Nation-State

Canada Says Chinese Reconnaissance Scans Targeting Government Organizations

Canada says multiple government and critical infrastructure organizations have been targeted in Chinese reconnaissance scans.

Canada bans Hikvision

The Canadian Centre for Cyber Security (Cyber Centre) says a sophisticated Chinese threat actor has performed numerous reconnaissance scans against government organizations.

Spanning over several months in 2024, most of the observed scanning activity targeted Canadian government departments and agencies, political parties, and the House of Commons and Senate.

However, democratic institutions, critical infrastructure, defense entities, media organizations, NGOs, and think tanks were also targeted for reconnaissance, Cyber Centre says.

“The Cyber Centre is aware that a sophisticated state-sponsored threat actor from the People’s Republic of China has performed broad based reconnaissance scanning over several months against numerous domains in Canada,” the agency notes.

Scanning activity occurs on a near-constant basis, but the operations of this sophisticated threat actor against multiple industries “is an opportunity to increase awareness of the potential threats facing Canadian organizations and share simple steps everyone can take to protect against them,” Cyber Centre says.

However, the agency also points out that the reconnaissance activity does not indicate that any of the targeted organizations has been compromised.

Advertisement. Scroll to continue reading.

Instead, it shows that the attackers are gathering information on these entities, potentially looking for exploitable vulnerabilities, likely in preparation for future, malicious attacks, Cyber Centre notes.

Organizations in Canada are advised to take protective measures to defend against these reconnaissance scans by following security best practices, such as implementing multi-factor authentication, checking logs for suspicious activity, and educating employees on phishing and social engineering.

“Threat actors often take advantage of unpatched systems. Organizations can protect themselves by ensuring they have updated their operating systems and applications to protect against all known vulnerabilities,” the agency says.

Related: DoJ: Chinese Man Used Spear-Phishing to Obtain Software From NASA, Military

Related: China and US Envoys Will Hold First Top-Level Dialogue on Artificial Intelligence

Related: China Accuses US of ‘Tens of Thousands’ of Cyberattacks

Related: US, UK Leaders Raise Fresh Alarms About Chinese Espionage

Related Content

Malware & Threats

US, UK, and Dutch government agencies published a report detailing the malware, and the FBI described the abuse of Telegram for C&C.

Data Breaches

Hackers exploited a vulnerability in a VPN product to steal the personal information of roughly 240,000 people.

Artificial Intelligence

China’s Ministry of Foreign Affairs responded to a question about Amodei’s essay by saying that all parties should work together on AI.

Nation-State

The Chinese-language input method editor for Windows can allow attackers to execute arbitrary code remotely.

Data Breaches

Stolen credentials were used in a multi-month campaign to access subscriber personal data and billing records.

Artificial Intelligence

Distillation is an ‘attack’ against an AI model designed to capture outputs, understand reasoning processes, and subsequently train a different model.

Artificial Intelligence

The ruling is part of Anthropic's legal battle against the Pentagon after the government labeled the company as a supply chain risk earlier this...

Artificial Intelligence

New research shows that country-of-origin labels can obscure an AI model’s upstream dependencies, inherited behaviors and potential security risks.

Copyright © 2026 SecurityWeek ®, a Wired Business Media Publication. All Rights Reserved.

Exit mobile version