ClearGlass Intelligence Desk · UNCLASSIFIED / PUBLIC · 18 September 2026

When the Court Lets an Intelligence Service Reach Into a Router

CSIS, two foreign-operated botnets, Canadian SOHO routers and IoT devices — and the architectural boundary between protecting national infrastructure and touching somebody else's machine.

Burlington, Ontario · Cyber intelligence / critical infrastructure · Evidence-led analysis · No client names · No operational targeting guidance

Evidence status: The factual core of this article is anchored to the Federal Court's public bulletin for File C-6-24, published 15 June 2026. The Court says this was the first application of this kind under the CSIS Act. The warrant was issued 1 May 2024, renewed 29 August 2024, and confidential reasons were issued 26 February 2026. This article separates what the Court publicly established from ClearGlass analytical inference. It is not legal advice.
CASEFederal Court File C-6-24
AUTHORITYCSIS Act ss. 12.1 and 21.1
PUBLIC RECORDPublic reasons released 15 June 2026
DEVICESServers · SOHO routers · IoT
TARGETBotnet infrastructure, not named people
THREATForeign cyber activity affecting Canadian critical infrastructure

Executive finding

The important fact is not simply that Canada's intelligence service received a warrant to interfere with malware. It is that the Federal Court authorized a threat-reduction operation whose technical objects were Canadian devices: servers, small-office/home-office routers and Internet-connected devices such as security cameras, televisions and doorbells.

The Court's public summary says the devices had been infected with malware and were operating together as a botnet. The botnets were associated with two foreign adversaries. The Court found the threat to Canada's security clearly established and imminent and concluded that the specified measures were necessary, reasonable and proportionate. The measures were directed against devices rather than persons, and the Court states that no identifying information, personal information or other content was collected.

That creates a consequential security architecture lesson: a device can be physically owned by a Canadian household or business while, from a national-security perspective, functioning as foreign-controlled relay infrastructure. Ownership, intent and network role can diverge.

What the Federal Court actually said

The public Federal Court bulletin is the primary source for the case. It identifies the application as involving cyber espionage, cyber sabotage, cyber foreign-influenced activities and malicious botnets. The application was filed on 24 April 2024. The Court issued the Cyber Threat Reduction Measures Warrant on 1 May 2024 for 120 days and renewed it on 29 August 2024 for another 120 days. Confidential reasons followed on 26 February 2026; the public version was released on 15 June 2026.

QuestionPublic recordAnalytical significance
Why was a warrant required?CSIS said the threat-reduction measures would likely constitute Criminal Code offences without judicial authorization.Cyber defence action against third-party devices can cross a legal boundary even when the objective is defensive.
What was targeted?Canada-based servers, SOHO routers and IoT devices infected with malware.The technical object was compromised infrastructure, not a named class of people.
What did the devices do?They formed a botnet: a network of infected devices under malicious control.Compromised consumer and small-business equipment can become part of strategic relay infrastructure.
What did the Court find?The threat to Canada's security was clearly established and imminent; measures were necessary, reasonable and proportional.The authorization was bounded by a judicial proportionality analysis.
Was personal content collected?The Court's public summary says no identifying information, personal information or other content was collected.This is materially different from a warrant framed around acquiring a person's communications or identity.

The relay-infrastructure problem

A botnet does not need every infected device to be the final victim. A compromised router, camera or server can be useful because it gives an operator a geographically distributed network of ordinary-looking source addresses.

Foreign controllerCommand infrastructure directs compromised nodes.
Relay layerCompromised devices obscure origin and provide distributed paths.
Canadian deviceRouter, server or IoT appliance appears to be a normal local endpoint.
Target networkGovernment, military or critical-infrastructure systems may see the relay.
Strategic effectReconnaissance, access preparation or disruptive potential.

The public ruling is especially important because it makes the relay layer part of the national-security picture. A Canadian device does not have to contain classified information to matter. Its network position can itself be strategically valuable.

The devices named by the Court change the threat model

The Court expressly identifies everyday IoT examples including Ring doorbells, security cameras, televisions and other Wi-Fi-enabled appliances. It also highlights end-of-life equipment and devices whose software has not been updated as particular vulnerabilities.

This matters because conventional enterprise security programs often draw a hard boundary around managed laptops, servers and identity systems. The botnet model ignores that boundary. A camera on a residential network, a small-office router behind a business firewall, or an obsolete appliance can become part of an attack path without the owner knowingly doing anything malicious.

