OTTAWA — On July 23, someone reached into the controls of the drinking-water plant in Saint-Noël, a village of fewer than four hundred people in Quebec’s Bas-Saint-Laurent, and began raising the chlorine. The alarms that should have sounded had been switched off. The plant went into a protective shutdown on its own, and the water stayed clean.
The next day a pro-Russia hacking crew called Z-Pentest Alliance posted video of the intrusion to its Telegram channel as a trophy. Weeks later the two Russian groups blamed for the July break-ins widened their attacks across Canadian critical infrastructure, in response to the Carney government’s pledge to keep arming Ukraine, and were joined by a pro-Palestine group, according to a new analysis by Graphika, a social media analytics firm based in New York.
The report, reviewed by The Bureau, appears to show the modern face of hybrid war, waged by loose coalitions of anti-Western forces as military and economic conflict spreads across the Middle East and Europe.
It took twenty days for Canadian authorities to be publicly identified as investigating, and when Radio-Canada reported on August 12 that Quebec and federal investigators were examining that intrusion along with a second one at a water facility in Georgetown, Ontario, the hackers responded.
A Russian-language Telegram channel called Black Mask amplified the Radio-Canada report the same day, drawing attention to the two groups named in it: Z-Pentest Alliance and NoName057(16).
Z-Pentest forwarded that post to its own channel, then followed with a message mocking Canadian authorities for taking “a whole 20 days to even figure out who hacked them.” The following day NoName circulated a report from the security outlet iQBlack describing the water-system intrusions as part of a broader campaign against Canada.
Beginning August 17, according to Graphika, NoName claimed a renewed wave of attacks under the banner #OpCanada, framing them as retaliation for Canada’s continued military assistance to Ukraine despite Russian warnings. The group claimed distributed denial of service attacks against Canadian technology firms, transportation operators and municipal web portals, and said it had compromised an oxygen-generation system.
The denial of service technique floods a website with junk traffic until real users cannot reach it.
Z-Pentest Alliance joined the following day with a different kind of proof, Graphika’s report says.
Rather than knocking a website offline, it published what it presented as security camera footage taken from the entrance of a Canadian residential building.
On August 20, a third group entered. Dark Storm Team, a pro-Palestine outfit best known for claiming responsibility for the outage that took down the social platform X in March 2025, said it had conducted denial of service attacks against the Canadian Advanced Technology Alliance and the telecommunications provider Primus Canada.
Dark Storm Team’s cause is Palestine, not Ukraine, and its target list has generally reflected that.
Asked whether the sequence reflects a broader alliance among anti-Western states, Léa Ronzaud, a senior investigator at Graphika, said the arrangement is routine.
“This is an extremely common pattern,” Ronzaud said, adding that the firm has tracked pro-Russia groups partnering with anti-Israel groups since early 2023, “in the form of cross-regional hacktivist alliances but also bilateral partnerships.”
Those alliances “often revolve around shared anti-West, conservative values, but also reflect a desire to be more impactful, efficient, and visible in the mainstream media sphere.” Even Russian state-sponsored groups, she said, “have tied dozens of partnerships over the years.”
Graphika describes NoName as Russian state-sponsored. Of the pro-Palestine group, Ronzaud said: “We have no evidence that Dark Storm Team is sponsored by any state.”
Iranian-sponsored groups, she added, “behave completely differently from the pro-Iran, seemingly independent groups we track,” and “usually operate within their own echo chamber.”
In The Bureau’s assessment, the attacking alliance is the routine part. What is novel in Canada, is the targets.
A campaign that began with website outages moved into the controls of a water plant and cameras at a residential apartment.
Russia’s war on Ukraine supplies the cause for one set of actors, the war in Gaza and the wider confrontation involving Iran may supply it for another.
Ottawa arms Ukraine, and the retaliation falls on non-military targets in Canada, possibly as a way of applying coercive force to the Canadian government.
In a sense, this can be understood as a form of terrorism.
The Criminal Code defines terrorist activity as an act committed for a political purpose, with the intention of intimidating the public about its security or compelling a government to act, that causes serious interference with an essential service. Manipulating a chlorine setting is an attack on a physical process with a public health consequence. Publishing footage from the entrance of a residential building is a demonstration that surveillance can reach into the lives of ordinary people.
European governments have spent two years describing this same pattern in their own territory, in the sabotage of undersea cables, in arson traced to recruited proxies, in drone incursions over airfields and in intrusions at utilities. More recently, attacks on synagogues and Jewish communities in Europe and Canada have been attributed by American prosecutors to proxies working for Iran’s Revolutionary Guard, hired through criminal gangs.



I think that what lies ahead knows no end! At least in Canada! Carney’s openly favouring of Beijing’s CCP and lesser questionable European/Asian/Middle East domains, his complete lack of action and caring on anything “Canada or Canadian”, his dark and evil lying side, his lead involvement with the heavily communist influenced WEF….just a tiny few of the influencers that currently control our country.
The complete lack of reaction to these attacks on various critical infrastructures - that the Russian group found quite hilarious - the inherent criminal and political corruption that runs rampant across Canada clearly spells out a future that Carney planned from his first encounter back in Canada after the UK kicked his sorry ass out of their country!!
I work in the IT industry. Canada is so far behind when it comes to cyber security. Both publicly and privately. I can tell you this is just the start.
Municipalities take years to update their systems due to bureaucratic nonsense. I can only imagine how bad it is with Provincial and Federal governements. The average person has no idea what cyber security even means. We live in a world where the internet and other large scale networks are a necessity for progress. Yet, most people don't know how to defend themselves in a space where conventional weapons and defenses have no place.
Tech education needs to be implemented in public education across the board. We need future generations to take this seriously and not push back or disregard the safety of their families, communities and businesses.