← All news

general

CSIS Got a Warrant to Clean Strangers' Routers

2026-06-22

Canada's Security Intelligence Service has done something it had never done before. It walked into Federal Court, asked a judge for permission to reach into infected servers, home routers, doorbells and smart TVs sitting in Canadian living rooms, and quietly clean them. The court said yes. The public version of the ruling landed on 15 June.

The target was two foreign-run botnets, both built on the familiar pattern of a command tier issuing orders while a layer of hijacked consumer gear relays the traffic. Routing a state-backed operation through a Canadian Ring doorbell or a forgotten SOHO router is convenient camouflage. The attacker looks like an ordinary broadband customer while poking at energy grids, government systems and military networks. The doorbell's owner gets to look responsible for traffic they never sent.

What the court actually approved

Justice Catherine Kane granted the original warrant on 1 May 2024 and renewed it that August. Without judicial sign-off, CSIS reaching into someone's router and wiping data would sit squarely inside the Criminal Code's definition of computer mischief.

The court found:

  • the threat was clearly established
  • the response was proportional
  • the operation went after devices, not people

No identities were sought. No content was intercepted. Incidental personal data picked up along the way was destroyed.

An intelligence-service version of an FBI move

The shape will look familiar to anyone who followed the FBI cleanups of late 2023 and early 2024: one against the China-linked Volt Typhoon crew squatting on end-of-life Cisco and NetGear boxes, the other against GRU-operated Ubiquiti routers. The Canadian version swaps law enforcement for an intelligence service drawing on the threat reduction powers written into the CSIS Act and reworked in 2019.

The Bureau, which surfaced the ruling, says the redactions make it impossible to tell whether Canada's two botnets were both Chinese, both Russian, or one of each. The court's reasoning suggests it didn't particularly matter to the legal question.

The bit a warrant can't fix

None of these cleanups touch the underlying problem. The malware comes off. The weakness stays. A factory reset or even a power cycle can undo the work and let the same gear get reinfected before the end of the day.

The botnets thrive on the kit nobody maintains. Routers past their support date. IoT gadgets running firmware from three years ago. Default credentials still in place. Management panels facing the open internet because somebody, once, needed to log in from the cottage.

A judge can authorise a one-off scrub. Keeping dead hardware off the network is still the owner's job, and the owner, in most cases, has no idea their doorbell has been moonlighting for a foreign intelligence service.

CSIS Got a Warrant to Clean Strangers' Routers | RiskSense