Sentrix

Analysis · Ransomware

Ransomware: what the Canadian Centre expects

Opportunistic, financially motivated, organized as ransomware-as-a-service: what the Canadian Centre for Cyber Security says about the adversary through 2027.

By Sentrix · Published 2026-10-01

Somewhere on a dark web forum, access to an organization's network changes hands. The seller will never deploy ransomware; the buyer did not write the malware they are about to launch. Neither picked the victim for its sector. That market, not a lone hacker, is what the Canadian Centre for Cyber Security describes in its Ransomware Threat Outlook 2025 to 2027, based on information available as of September 4, 2025.

What the Centre says

Who they are. The Centre assesses that ransomware actors operating against Canadian targets are "almost certainly opportunistic and financially motivated". The core membership of the top groups impacting Canada is, in its words, most likely Russian speaking and operating out of the Commonwealth of Independent States, while their affiliates operate globally.

How they are organized. The report describes an ecosystem of separate roles. In ransomware-as-a-service (RaaS), a core group of developers sells or leases its ransomware variant to affiliates. Initial access brokers sell network access, which, the Centre writes, reduces the time required to execute an attack. Dark web forums and marketplaces are where these services are sold, dedicated leak sites are where stolen data is published, and cryptocurrency is how the money is collected, with chain hopping and mixers to hide where the funds came from.

Who they hit. In 2024, the top three ransomware threats to Canada were Akira, Play and Medusa, all three using double extortion. The report ties Akira to manufacturing and telecommunications, Play to information and technology and to professional services, Medusa to critical infrastructure and information and communications technology. The incident examples the Centre selected cover the public sector, logistics, retail, education technology and energy. Its conclusion: no organization is immune.

How many. Canadian ransomware incidents known to the Centre grew by 26% year over year on average from 2021 to 2024, despite a small reduction in 2022, and the Centre estimates that the pace continues through 2025. The real number is almost certainly higher, it adds, because of underreporting.

What the Centre expects

The Centre assesses that these actors will remain a significant threat to Canada in the next two years. Five developments stand out across its two reports.

  • Multi-extortion. According to the open-source reporting the Centre cites, encryption and leaks are joined by distributed denial-of-service attacks and by ransom demands sent to the victim's suppliers, partners or customers.
  • Exfiltration only. The Centre calls it "a notable shift in behaviour": no encryption, only theft and extortion. It cites Hunters International, which focused on it in November 2024 and very likely rebranded to World Leaks in January 2025.
  • Artificial intelligence. Developing malware, generating deepfakes, automating negotiations with victims, researching vulnerabilities, social engineering: at each stage, large language models reduce the skill required.
  • Geopolitics. Some states protect cybercriminals; others quietly permit them as long as they serve their interests and spare victims at home.
  • Splintering. The National Cyber Threat Assessment 2025-2026 recalls the infrastructure seizures of Hive in January 2023, ALPHV in December 2023 and LockBit in February 2024, but judges that these disruptions almost certainly will not have an enduring impact: affiliates will almost certainly begin to act independently and create their own variants.

The same assessment calls ransomware "the top cybercrime threat facing Canada's critical infrastructure".

What we think at Sentrix

An opportunistic adversary is not looking for you: it finds you. For a mid-size organization, the Centre's portrait moves the priorities. In order:

  1. Close the doors the market resells. The Centre names the initial access points these actors often use: unpatched software, compromised credentials, phishing, remote desktop protocol. That is what a broker puts up for sale. Patch what faces the Internet first, require multi-factor authentication (MFA) everywhere, close or filter remote access.
  2. Make data theft the main scenario. The report recalls that the publication of stolen data, first seen in 2019, eliminated backups as an effective sole mitigation. Knowing which sensitive data you hold, keeping less of it and detecting a mass outflow now matter as much as restoring.
  3. Count your providers in your attack surface. The Centre counts managed service providers among the attractive targets, because of their client networks. Their access to your systems deserves the same requirements as your own.
  4. Decide before the incident. Paying guarantees nothing, the Centre recalls, and a poorly protected cyber insurance policy can reveal the coverage amount to the attacker.
  5. Stay reachable. In the 2024 to 2025 fiscal year, the Centre issued 336 pre-ransomware notifications to over 300 Canadian organizations, for savings of up to CAD 18 million. A notification only helps if someone receives it and knows what to do with it.

The next step

Take the four access points the Centre names and answer for each, in writing: what is exposed today, and who answers for it? Akira, Play and Medusa each have a profile in our Threats section.

Sources

Frequently asked questions

Is a mid-size organization really a target?
Yes. The Canadian Centre for Cyber Security assesses that any Canadian organization, small or large, can be susceptible to ransomware. Some groups research companies to identify those most likely to pay; others mostly want more posts on their dedicated leak site, regardless of victim size, to bolster their reputation. Managed service providers also widen the exposure of smaller businesses that rely on them.
What is ransomware-as-a-service (RaaS)?
According to the Centre's glossary, a core group of developers sells or leases its ransomware variant to other threat actors, called affiliates, in exchange for an upfront payment, subscription fees or a cut of the profits. The Centre assesses it is very likely that this model has lowered the technical barriers to entry and allowed sophisticated tactics, techniques and procedures to proliferate against Canadian organizations.
Does paying the ransom get the data back?
There is no guarantee, the Centre writes: threat actors may not unlock systems or return stolen data, and they can copy the data to extort the organization or its customers again. In one of the report's examples, the actor kept contacting victims after the payment. The Centre advises reporting the attack to local authorities, the Canadian Anti-Fraud Centre and the Cyber Centre itself.

Let's talk about your compliance program.

Last updated: 2026-10-01