Canada’s proposed lawful access bill, Bill C-22, drew opposition from Signal, Apple, Google, Meta, NordVPN, DuckDuckGo, Windscribe, and Tailscale, which warned that the measure could force providers to weaken encryption, retain user metadata for up to one year, and build technical capabilities for government access. Critics said the bill’s use of secret ministerial orders and limited judicial oversight could undermine privacy commitments, raise compliance costs, and create new security weaknesses that malicious actors could exploit.
Canadian officials said the legislation is intended to modernize investigative powers and that amendments will clarify it is not meant to break encryption, but the government plans to preserve the one-year metadata retention requirement. Civil liberties groups and researchers including Citizen Lab and the Canadian Civil Liberties Association argued that the metadata retention and ministerial-order provisions should be removed entirely, warning that the proposal deepens the conflict between lawful access demands and the need to protect privacy, cybersecurity, and secure communications.

See the reporting duties and controls this puts on the clock.
6 events from the most recent confirmed update back to the earliest known activity.
Public Safety Minister Gary Anandasangaree said amendments to Bill C-22 will clarify that the legislation is not intended to undermine encryption, while the government plans to retain the one-year metadata retention provision.
Signal, NordVPN, Windscribe, DuckDuckGo, Apple, Google, Meta, Tailscale, and privacy advocates publicly opposed Canada's proposed lawful access bill, warning it could weaken encryption, mandate metadata retention, and require government access capabilities.
Airline passengers asked the full Fifth Circuit Court of Appeals to rehear their lawsuit against CrowdStrike, arguing their claims concern CrowdStrike's negligence as a software developer rather than airline services. CrowdStrike said it remains confident the dismissal will be upheld.
A U.S. District judge and later a three-judge Fifth Circuit panel held that airline passengers' claims against CrowdStrike were preempted by the Airline Deregulation Act.
In July 2024, a defective CrowdStrike Falcon software update caused a major outage that disrupted 8.5 million systems and led to airline-related disruptions affecting passengers.
On 2026-06-02, Citizen Lab submitted an analysis of Canada's Bill C-22 to the Standing Senate Committee, warning that the proposal could impose broad surveillance obligations, threaten human rights and transparency, weaken encryption, and harm cybersecurity. The submission recommended withdrawing several elements of the bill and amending others to reduce harm.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See what this changes for your reporting obligations and which controls it puts on the clock.
3 references tracked. Mallory keeps watching after this page renders.
citizenlab.ca
Open sourcecysecurity.news
Open sourcegovinfosecurity.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.