ClearGlass analytical distinction: “endpoint” should not mean “corporate laptop.” For critical-infrastructure threat modelling, the useful unit is the network position: anything that can originate, relay, terminate, authenticate or conceal traffic. Asset inventory therefore has to include unmanaged and semi-managed infrastructure where the organization can reasonably discover it.

Ontario: important exposure, but do not invent a number

Ontario deserves specific attention because it contains a very large concentration of Canada's population, businesses, cloud connectivity, Internet users and critical infrastructure. It is therefore reasonable to expect that a Canada-wide population of compromised devices could include a substantial Ontario component.

But the public Federal Court bulletin does not publish a province-by-province device count. ClearGlass is therefore not assigning a percentage, estimating a device total, or claiming that Ontario represented a particular share of the operation.

The defensible conclusion is narrower: Ontario organizations and households should treat this as directly relevant Canadian cyber-risk intelligence, not as an abstract Ottawa-only event. Any organization responsible for public-facing infrastructure, managed networks, municipal systems, energy-adjacent services, professional services or connected-device fleets should be able to answer whether obsolete or unmanaged equipment can be used as relay infrastructure.

The legal boundary is the story

There is a common but dangerous assumption that “defensive cyber” automatically means “authorized cyber.” The Court's bulletin demonstrates the opposite. CSIS required a Cyber Threat Reduction Measures Warrant because the measures it sought to take against infected devices would likely constitute Criminal Code offences.

That is a critical distinction for private-sector defenders. A security team may discover a compromised third-party device communicating through its environment. That does not automatically create authority to log into, modify, wipe or otherwise interfere with the third party's equipment.

The architecture should therefore separate detection, containment within your own administrative boundary, and external remediation. The first two may be ordinary defensive operations when properly authorized. The third can raise materially different legal and contractual questions.

What this decision does not establish

Why the “devices, not persons” distinction matters

The public summary makes an unusually explicit distinction: the measures were directed against devices, not persons, and no identifying information, personal information or other content was collected.

That distinction is central to understanding the proportionality analysis. The operational object was the malicious technical function: the device's participation in a botnet. The Court's public explanation does not describe the operation as an intelligence collection exercise designed to identify the householders or employees behind the devices.

For defenders, this reinforces a useful principle: security telemetry should distinguish asset identity from human identity. A device can be high-risk because of its network behaviour without its owner being a threat actor.

Why this is bigger than one warrant

The case sits inside a broader change in cyber conflict. State-sponsored operators increasingly use infrastructure that is not visibly theirs: compromised routers, virtual servers, edge appliances, consumer devices and other systems that blend into normal Internet traffic.

CSIS's own public reporting describes concern about state-sponsored cyber actors targeting North American critical infrastructure and using Internet-connected devices to maintain network presence while blending with legitimate activity. CSIS also reported participation in a 2024 cyber-disruption operation involving a GRU-controlled botnet of compromised routers, including devices in Canada.

The strategic implication is straightforward: Canada's attack surface includes infrastructure that Canadians did not build, do not centrally administer, and may not know is compromised.

Defensive control architecture: what changes Monday morning

1 · INVENTORYDiscover Internet-facing routers, cameras, appliances, remote-management interfaces and end-of-life equipment.
2 · SEGMENTKeep unmanaged IoT and edge equipment away from privileged administrative paths and sensitive systems.
3 · UPDATETrack firmware age, vendor support status and remediation ownership as security controls.
4 · OBSERVELook for unusual outbound connections, persistent relay behaviour and unexpected management traffic.
5 · CONTAINUse controls you own: network isolation, access revocation, routing restrictions and replacement.
6 · EVIDENCEPreserve timestamps, device identity, owner, firmware, network role and response decisions.

The evidence ledger a serious organization should maintain

A device inventory is not enough. If an incident reaches a regulator, insurer, customer, court or national-security partner, the organization needs to reconstruct what it knew and when.

FieldMinimum question
Asset identityWhat device, interface or service was involved?
Administrative ownerWho is authorized to manage it?
Physical/business locationWhere is the asset deployed?
Network roleEndpoint, gateway, relay-capable appliance, server, camera, sensor?
Firmware/support stateIs it supported and patched?
Observed behaviourWhat traffic or control behaviour triggered investigation?
Containment actionWhat did the organization change within its own authority?
Evidence timestampWhen was each observation and action recorded?
External coordinationWas a vendor, ISP, law-enforcement or government cyber authority contacted?
Decision authorityWho approved material response actions?

Threat reduction versus threat collection

One of the most useful analytical distinctions in the case is between learning about a threat and reducing it.

