File C-6-24

Coat of Arms

Ottawa, June 15, 2026 – The Honourable Catherine Kane of the Federal Court issued a public version of the confidential Reasons today in file C‑6‑24:

IN THE MATTER OF AN APPLICATION BY XXXX FOR WARRANTS PURSUANT TO SECTIONS 12.1 AND 21.1 OF THE CANADIAN SECURITY INTELLIGENCE SERVICE ACT, RSC 1985, C C-23
and
IN THE MATTER OF CYBER ESPIONAGE, CYBER SABOTAGE, CYBER FOREIGN-INFLUENCED ACTIVITIES and MALICIOUS BOTNETS

Summary: Although the Canadian Security Intelligence Service Act, RSC 1985, c C-23 [CSIS Act] has provided for the issuance of warrants for threat reduction measures [TRM] for several years, this is the first application of its kind. The application was filed on April 24, 2024, pursuant to sections 12.1 and 21.1 of the CSIS Act seeking warranted powers to reduce the threat to critical infrastructure posed by foreign adversaries as a result of the infection of certain devices with malicious software, known as malware [the Cyber Threat Reduction Measures Warrant or the TRM warrant].

The Court issued the Cyber Threat Reduction Measures Warrant on May 1, 2024, upon considering the evidence of the affiant, and the submissions of the Attorney General of Canada and the amicus curiae appointed by the Court, and upon finding that the requirements of section 21.1 were met, including that the threat to the security of Canada was clearly established and imminent and that the warranted powers were necessary to reduce the threat. The warrant was first granted for a period of 120 days. On August 29, 2024, the Court renewed the Cyber Threat Reduction Measures Warrant for a further 120 days. The Court undertook to provide brief Reasons for granting the initial application at a later date. The confidential reasons were issued on February 26, 2026.

CSIS sought the warranted powers to protect critical infrastructure from foreign adversaries that have infected Canada-based servers, small office or home office [SOHO] routers and Internet of Things [IoT] devices (which would include everyday objects that can connect to the Internet, such as “Ring Doorbells”, security cameras, televisions, or other Wi-Fi enabled appliances) with malware. The malware causes these servers, routers, and devices to operate as a network of infected devices, referred to as a “botnet”. All types of devices, SOHO routers, and IoT devices can become vulnerable to cyber attack and can become part of a botnet, in particular, devices that are “end of life” and cannot be updated and those that have not updated their software when reminded to do so.

CSIS required the Cyber Threat Reduction Measures Warrant because the necessary threat reduction measures to neutralize the botnets, which are targeted at the devices, would likely constitute offences pursuant to the Criminal Code, RSC 1985, c C-46 [Criminal Code] and, as such, require judicial authorization in accordance with subsection 12.1(3.4) of the CSIS Act.

The Court was satisfied that the actions of two foreign adversaries constituted a threat to the security of Canada, that there were reasonable grounds to believe that the warrant was required to reduce this threat and that the specific measures as described were necessary, reasonable, and proportional in the circumstances. These measures were directed against devices, not persons; no identifying information, personal information or other content was collected.

The decision is posted on the News Bulletins page of the Federal Court website.

This is a Modal Popup Form