Canada did not issue a new legal or diplomatic designation called “cyber threat adversary.” In its National Cyber Threat Assessment 2025–2026, published October 30, 2024, the Canadian Centre for Cyber Security placed India in the report’s section on cyber threats from state adversaries. It assessed that Indian state-sponsored actors likely conduct espionage-related activity against Canadian government networks and that strained bilateral relations will very likely drive such activity. India rejected the assessment as unsupported.
What Canada published—and what “adversary” means
The Canadian Centre for Cyber Security, part of the Communications Security Establishment (CSE), published its National Cyber Threat Assessment 2025–2026 on October 30, 2024. Its information cut-off was September 20, 2024. The assessment considers threats to people, organizations and governments in Canada and forecasts developments through 2026.
India appears in Section 1, “Cyber threat from state adversaries,” alongside China, Russia, Iran and North Korea. The report also has sections on cybercrime and trends shaping Canada’s cyber threat landscape. “State adversary” is an analytical category in this assessment, not a formal legal designation, sanctions decision or diplomatic notice. The phrase “Canada names India a cyber adversary” is shorthand for India’s inclusion in that section.
The report does not claim that every cyber incident involving an India-linked person or group was directed by the Indian government. Nor does it disclose a public catalogue of specific Indian operations against Canada. Its statements are intelligence judgments: the report explains that “we assess” and “we judge” introduce analytic assessments, while terms such as “likely” and “very likely” express probability and confidence. CSE says its conclusions draw on classified and unclassified reporting, but the public report does not reveal all underlying intelligence.
Windows Errors? Fix Them Before They Spread
Repair common Windows errors and clear accumulated junk for a smoother, more stable PC - no reinstall needed.Free scan · no reinstallCrashes, No Sound, or Screen Glitches?
Random freezes, missing sound and display glitches usually trace back to one bad driver. Find and replace yours safely.Free scan · under a minuteWhat CSE assessed about India
CSE’s judgments describe both India’s cyber ambitions and the activity it expects to affect Canada. The report says India’s leadership almost certainly aspires to build a modernized cyber program with domestic capabilities. It assesses that India very likely uses cyber capabilities to advance national-security objectives, including espionage, counterterrorism, promoting India’s global status, and countering narratives about India and its government. It also says India’s cyber program likely uses commercial cyber vendors to enhance operations.
#1 Best Overall
The Canada-specific judgment is narrower: Indian state-sponsored cyber actors likely conduct cyber activity against Government of Canada networks for espionage. CSE further judges that official bilateral relations will very likely drive Indian state-sponsored cyber activity against Canada. These are probabilistic assessments attributed to CSE, not public technical disclosures of a particular intrusion.
Why bilateral tensions are part of the assessment
The report explicitly connects deteriorating relations with expected cyber activity. The diplomatic rupture had roots in September 2023, when then-Prime Minister Justin Trudeau said Canadian intelligence had evidence of a possible link between Indian government agents and the killing of Sikh activist Hardeep Singh Nijjar in British Columbia. India rejected Canada’s allegations. The dispute was followed by reciprocal diplomatic expulsions and continuing accusations involving foreign interference, surveillance, criminal activity and alleged support for separatist or extremist groups.
The cyber assessment was issued amid that wider confrontation. Its forecast that bilateral relations would drive cyber activity does not establish that the report itself was retaliation, or that a particular cyber operation followed from a specific diplomatic event. It identifies worsening relations as a factor in the threat outlook.
India is not described as Canada’s top cyber threat
India’s inclusion is politically significant, but the report does not rank it above China or characterize it as Canada’s dominant state cyber threat. The Canadian government described China as the most sophisticated and active state cyber threat facing the country. The assessment presents China’s cyber program as the most comprehensive, involving espionage, intellectual-property theft, malign influence and transnational repression. It also discusses Russia and Iran as significant threats with different objectives, as well as North Korea.
So the report’s message is not that India poses the greatest cyber danger to Canada. It adds India to the state-threat picture and makes a specific forecast about likely espionage against government networks in the context of bilateral tensions.
Rank #3
State-sponsored espionage is distinct from India-aligned hacktivism
A separate CSIS public report said Canada observed low-sophistication cyber activity by India-aligned non-state actors after relations deteriorated. CSIS explicitly said it had no indication that the Government of India was responsible for those particular incidents.
That distinction matters: CSE’s assessment concerns likely state-sponsored espionage against government networks; CSIS’s observation concerns activity by non-state actors described as aligned with India. The public statements do not establish that those actors were controlled by New Delhi, and the espionage judgment should not be recast as an accusation of ransomware, destructive attacks or attacks on civilian infrastructure.
India’s response
India’s Ministry of External Affairs acknowledged that Canada had placed India in the report’s “Cyber threat from state adversaries” section. In a response recorded in the Indian Parliament, the ministry called the report another example of Canada’s “negative approach” to bilateral relations and said imputations had been made without evidence.
Rank #4
The ministry also alleged that Indian consular officials in Vancouver had been told they were under audio and video surveillance and that private communications had been intercepted. It said India protested through diplomatic channels and described the alleged conduct as incompatible with diplomatic norms. These are India’s claims; the cited public response does not independently establish them.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.What the assessment means for Canadians and organizations
The India-specific judgment is primarily about espionage risk to Canadian government networks, not a warning that ordinary Canadians face a newly identified consumer threat. The assessment separately identifies financially motivated cybercrime and ransomware as the threats most likely to affect people and organizations generally.
Best Value
For organizations and communities with relevant exposure, the report’s implications are more targeted:
- Government and diplomatic networks: Sensitive accounts and information may be of interest for espionage, particularly during periods of strained relations.
- Officials, researchers, activists and diaspora communities: The broader concerns described by Canadian security agencies include possible surveillance or intimidation of dissidents and political opponents abroad. This is a risk context, not proof that a specific person has been targeted.
- Organizations holding sensitive data: Phishing and credential theft are practical routes to access accounts and information. Organizations supporting government, diplomatic or research work should apply their normal security controls to high-value accounts and data.
- Public discussion during a crisis: Influence activity and counter-narrative efforts can accompany political tensions. A group acting in sympathy with a government is not, by that fact alone, shown to be under state direction.
CSE’s statement that India likely uses commercial cyber vendors does not by itself establish a particular spyware campaign against Canadians. The report’s India-specific public judgment remains focused on likely espionage against Canadian government networks.
Quick Recap
What the report does—and does not—establish
- It establishes Canada’s public assessment: CSE placed India in its state-adversary section and assessed likely state-sponsored espionage-related activity against Canadian government networks.
- It links the forecast to diplomacy: CSE judged that official bilateral relations would very likely drive such activity.
- It does not make a legal designation: The section label is not itself a sanctions measure or diplomatic action.
- It does not provide a public incident file: The assessment does not disclose all intelligence behind its judgments or identify a detailed set of specific Indian cyber incidents.
- It does not say India is Canada’s leading cyber threat: Canada identifies China as its most sophisticated and active state cyber threat.
- It does not establish direct state control of all India-aligned activity: CSIS said it had no indication the Indian government was responsible for the low-sophistication non-state incidents it observed.
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




