect compromised devices.

The warrant authorized CSIS to alter, degrade, and destroy botnet data on infected machines and to sever those devices from the networks issuing them commands. The targets were Canada-based servers, SOHO routers, and Internet of Things devices including Ring-style doorbells, security cameras, and televisions. The court stressed that the operation went after devices, not people: it sought no user identities, intercepted no content, and required that any personal data swept up incidentally be destroyed. CSIS needed the order in the first place because the cleanup would otherwise likely have been a crime — reaching into someone else's device and wiping data is computer mischief under Canada's Criminal Code.

The court found the threat to Canada clearly established and imminent, and the measures necessary, reasonable, and proportional. The two botnets ran a standard relay playbook: a command tier issued orders while a layer of infected devices relayed the traffic, letting a foreign state route through hijacked Canadian hardware to look like an ordinary home connection while it probed critical infrastructure, government, and military networks. The court flagged the energy sector among the potential targets. Notably, the public ruling settles the what — two foreign adversaries, a threat the court found clearly made out — but strips the who: the operator identities are redacted, and reporting that surfaced the ruling could not determine from the redacted reasons whether the two botnets were both Chinese, both Russian, or one of each. Neither the specific botnet names nor a device count appears in the public record.

The Regulatory-Precedent Implications

The legal mechanism is what makes this case a precedent rather than a routine takedown. CSIS acted under its threat-reduction-measures (TRM) authority — the power to actively disrupt a threat rather than simply gather intelligence on it. That authority was written into the CSIS Act years ago and reworked in the National Security Act, 2017, which took effect in 2019, but the agency had never reached for it in this way until now. A botnet cleanup is a long way from the kinds of disruption the power was first imagined for, and the court's willingness to authorize remote modification of private devices establishes a template that future applications can cite. It sits alongside a broader run of coordinated takedown operations that have steadily expanded what authorities are willing to do to compromised consumer hardware.

Equally significant is the judicial framing. By insisting the operation target devices and not people, decline to seek user identities, and destroy incidentally collected personal data, the court built a privacy-protective scaffold around an inherently intrusive act. That scaffold is itself a precedent: it signals the conditions under which a Canadian court will permit an intelligence service to act on private hardware, and it gives future applicants a checklist of safeguards to mirror. For an agency whose default mode is collection rather than intervention, having a court bless a tightly bounded disruption operation lowers the institutional and legal risk of doing so again.

The proportionality finding matters too. The court did not treat the warrant as a blank cheque; it weighed the threat — foreign states routing through Canadian devices to probe critical infrastructure, including the energy sector — against the intrusion and found the measures necessary and proportional. That reasoning becomes the yardstick against which the next intelligence-led cleanup will be measured, and it establishes that the severity of the underlying threat, not merely the convenience of acting, is what justifies reaching into private machines.

How Parallel Actions Might Emerge in Other Jurisdictions

The closest precedents come from the United States, where the shape of the operation is familiar but the authority is different. In a December 2023 operation, the FBI used a botnet's own command channel to delete the KV-botnet malware from hundreds of U.S. SOHO routers — mostly end-of-life Cisco and NetGear boxes that the China-linked Volt Typhoon had been using to hide pre-positioned access inside American communications, energy, water, and transportation systems. Weeks later, U.S. authorities ran a near-identical operation against a network of Ubiquiti routers that Russia's GRU, the APT28 group, had turned into an espionage relay. Those operations echoed the cross-border enforcement actions that have become a defining feature of state-aligned cybercrime response.

The distinction is who holds the warrant. The U.S. operations were law-enforcement actions — the FBI and Department of Justice acting under search-and-seizure authority. Canada's is an intelligence service acting under threat-reduction powers. That difference shapes how parallel actions might emerge elsewhere: jurisdictions whose intelligence agencies hold active-disruption mandates now have a worked example of using them for device cleanup, while those that rely on law enforcement have the U.S. model. Either route requires a court willing to authorize remote modification of private hardware, and the Canadian ruling demonstrates that the intelligence-led path can clear that bar.

For allied governments watching, the case also reinforces a shared operational pattern: neglected consumer gear, a state operator hiding behind it, and a judge signing off on remote disinfection. Canada's cyber centre had already joined allied warnings about state actors abusing SOHO and IoT devices, so the underlying threat picture is common across the Five Eyes and beyond. What the Federal Court added is a concrete legal pathway, and concrete pathways are what other jurisdictions tend to borrow when they confront the same problem. The likeliest near-term effect is not a wave of identical warrants but a set of legal teams able to point to a peer democracy that found a way to do this lawfully.