Traditional intelligence collection tries to answer questions: who controls the infrastructure, what are they targeting, what capabilities do they have, and what are they likely to do next? Threat reduction asks a different question: what authorized action can reduce the danger now?

The Federal Court record shows a judicially authorized move toward the second category. The purpose described publicly was to neutralize the botnets and protect Canadian critical infrastructure from the threat created by infected Canadian devices.

For enterprise security leaders, the analogue is not “hack back.” It is controlled remediation inside the organization's own authority boundary: isolate the device, remove its route, revoke credentials, replace unsupported equipment, notify the relevant provider, and preserve evidence.

What the case means for AI-agent security

There is also a direct connection to agentic systems. An AI agent that can discover assets, query telemetry, open tickets, change network policy or initiate remediation is itself an operational identity.

The Federal Court case makes the boundary especially clear: technical capability is not the same thing as authority. An agent may be technically capable of reaching a device without being legally or organizationally authorized to modify it.

Agent control rule: discovery can be automated broadly; consequential external modification should require an explicit authority boundary, authenticated identity, policy decision, human or pre-authorized approval where appropriate, and durable evidence of what action occurred.

That principle applies whether the operator is a human administrator, a SOAR platform, an autonomous agent or a scripted remediation system.

Questions for Ontario security leaders

Can an old router become part of a national-security problem?

Yes. The Federal Court expressly describes end-of-life and unpatched SOHO routers and IoT devices as vulnerable to becoming part of botnets. The device's strategic relevance can arise from its network position rather than the owner's intent.

Does Canadian ownership make a device trustworthy?

No. Ownership and network control are different properties. A Canadian-owned device can be compromised and controlled remotely.

Should every IoT device be treated as hostile?

No. The useful model is risk-based: identify exposure, support status, network position, management paths and observed behaviour, then apply proportionate controls.

Can a company “clean” a third party's infected device?

Do not infer authority from this case. The Court record specifically describes why CSIS sought a warrant. Private organizations should obtain appropriate legal and contractual authority before interfering with equipment they do not own or administer.

Does this ruling mean Ontario households were individually targeted?

The public record does not support that conclusion. The Court says the measures were directed at devices rather than persons and that no identifying information, personal information or other content was collected.

ClearGlass assessment model

For a Canadian organization, the practical assessment is not “are we likely to be hacked by a foreign intelligence service?” It is more measurable:

  1. Can we enumerate the Internet-facing equipment that can originate or relay traffic?
  2. Can we identify equipment that is end-of-life or no longer receiving security updates?
  3. Can we isolate unmanaged IoT without taking the business offline?
  4. Can our telemetry distinguish normal remote administration from anomalous control?
  5. Can we reconstruct who authorized each material containment action?
  6. Can we preserve evidence without unnecessarily collecting personal content?
  7. Can an automated agent perform only the remediation actions it is actually authorized to perform?

If the answer to several of these is “no,” the gap is not merely an IoT problem. It is an evidence-and-authority problem.

Bottom line

Federal Court File C-6-24 is significant because it makes a previously abstract cyber-defence boundary concrete. Foreign-controlled botnets can turn ordinary Canadian-connected equipment into relay infrastructure. The Canadian state sought judicial authority to alter that infrastructure. The Court found the legal threshold met and authorized specified threat-reduction measures.

The lesson for Canadian organizations is not to imitate an intelligence operation. It is to make the ordinary defensive layer stronger: know what is connected, retire what cannot be secured, segment what cannot be trusted, monitor the network role of edge devices, preserve evidence, and make authority explicit before an automated system takes a consequential action.

Ontario is part of that picture. But precision matters: the public ruling does not quantify affected devices by province. ClearGlass therefore treats Ontario exposure as a material risk-assessment question, not a published device-count claim.

Primary source
Federal Court of Canada, File C-6-24, “In the Matter of an Application by XXXX for Warrants Pursuant to Sections 12.1 and 21.1 of the Canadian Security Intelligence Service Act” — public bulletin dated 15 June 2026.
Read the Federal Court bulletin →
Related official context
CSIS public reporting on intelligence operations and state-sponsored cyber activity, including discussion of botnets and compromised routers in Canada.
Read the CSIS public report →

Editorial method: Public sources only. Facts attributed to the Federal Court or CSIS are distinguished from ClearGlass analysis. No classified access is implied. No device targeting instructions, exploit procedures or unauthorized-access methods are provided. This publication is informational and is not legal advice.

CSISFederal CourtbotnetsIoT securitySOHO routerscritical infrastructureOntario cyber riskagent governance