Open Questions

Several threads remain unresolved. The most consequential is whether device owners were ever told that an intelligence agency had reached into their hardware. The public ruling does not close that question, and the answer carries weight for any jurisdiction weighing a similar approach: an effective cleanup that leaves owners unaware does nothing to stop reinfection. In the U.S. operations, the malware came off but the underlying weaknesses stayed, and a reboot or factory reset could undo the fix. Retiring dead hardware and locking down what remains falls on the owner, not the agency that cleaned up after them — which means the durability of any such operation depends on a notification-and-remediation step the public record here does not describe.

A second open question concerns the inputs to the application itself. By one account, the warrant request leaned on IP addresses that CSIS had collected without a warrant, weeks after the Supreme Court of Canada held in R. v. Bykovets that an IP address carries a reasonable expectation of privacy. Whether that collection squares with CSIS's authorities is not settled in the public reasons, and it is precisely the kind of issue a future challenge — or a future applicant in another country — would have to confront. The precedent the ruling sets is therefore partial: clear on the disruption power, less clear on the collection that feeds it.

Finally, the redactions leave the threat attribution unresolved in public. The court found a foreign-state hand and an imminent threat to Canada, but stripped the operators' identities, so the public cannot confirm which states ran the two botnets. This piece reflects a single primary ruling and the reporting around it; the specific botnet names and the number of devices cleaned are not disclosed, and the attribution beyond a general foreign-state finding remains, on the public record, a redaction rather than a confirmed fact. What is established is enough to mark the moment: a Western intelligence service has, for the first time, won a court's permission to remotely clean privately owned devices — and in doing so has set a precedent the rest of the field will study.


The CyberSignal Analysis

The reported facts above come from the Federal Court's public ruling and the reporting around it; what follows is The CyberSignal's editorial reading of what defenders and policymakers should take from them. None of the judgments below are new reported facts.

Signal 01 — Intelligence-Agency Cleanup Is a New Precedent, Not Just a New Warrant

The headline is not that a botnet got cleaned but who did the cleaning and under what power. Earlier device-cleanup operations were law-enforcement actions run under search-and-seizure authority; here a domestic intelligence service reached into private hardware under a threat-reduction mandate whose default mode is collection, not intervention. Our reading is that this reclassification matters more than the operation itself, because it opens a second lawful pathway to remote disinfection — one available to agencies that were never framed as enforcers.

That distinction travels. Jurisdictions whose spy services hold active-disruption mandates now have a worked example they can cite, and the institutional risk of a first-of-its-kind operation drops sharply once a peer democracy has done it and survived judicial scrutiny. We would expect the near-term effect to be quiet borrowing by legal teams rather than a visible wave of identical warrants.

The most defensible criticism of an operation like this is not that it is intrusive but that it may be incomplete. A cleanup that removes malware without telling the device owner leaves the underlying weakness in place, and a reboot or factory reset can undo the fix. Our assessment is that the durability of any intelligence-led cleanup hinges on a notification-and-remediation step the public record here does not describe — the agency wipes the infection, but retiring dead hardware and closing the hole that let it in still falls on an owner who may never learn any of this happened.

There is a privacy dimension to the same gap. The court built a device-not-people scaffold — no user identities sought, incidental personal data destroyed — but that scaffold is precisely what makes silent, owner-unaware intervention legally comfortable. We read the unresolved notification question as the pressure point a future challenge, or a future applicant abroad, will have to answer before this model generalizes.

Signal 03 — Other Jurisdictions Will Follow the FBI and Dutch Model, Now With a Canadian Variant

The operational template is by now familiar across allied governments: neglected consumer gear, a state operator hiding behind it, and a judge signing off on remote disinfection. What the Federal Court added is not a new tactic but a new legal route to the same tactic, and concrete legal routes are what other jurisdictions borrow when they face the identical problem. Our expectation is that the Canadian ruling becomes a citation, sitting beside the U.S. law-enforcement precedents as the intelligence-led alternative.

The forward-looking watch item is which route a given country takes. Governments that rely on law enforcement have the FBI and Dutch examples; those with disruption-capable intelligence services now have Canada's. Either path still requires a court willing to authorize remote modification of private hardware, so the binding constraint remains judicial appetite, not the absence of a model — and this ruling has removed one of the last excuses that no peer had tried it.


Sources

TypeSource
PrimaryFederal Court of Canada — File C-6-24 (public ruling)
ReportingThe Hacker News
BackgroundGovernment of Canada — Amendments to the CSIS Act: Threat Reduction Measures
RelatedThe CyberSignal — Europol Operation Endgame 2.0
RelatedThe CyberSignal — Dutch Politie / NCSC AsockS residential-proxy takedown
RelatedThe CyberSignal — FBI / Google Outsider China cybercrime network takedown